﻿<?xml version="1.0" encoding="UTF-8"?>
<procmon><processlist><process>
<ProcessIndex>1</ProcessIndex>
<ProcessId>11372</ProcessId>
<ParentProcessId>10560</ParentProcessId>
<ParentProcessIndex>2</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770632346846</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon64.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Temp\Procmon64.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Temp\Procmon64.exe&quot;  /originalpath &quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot;</CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>2</ProcessIndex>
<ProcessId>10560</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770594566098</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon.exe</ProcessName>
<ImagePath>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot; </CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x1000000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x62530000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\RICHED20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cd0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72520000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\Riched32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wrapper Dll for Richedit 1.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>3</ProcessIndex>
<ProcessId>4048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765778109600457</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchIndexer.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchIndexer.exe</ImagePath>
<CommandLine>C:\Windows\system32\SearchIndexer.exe /Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Индексатор службы Microsoft Windows Search</Description>
<modulelist>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ff63db40000</BaseAddress>
<Size>929792</Size>
<Path>C:\Windows\system32\SearchIndexer.exe</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индексатор службы Microsoft Windows Search</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\MSSRCH.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabd990000</BaseAddress>
<Size>720896</Size>
<Path>C:\Windows\system32\ElsLad.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ELS Language Detection</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\Msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>4</ProcessIndex>
<ProcessId>580</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776275984299</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>services.exe</ProcessName>
<ImagePath>C:\Windows\system32\services.exe</ImagePath>
<CommandLine>C:\Windows\system32\services.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Приложение служб и контроллеров</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>5</ProcessIndex>
<ProcessId>9600</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795770643965692</CreateTime>
<FinishTime>131795770702408501</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645320867</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645748052</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645321771</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645749803</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645749049</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645313279</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>6</ProcessIndex>
<ProcessId>664</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776282506625</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k DcomLaunch</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc6a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\SebBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; SEB Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc7e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\SmartCardBackgroundPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartCardBackgroundPolicy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8c0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\CbtBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; CBT Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8d0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\ACPBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; ACP Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc900000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BackgroundMediaPolicy.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Background Media Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\RmClient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca740000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\DAB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL брокера активности компьютера</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacabd0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\OnDemandBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OnDemandBrokerClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacae70000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\systemeventsbrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер системных событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacafc0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy RM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb010000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SYSTEM32\psmserviceexthost.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager PSM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb390000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\psmsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process State Manager (PSM) Service</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb4f0000</BaseAddress>
<Size>794624</Size>
<Path>c:\windows\system32\bisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба инфраструктуры фоновых задач</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb720000</BaseAddress>
<Size>344064</Size>
<Path>c:\windows\system32\mintdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>c:\windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb820000</BaseAddress>
<Size>712704</Size>
<Path>C:\Windows\SYSTEM32\tdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8d0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\umpoext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения службы пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8f0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\umpo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb940000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\umpnpmgr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский режим службы самонастройки (Plug-and-Play)</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>7</ProcessIndex>
<ProcessId>884</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776292813936</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9230000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\bluetoothapis.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Usermode Api host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9580000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\BthRadioMedia.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab95a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WlanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wlan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaba920000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\rmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Radio Manager API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabae80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\NfcRadioMedia.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NFC Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabb8a0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\XboxGipRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Xbox GIP Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc0e0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\WwanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wwan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac78c0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\shacct.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Classes</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7f80000</BaseAddress>
<Size>208896</Size>
<Path>c:\windows\system32\wscsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8490000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\dhcpcore6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8c90000</BaseAddress>
<Size>385024</Size>
<Path>c:\windows\system32\dhcpcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>c:\windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac9c30000</BaseAddress>
<Size>1732608</Size>
<Path>c:\windows\system32\wevtsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба протоколирования событий</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca2a0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\timebrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер событий времени</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca330000</BaseAddress>
<Size>36864</Size>
<Path>c:\windows\system32\nrpsrv.DLL</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Name Resolution Proxy (NRP) RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4d0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lmhsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб транспорта TCPIP NetBios</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>8</ProcessIndex>
<ProcessId>0</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:00000000</AuthenticationId>
<CreateTime>131765775874898587</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>4294967295</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity></Integrity>
<Owner></Owner>
<ProcessName>Idle</ProcessName>
<ImagePath>Idle</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>9</ProcessIndex>
<ProcessId>4</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775907178738</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>System</ProcessName>
<ImagePath>System</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b6e00000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\System32\win32kfull.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Win32k Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7190000</BaseAddress>
<Size>1576960</Size>
<Path>C:\Windows\System32\win32kbase.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Базовый драйвер ядра Win32k</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7320000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\TSDDD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Framebuffer Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7330000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\cdd.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Canonical Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b74a0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\win32k.sys</Path>
<Version>10.0.14393.594 (rs1_release_inmarket.161213-1754)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Multi-User Win32 Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80278934000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\kd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Kernel Debugger</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80279678000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92e00000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\ksecdd.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ee0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\cmimcext.sys</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Configuration Manager Initial Configuration Extension Host Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ef0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\ntosext.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTOS extension host driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92fa0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\drivers\cng.sys</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Cryptography, Next Generation</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93040000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\system32\drivers\Wdf01000.sys</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения платформы драйвера режима ядра</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93120000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\drivers\WDFLDR.SYS</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Mode Driver Framework Loader</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93140000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\Drivers\acpiex.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPIEx Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93170000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\Drivers\WppRecorder.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WPP Trace Recorder</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93180000</BaseAddress>
<Size>733184</Size>
<Path>C:\Windows\System32\drivers\ACPI.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPI драйвер для NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93240000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\WMILIB.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMILIB WMI support library Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93260000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\intelpep.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Power Engine Plugin</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93280000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\drivers\WindowsTrustedRT.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932a0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Service Proxy Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\pcw.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Performance Counters for Windows Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932d0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\msisadrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ISA Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932e0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\isapnp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер шины PNP ISA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932f0000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\drivers\pci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Plug and Play PCI-перечислитель</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93350000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\vdrvroot.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Drive Root Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93370000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\drivers\pdc.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Power Dependency Coordinator Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933a0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\CEA.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation Kernel Mode Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\partmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Partition driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\nvraid.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) RAID Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93420000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\CLASSPNP.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI Class System Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93490000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\vmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Дочерний драйвер шины виртуальной машины Microsoft Hyper-V</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d934c0000</BaseAddress>
<Size>1212416</Size>
<Path>C:\Windows\System32\drivers\NDIS.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS (Network Driver Interface Specification)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d935f0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\drivers\NETIO.SYS</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network I/O Subsystem</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93670000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\hvsocket.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Hyper-V Socket Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\vmbkmcl.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V VMBus KMCL</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\winhv.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Hypervisor Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\pciide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Generic PCI IDE Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936e0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\PCIIDEX.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PCI IDE Bus Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93700000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\drivers\spaceport.sys</Path>
<Version>10.0.14393.1914 (rs1_release_inmarket.171117-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Spaces Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937a0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\intelide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel PCI IDE Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937b0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\volmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937d0000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\drivers\volmgrx.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер расширения диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93830000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\drivers\mountmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер точек подключения</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93850000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\nvstor.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) Sata Performance Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\drivers\storport.sys</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Storage Port Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93910000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\atapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI IDE Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93920000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\System32\drivers\ataport.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93960000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\storahci.sys</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS AHCI Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93990000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\stornvme.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft NVM Express Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\drivers\EhStorClass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enhanced Storage Class driver for IEEE 1667 devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\fileinfo.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FileInfo Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939f0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\Drivers\Wof.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр оверлея Windows</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93a80000</BaseAddress>
<Size>2297856</Size>
<Path>C:\Windows\System32\Drivers\NTFS.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер файловой системы NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\storvsc.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage VSC Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cd0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\Drivers\Fs_Rec.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>File System Recognizer Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93d10000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\System32\drivers\USBPORT.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта USB 1.1 и 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93db0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\mcupdate_GenuineIntel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Microcode Update Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93e50000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\System32\drivers\CLFS.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Common Log File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ec0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\tm.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Transaction Manager Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ef0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\PSHED.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер аппаратных ошибок, специфичных для платформы</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f10000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\BOOTVID.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>VGA Boot Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f20000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\FLTMGR.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер фильтров файловых систем Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\drivers\msrpc.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Remote Procedure Call Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94000000</BaseAddress>
<Size>430080</Size>
<Path>C:\Windows\System32\drivers\fwpkclnt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FWP/IPsec Kernel-Mode API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94070000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\wfplwfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WFP NDIS 6.30 Lightweight Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d940b0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DRIVERS\fvevol.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BitLocker Drive Encryption Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94160000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\volume.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94170000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\System32\drivers\volsnap.sys</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume Shadow Copy driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d941e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\scmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Class Memory Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\drivers\rdyboost.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ReadyBoost Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94250000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\Drivers\mup.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер поставщика множественных UNC</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94280000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\drivers\iorate.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>I/O rate control Filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942a0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\disk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PnP Disk Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942e0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\crashdmp.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crash Dump Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d943c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\drivers\cdrom.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI CD-ROM Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94400000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\drivers\filecrypt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows sandboxing and encryption filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94420000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\tbs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Export driver for kernel mode TPM API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94430000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Null.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NULL Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94440000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Beep.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BEEP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94450000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\BasicDisplay.sys</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94470000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\watchdog.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Watchdog Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94490000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\System32\drivers\dxgkrnl.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Kernel</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\BasicRender.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Render Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\Npfs.SYS</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPFS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94700000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\DRIVERS\tdx.sys</Path>
<Version>10.0.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDI Translation Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94740000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\DRIVERS\netbt.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>MBT Transport driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94790000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\drivers\afd.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер дополнительных функций для Winsock</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94830000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\vwififlt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual WiFi Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94850000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\pacer.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Планировщик пакетов QoS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\drivers\netbios.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetBIOS interface driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d948a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\rdbss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер подсистемы буферизации перенаправленного диска</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94920000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\drivers\csc.sys</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Client Side Caching Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\nsiproxy.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\npsvctrig.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Named pipe service triggers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\gpuenergydrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GPU Energy Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a00000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Drivers\dfsc.sys</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DFS Namespace Client Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a50000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\DRIVERS\ahcache.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Compatibility Cache</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a90000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-Transport Composite Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\kdnic.sys</Path>
<Version>6.01.00.0000 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Kernel Debugger Network Miniport</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ac0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\drivers\umbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User-Mode Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ae0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\i8042prt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта i8042</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b10000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\drivers\kbdclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса клавиатуры</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b30000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\mouclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса мыши</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b80000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\HDAudBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ba0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\drivers\portcls.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Port Class (Class Driver for Port/Miniport Devices)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c10000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\drmk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trusted Audio Drivers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c40000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\drivers\ks.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel CSA Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cb0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\usbohci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OHCI USB Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\CmBatt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Control Method Battery Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cd0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\BATTC.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Class Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ce0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\intelppm.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Processor Device Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d10000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\NdisVirtualBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечислитель виртуальных сетевых адаптеров (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d20000</BaseAddress>
<Size>2588672</Size>
<Path>C:\Windows\System32\drivers\tcpip.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fa0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\swenum.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Plug and Play Software Device Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fb0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\rdpbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft RDP Bus Device driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95200000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\DRIVERS\udfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UDF File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95280000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\Drivers\dump_diskdump.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d952c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\Drivers\dump_storahci.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95310000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\Drivers\dump_dumpfve.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95330000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\system32\drivers\HTTP.sys</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Стек протокола HTTP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95450000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\drivers\WudfPf.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - User-mode Driver Framework Platform Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95470000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\DRIVERS\bowser.sys</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Lan Manager Datagram Receiver Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d954a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT SMB Minirdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95520000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\mpsdrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Protection Service Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95540000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb20.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB 2.0 Redirector</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95580000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\DRIVERS\srvnet.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Network driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d955d0000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\System32\DRIVERS\srv2.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер сервера SMB 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95690000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb10.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB Downlevel SubRdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d956e0000</BaseAddress>
<Size>573440</Size>
<Path>C:\Windows\System32\DRIVERS\srv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95770000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\tcpipreg.sys</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>TCP/IP Registry Compatibility Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95860000</BaseAddress>
<Size>684032</Size>
<Path>C:\Windows\System32\drivers\dxgmms2.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics MMS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95910000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\luafv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра виртуализации файлов LUA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95960000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\storqosflt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр качества обслуживания хранилища</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95980000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\registry.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Registry Containment Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959a0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\drivers\lltdio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Mapper I/O Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959c0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\drivers\mslldp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер протокола Microsoft LLDP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\rspndr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Responder Driver for NDIS 6</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95ae0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\USBD.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Universal Serial Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95af0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\DRIVERS\HdAudio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Function Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95b60000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\ksthunk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Streaming WOW Thunk Service</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95bc0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\HIDPARSE.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hid Parsing Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97020000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\Drivers\360AntiHacker64.sys</Path>
<Version>1.0.0.1149</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络防黑模块</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97060000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\DRIVERS\360AvFlt.sys</Path>
<Version>1.1.0.1056</Version>
<Company>360.cn</Company>
<Description>360杀毒 文件监控驱动</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97080000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\DRIVERS\BAPIDRV64.sys</Path>
<Version>2.0.0.1221</Version>
<Company>360.cn</Company>
<Description>BAPIDRV</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d970c0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\drivers\360netmon.sys</Path>
<Version>2.1.11.5195</Version>
<Company>360.cn</Company>
<Description>360netmon</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97120000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\system32\DRIVERS\360Box64.sys</Path>
<Version>2.1.0.1253</Version>
<Company>360.cn</Company>
<Description>360Box64</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97180000</BaseAddress>
<Size>811008</Size>
<Path>C:\Windows\system32\DRIVERS\360FsFlt.sys</Path>
<Version>6.9.1.1751</Version>
<Company>360.cn</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97330000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\hidusb.sys</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>USB Miniport Driver for Input Devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97350000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\HIDCLASS.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека классов HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97380000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\mouhid.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра мыши HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97390000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\rassstp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS SSTP Miniport Call Manager</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973b0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\DRIVERS\NDProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\drivers\AgileVpn.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер вызовов минипорта RAS Agile VPN</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97420000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\drivers\rasl2tp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS L2TP mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97460000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\raspptp.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Peer-to-Peer Tunneling Protocol</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974a0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\raspppoe.sys</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS PPPoE mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\DRIVERS\ndistapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS 3.0 connection wrapper driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974d0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\drivers\ndiswan.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS PPP Framing Driver (Strong Encryption)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97510000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\DRIVERS\wanarp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS Remote Access and Routing ARP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97550000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\E1G6032E.sys</Path>
<Version>8.4.13.0 built by: WinDDK</Version>
<Company>Intel Corporation</Company>
<Description>Intel(R) PRO/1000 Adapter NDIS 6 deserialized driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97580000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\tunnel.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер интерфейса туннеля (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97600000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\Drivers\PROCMON24.SYS</Path>
<Version>3.10</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97a60000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\system32\drivers\peauth.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Protected Environment Authentication and Authorization Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b30000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\Ndu.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Network Data Usage Monitoring Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b60000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\drivers\mmcss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMCSS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97bb0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\condrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Driver</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>10</ProcessIndex>
<ProcessId>320</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775908989732</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>smss.exe</ProcessName>
<ImagePath>C:\Windows\System32\smss.exe</ImagePath>
<CommandLine>\SystemRoot\System32\smss.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер сеанса  Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>11</ProcessIndex>
<ProcessId>3108</ProcessId>
<ParentProcessId>3092</ParentProcessId>
<ParentProcessIndex>12</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777624392598</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Explorer.EXE</ProcessName>
<ImagePath>C:\Windows\Explorer.EXE</ImagePath>
<CommandLine>C:\Windows\Explorer.EXE</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x31b0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5db0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Program Files\Uninstall Tool\utshellext.dll</Path>
<Version>1.1.0.15</Version>
<Company>CrystalIDEA Software</Company>
<Description>Uninstall Tool Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x81a0000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\MICROS~1\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x8cb0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5bf70000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_08e394a1a83e212f\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\Notepad++\NppShell_06.dll</Path>
<Version>0.1</Version>
<Company></Company>
<Description>ShellHandler for Notepad++ (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\Explorer.EXE</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2093056</Size>
<Path>C:\Windows\system32\wpdshext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки для переносных устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab350000</BaseAddress>
<Size>1683456</Size>
<Path>C:\Windows\System32\comsvcs.dll</Path>
<Version>2001.12.10941.16384 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Services</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab4f0000</BaseAddress>
<Size>1400832</Size>
<Path>C:\Windows\system32\connect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Мастера подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab650000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\system32\rasgcw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Страницы мастера RAS</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\System32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\system32\ieframe.DLL</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0df0000</BaseAddress>
<Size>1626112</Size>
<Path>C:\Windows\SYSTEM32\d3d9.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 9 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0f80000</BaseAddress>
<Size>1777664</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoViewer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Просмотр фотографий Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab27c0000</BaseAddress>
<Size>516096</Size>
<Path>C:\Windows\System32\imapi2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>IMAPI версии 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2840000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\bthprops.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложение панели управления Bluetooth</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2880000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\cscobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Внутрипроцессный COM-объект используемый клиентами CSC API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab29a0000</BaseAddress>
<Size>1912832</Size>
<Path>C:\Windows\System32\pnidui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Значок сетевой системы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2b80000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\system32\SettingMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Change Monitor</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2bc0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\PortableDeviceTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device (Parameter) Types Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab34f0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\System32\Actioncenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5120000</BaseAddress>
<Size>1691648</Size>
<Path>C:\Windows\system32\BatMeter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Meter Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\MsftEdit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7e40000</BaseAddress>
<Size>3420160</Size>
<Path>C:\Windows\System32\SyncCenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр синхронизации Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\system32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\system32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab99b0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\dxp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки компонента Device Stage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9ba0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\SYSTEM32\searchfolder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SearchFolder</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabac60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\EhStorAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Enhanced Storage API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae20000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msiltcfg.dll</Path>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer Configuration API Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaea0000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\system32\SHDOCVW.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\SYSTEM32\settingsynccore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SYSTEM32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SYSTEM32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd3c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\InputSwitch.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переключатель ввода Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd670000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\framedynos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI SDK Provider Framework</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd6c0000</BaseAddress>
<Size>1306624</Size>
<Path>C:\Windows\System32\werconcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PRS CPL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd800000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\NPSMDesktopProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Библиотека DLL локального поставщика рабочего стола NPSM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabda60000</BaseAddress>
<Size>1241088</Size>
<Path>C:\Windows\System32\wscui.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdeb0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\wpdshserviceobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device Shell Service Object</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabded0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\stobject.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Объект службы оболочки Systray</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe470000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\wscinterop.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Health Center WSC Interop</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe580000</BaseAddress>
<Size>831488</Size>
<Path>C:\Program Files (x86)\360\Total Security\MenuEx64.dll</Path>
<Version>9, 6, 0, 1001</Version>
<Company></Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe650000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\system32\zipfldr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сжатые ZIP-папки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9a0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\Syncreg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Synchronization Framework Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\system32\NetworkExplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0b0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\playtomenu.dll</Path>
<Version>12.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека меню функции &quot;Передать на устройство&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\System32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf590000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\syncui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Портфель Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfba0000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\WSCAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\MICROS~1\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b40000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\dlnashext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLNA Namespace DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\srchadmin.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры индексирования</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0f60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SYSTEM32\CHARTV.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Chart View</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1cc0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.Sockets.PushEnabledApplication DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac27a0000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.111.0603.0006\amd64\FileSyncShell64.dll</Path>
<Version>18.111.0603.0006</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac32e0000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\twext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Свойства: Предыдущие версии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3350000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\OLEACCHOOKS.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Event Hooks Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\dsreg.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5140000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\AboveLockAppHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AboveLockAppHost</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5190000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\NotificationController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5570000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\system32\twinui.pcshell.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Twinui.PCShell</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac55d0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\windows.immersiveshell.serviceprovider.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.ImmersiveShell.ServiceProvider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\system32\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5c70000</BaseAddress>
<Size>65536</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoBase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Base Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6650000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\npsm.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPSM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac78f0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\hgcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Панель управления домашней группы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d40000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\SYNCENG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Briefcase Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d90000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\SYSTEM32\SndVolSSO.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Громкость SCA </Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7f50000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\acppage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека расширений для вкладки &quot;Совместимость&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\SYSTEM32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ea0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\hcproviders.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщики компонента &quot;Центр безопасности и обслуживания&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca190000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\WorkFoldersShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки рабочих папок (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac80000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SYSTEM32\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>13</ProcessIndex>
<ProcessId>404</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776186257169</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>15</ProcessIndex>
<ProcessId>468</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776223665667</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>17</ProcessIndex>
<ProcessId>484</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226419105</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>wininit.exe</ProcessName>
<ImagePath>C:\Windows\system32\wininit.exe</ImagePath>
<CommandLine>wininit.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Автозагрузка приложений Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>18</ProcessIndex>
<ProcessId>520</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226825613</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>winlogon.exe</ProcessName>
<ImagePath>C:\Windows\system32\winlogon.exe</ImagePath>
<CommandLine>winlogon.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Программа входа в систему Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ff7b5570000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\winlogon.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа входа в систему Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaee0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\dwminit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMInit</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacafa0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\UXINIT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows User Experience Session Initialization Dll</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>19</ProcessIndex>
<ProcessId>588</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776277547408</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>lsass.exe</ProcessName>
<ImagePath>C:\Windows\system32\lsass.exe</ImagePath>
<CommandLine>C:\Windows\system32\lsass.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Description>Local Security Authority Process</Description>
<modulelist>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x222e3610000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\msprivs.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переводы привилегий Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ff6b2d20000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\lsass.exe</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Security Authority Process</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffab9170000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\vaultsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба диспетчера учетных данных</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf170000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\hmkd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows HMAC Key Derivation API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf190000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\ngcpopkeysrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Passport Proof-of-possession Key Service</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\keyiso.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба изоляции ключей CNG</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SYSTEM32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf270000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SecureTimeAggregator.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Secure Time Aggregator</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb9b0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\scecli.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент редактора конфигураций безопасности</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\SspiSrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA SSPI RPC interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\dpapisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DPAPI Server</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbad0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\efslsaext.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA extension for EFS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbb70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wdigest.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Digest Access</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc00000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\MicrosoftAccountCloudAP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MicrosoftAccount Cloud AP Plugin</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc50000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\cloudAP.DLL</Path>
<Version>10.0.14393.1358 (rs1_release.170602-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cloud AP Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbcb0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\system32\pku2u.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pku2u Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd00000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\tspkg.DLL</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Web Service Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe30000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\gmsaclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;gmsaclient.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe60000</BaseAddress>
<Size>843776</Size>
<Path>C:\Windows\system32\netlogon.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека службы Net Logon</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc030000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\KerbClientShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kerberos Client Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc180000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\negoexts.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NegoExtender Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\JOINUTIL.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\netprovfw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Provisioning Service Framework DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc260000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\SYSTEM32\samsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сервера диспетчера учетных записей</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc380000</BaseAddress>
<Size>1527808</Size>
<Path>C:\Windows\system32\lsasrv.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера LSA</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>20</ProcessIndex>
<ProcessId>704</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776284978539</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k RPCSS</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8250000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\wshhyperv.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V Winsock2 Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6a0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\RpcRtRemote.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote RPC Extension</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\rpcepmap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сопоставитель конечных точек RPC
</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>21</ProcessIndex>
<ProcessId>808</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0000c8d4</AuthenticationId>
<CreateTime>131765776288401882</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>Window Manager\DWM-1</Owner>
<ProcessName>dwm.exe</ProcessName>
<ImagePath>C:\Windows\system32\dwm.exe</ImagePath>
<CommandLine>&quot;dwm.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер окон рабочего стола</Description>
<modulelist>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ff683990000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\dwm.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\system32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7b70000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\System32\Windows.Gaming.Input.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Gaming Input API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\avrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9a30000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SYSTEM32\ism32k.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca110000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\dwmghost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMGhost</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca8d0000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\system32\dwmcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека ядра Microsoft DWM</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacac90000</BaseAddress>
<Size>856064</Size>
<Path>C:\Windows\SYSTEM32\udwm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\dwmredir.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компонент перенаправления диспетчера окон рабочего стола Microsoft</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>22</ProcessIndex>
<ProcessId>904</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776293087855</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x259b0640000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\SFC.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab830000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\netman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>c:\windows\system32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>c:\windows\system32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab1260000</BaseAddress>
<Size>10350592</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll</Path>
<Version>4.7.2117.0 built by: NET47REL1LAST</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Common Language Runtime - WorkStation</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>c:\windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabfa00000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\SYSTEM32\MSVCR120_CLR0400.dll</Path>
<Version>12.00.52519.0 built by: VSWINSERVICING</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\MSI.DLL</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0fc0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\spp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих точек защиты Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1010000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\system32\MSCOREE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac10f0000</BaseAddress>
<Size>421888</Size>
<Path>c:\windows\system32\storsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы хранения</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1240000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll</Path>
<Version>4.7.2623.0 built by: NET471REL1LAST_C</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2420000</BaseAddress>
<Size>466944</Size>
<Path>c:\windows\system32\das.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сопоставления устройств</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac41c0000</BaseAddress>
<Size>139264</Size>
<Path>c:\windows\system32\trkwks.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент отслеживания изменившихся связей</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4650000</BaseAddress>
<Size>516096</Size>
<Path>c:\windows\system32\pcasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба помощника по совместимости программ</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Assembly manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b50000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\dssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы NT для службы совместного доступа к данным</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6120000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\sysmain.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост службы Superfetch</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b10000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\SYSTEM32\WUDFPlatform.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - библиотека платформ пользовательского режима</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b50000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\wudfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation (WDF) - служба среды выполнения платформы драйвера режима пользователя</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9800000</BaseAddress>
<Size>376832</Size>
<Path>c:\windows\system32\audioendpointbuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство построения конечных точек Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9de0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\portabledeviceconnectapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Portable Device Connection API Components</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SYSTEM32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca2d0000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\ncbservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Посредник подключений к сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>c:\windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca710000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\pcadm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Diagnostic Module</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\system32\SXS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>c:\windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>23</ProcessIndex>
<ProcessId>96</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776304995849</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2510000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\energyprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2580000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\ncuprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Connectivity Statistics Provider for System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2b90000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\nduprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик сетевой статистики для службы отслеживания использования ресурсов системы</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bb0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\appsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bd0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\eeprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy Estimator SRUM provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2c20000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\wfapigp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall GPO Helper dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2d70000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\wpnsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SRUM provider for WPN</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3310000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\srumsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3730000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\pnpts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PlugPlay Troubleshooter</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3bd0000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\ncdautosetup.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы автоматической настройки сетевых устройств</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac41f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\adhapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD harvest sites and subnets API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4500000</BaseAddress>
<Size>200704</Size>
<Path>c:\windows\system32\dps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба политики диагностики WDI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4cd0000</BaseAddress>
<Size>933888</Size>
<Path>c:\windows\system32\mpssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба защиты (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6740000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\dtsh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API состояния общего доступа и обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac74b0000</BaseAddress>
<Size>827392</Size>
<Path>c:\windows\system32\bfe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба базовой фильтрации</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\coremessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\system32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\CFGMGR32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>24</ProcessIndex>
<ProcessId>348</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776305446235</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k netsvcs</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaa0aa0000</BaseAddress>
<Size>2138112</Size>
<Path>c:\windows\system32\wlidsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба учетных записей Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0750000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\system32\rascustom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль настраиваемых протоколов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab07b0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\vpnike.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>VPNIKE Protocol Engine - Test dll</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab09b0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\system32\rasppp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access PPP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0a00000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\rastapi.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access TAPI Compliance Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab3440000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\rasmans.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер подключений удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4c50000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\eappprxy.dll</Path>
<Version>10.0.14393.187 (rs1_release_inmarket.160906-1818)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft EAPHost Peer Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab9a90000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\dmEnrollEngine.DLL</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enroll Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabc210000</BaseAddress>
<Size>2355200</Size>
<Path>c:\windows\system32\wuaueng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Агент Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabdf60000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\raschap.dll</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>Удаленные доступ через PPP CHAP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4a0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\appinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о приложении</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabed80000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\system32\wbem\wbemess.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee10000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee30000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\system32\wbem\wmiprvsd.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf090000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>c:\windows\system32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfda0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\wbem\ncprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Non-COM WMI Event Provision APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0000000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wbem\repdrvfs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Repository Driver</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\shacctprofile.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Profile Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1530000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SYSTEM32\dpx.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft(R) Delta Package Expander</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1900000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\appxapplicabilityblob.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Appx Applicability Blob DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1970000</BaseAddress>
<Size>1073152</Size>
<Path>c:\windows\system32\qmgr.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фоновая интеллектуальная служба передачи</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1c30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\DMProcessXMLFiltered.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmprocessxmlfiltered</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1cf0000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\SYSTEM32\wuuhext.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update Agent plugin for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1df0000</BaseAddress>
<Size>61440</Size>
<Path>c:\windows\system32\NCI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CoInstaller: NET</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e20000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f10000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\DMCmnUtils.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmcmnutils</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f50000</BaseAddress>
<Size>471040</Size>
<Path>C:\Windows\system32\wbem\esscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20f0000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\CLUSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API кластера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2210000</BaseAddress>
<Size>1351680</Size>
<Path>C:\Windows\system32\wbem\wbemcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инструментарий управления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2370000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\adhsvc.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD Harvest Sites and Subnets Service</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2390000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\httpprxm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac24a0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\system32\RESUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служебной программы ресурсов кластера (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2640000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\wmidcom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2670000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\miutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура управления</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac26f0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\sscoreext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Core DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2720000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SYSTEM32\WPTaskScheduler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WP Task Scheduler DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2770000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\SSCORE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основная DLL-библиотека службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2940000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CSystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Classic System Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>c:\windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a40000</BaseAddress>
<Size>974848</Size>
<Path>c:\windows\system32\iphlpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Эта служба предоставляет автоматическое подключение IPv6 в сети IPv4.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c60000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\WDSCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Panther Engine Module</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\system32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3740000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3b40000</BaseAddress>
<Size>245760</Size>
<Path>c:\windows\system32\wbem\wmisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3fa0000</BaseAddress>
<Size>331776</Size>
<Path>c:\windows\system32\srvsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) ресурсов для службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4160000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\wpnservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба системы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4480000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\taskcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оснастка обратной совместимости диспетчера задач</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4540000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\ProximityServicePAL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service PAL</Description>
</module>
<module>
<Timestamp>131795771111594425</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4cc0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ProximityCommonPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Common PAL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4dc0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\ProximityCommon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Универсальная реализация близкого взаимодействия</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4ee0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\ProximityService.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service Implementation</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5ef0000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\System32\MbaeApiPublic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Mobile Broadband Account API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7700000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\CredentialMigrationHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Migration Handler</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\sqmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SQM Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d60000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\UpdatePolicy.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Policy Reader</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e90000</BaseAddress>
<Size>749568</Size>
<Path>c:\windows\system32\FVEAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows BitLocker Drive Encryption API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac82d0000</BaseAddress>
<Size>643072</Size>
<Path>c:\windows\system32\shsvcs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8590000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\LocationWinPalMisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Location Platform Abstraction Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac85c0000</BaseAddress>
<Size>1810432</Size>
<Path>c:\windows\system32\LocationFramework.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа географического положения Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8780000</BaseAddress>
<Size>274432</Size>
<Path>c:\windows\system32\UBPM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL единого диспетчера фоновых процессов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8b60000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\schedsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac91c0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\profsvcext.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvcExt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92a0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\sens.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба уведомления о системных событиях (SENS)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\themeservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы темы оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9420000</BaseAddress>
<Size>380928</Size>
<Path>c:\windows\system32\profsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvc</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9a70000</BaseAddress>
<Size>1257472</Size>
<Path>c:\windows\system32\gpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca700000</BaseAddress>
<Size>32768</Size>
<Path>c:\windows\system32\DABAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Desktop Activity Broker API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca720000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\bitsigd.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service IGD Support</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacab70000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба географического положения</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac40000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\seclogon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL службы вторичного входа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac50000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\bitsperf.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Perfmon Counter Access</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\MSWSOCK.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>25</ProcessIndex>
<ProcessId>372</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776305463443</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>c:\windows\system32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab91f0000</BaseAddress>
<Size>233472</Size>
<Path>c:\windows\system32\sstpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обеспечивает возможность использования SSTP для подключения к удаленным компьютерам с помощью VPN.</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabc610000</BaseAddress>
<Size>540672</Size>
<Path>c:\windows\system32\w32time.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба времени Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabef00000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\cdpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба CDP Майкрософт (R)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05e0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\sbservicetrigger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Socket Broker Service Trigger</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4130000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\fdphost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба размещения поставщиков функций обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4200000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\perftrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Performance PerfTrack</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5b80000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\AuthBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API WinRT для веб-проверки подлинности</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66e0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\fdssdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery SSDP Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6960000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\fdwsd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery WS Discovery Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac76d0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\vmictimeprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Machine Integration Component Time Sync Provider Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7a10000</BaseAddress>
<Size>544768</Size>
<Path>c:\windows\system32\netprofmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер списка сетей</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7f70000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\licensemanagersvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManagerSvc</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90a0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\nsisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RPC-сервер интерфейса сохранения сети</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac91f0000</BaseAddress>
<Size>172032</Size>
<Path>c:\windows\system32\FontProvider.dll</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Font Provider Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9860000</BaseAddress>
<Size>1896448</Size>
<Path>c:\windows\system32\fntcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэша шрифтов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>c:\windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>26</ProcessIndex>
<ProcessId>360</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311216195</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffabaad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\deviceaccess.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Broker And Policy COM Server</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac7e70000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\coreaudiopolicymanagerext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;coreaudiopolicymanagerext.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac87d0000</BaseAddress>
<Size>237568</Size>
<Path>c:\windows\system32\AUDIOSRVPOLICYMANAGER.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Audio Service Policy Manager</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac90d0000</BaseAddress>
<Size>978944</Size>
<Path>c:\windows\system32\audiosrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\POWRPROF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>27</ProcessIndex>
<ProcessId>1040</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311708649</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8820000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SYSTEM32\cmintegrator.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>cmintegrator.dll</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8c50000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wcmcsp.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Service Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8fe0000</BaseAddress>
<Size>737280</Size>
<Path>c:\windows\system32\wcmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы диспетчера подключений Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>28</ProcessIndex>
<ProcessId>1068</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776312395030</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\CRYPTNET.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\cryptcatsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Catalog Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65f0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\crypttpmeksvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic TPM Endorsement Key Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6680000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\cryptsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6f00000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\wkssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы рабочей станции</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79e0000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\netjoin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL присоединения к домену</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\WlanApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7c00000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\ssdpapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8260000</BaseAddress>
<Size>425984</Size>
<Path>c:\windows\system32\ncsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индикатор работоспособности сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8370000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\nlasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о подключенных сетях 2</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8410000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dnsext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DNS extension DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SYSTEM32\Fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8830000</BaseAddress>
<Size>290816</Size>
<Path>c:\windows\system32\dnsrslvr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэширующего сопоставителя DNS</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\JoinUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>29</ProcessIndex>
<ProcessId>1248</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776322176070</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>spoolsv.exe</ProcessName>
<ImagePath>C:\Windows\System32\spoolsv.exe</ImagePath>
<CommandLine>C:\Windows\System32\spoolsv.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер очереди печати</Description>
<modulelist>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ff639680000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\spoolsv.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер очереди печати</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffab8a60000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaba980000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\jscript.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabb7d0000</BaseAddress>
<Size>851968</Size>
<Path>C:\Windows\System32\win32spl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик печати с исполнением на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\prntvpt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Ticket Services Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd70000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_53d78f68bc1697cc\Amd64\PrintConfig.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc0c0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPFILEQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPFILEQ</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc590000</BaseAddress>
<Size>118784</Size>
<Path>C:\Program Files\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc5b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\amsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Anti-Malware Scan Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd040000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdPnp.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pnp Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd060000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\WSDMon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер порта принтера WSD</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd100000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\usbmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Standard Dynamic Printing Port Monitor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd160000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\wsnmp32.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft WinSNMP v2.0 Manager API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd2a0000</BaseAddress>
<Size>1159168</Size>
<Path>C:\Windows\System32\localspl.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека локального диспетчера очереди</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabde60000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\System32\tcpmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека монитора портов TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe3f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\spool\PRTPROCS\x64\winprint.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Print Processor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe6c0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\PrintIsolationProxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Sandbox COM Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe8a0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\snmpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SNMP Utility Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe980000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\SPOOLSS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Spooler SubSystem DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f00000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\FXSMON.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft  Fax Print Monitor</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac4e90000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\wshirda.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Sockets Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac7e00000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\inetpp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Internet Print Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>30</ProcessIndex>
<ProcessId>1512</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776336551242</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffabe9f0000</BaseAddress>
<Size>258048</Size>
<Path>c:\windows\system32\ssdpsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы SSDP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69b0000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\fdrespub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба публикации ресурсов обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>c:\windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>31</ProcessIndex>
<ProcessId>1556</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776339471770</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k utcsvc</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x272f9bf0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf140000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\CourtesyEngine.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Feedback Courtesy Engine DLL Server</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfde0000</BaseAddress>
<Size>143360</Size>
<Path>c:\windows\system32\CRYPTXML.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API-интерфейс XML DigSig</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\Netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\DSREG.DLL</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac5fd0000</BaseAddress>
<Size>1056768</Size>
<Path>c:\windows\system32\WindowsPerformanceRecorderControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Performance Recorder Control Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>c:\windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6210000</BaseAddress>
<Size>2007040</Size>
<Path>c:\windows\system32\diagtrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диагностическое отслеживание Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>32</ProcessIndex>
<ProcessId>1636</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776343009549</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k appmodel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>c:\windows\system32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3c10000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\tileobjserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер моделей данных плиток</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>c:\windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>c:\windows\system32\windows.staterepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>33</ProcessIndex>
<ProcessId>1744</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776348255325</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>MemCompression</ProcessName>
<ImagePath>MemCompression</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>34</ProcessIndex>
<ProcessId>2100</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776438403561</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffabff90000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\ipsecsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows IPsec SPD Server DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac1e00000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\FwRemoteSvr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall Remote APIs Server</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>35</ProcessIndex>
<ProcessId>2648</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777555980720</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>sihost.exe</ProcessName>
<ImagePath>C:\Windows\system32\sihost.exe</ImagePath>
<CommandLine>sihost.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Shell Infrastructure Host</Description>
<modulelist>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ff7bbae0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\sihost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Infrastructure Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb910000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\container.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Containers</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb970000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\daxexec.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>daxexec</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc450000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\system32\ShareHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShareHost</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc800000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\windowmanagement.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Window Management</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc850000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\AppointmentActivation.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL for AppointmentActivation</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc8b0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\NotificationPlatformComponent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationPlatformComponent</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc9a0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\activationmanager.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Activation Manager</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabca10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\ClipboardServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Modern Clipboard</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcde0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Windows\System32\modernexecserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Modern Execution</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcf10000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\desktopshellext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DesktopHost Extensions</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\system32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>36</ProcessIndex>
<ProcessId>840</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777563791648</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k UnistackSvcGroup</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf6a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\PhoneUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Phone utilities</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf700000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\System32\PIMSTORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>POOM</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab05d0000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\AccountAccessor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync data model to access accounts</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab0630000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\SyncController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SyncController for managing sync of mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb20000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\CEMAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CEMAPI</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcd80000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\cdpusersvc.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP User Components</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabd630000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\MCCSEngineShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Utilies shared among OneSync engines</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabdde0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\SYNCUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabed20000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\aphostservice.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>c:\windows\system32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4100000</BaseAddress>
<Size>151552</Size>
<Path>c:\windows\system32\NetworkHelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac97b0000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\InprocLogger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>In-proc Private Event Trace Logger</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca1d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\UserDataTypeHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Type Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca270000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\UserDataLanguageUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Language-related helper functions for user data</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca520000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\APHostClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service RPC Client </Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacabf0000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\MCCSPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform abstraction layer dll for MCCS</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacac20000</BaseAddress>
<Size>86016</Size>
<Path>c:\windows\system32\UserDataPlatformHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>37</ProcessIndex>
<ProcessId>528</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777565618284</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\system32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb440000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\system32\MTFServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;MTFServer.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb510000</BaseAddress>
<Size>2854912</Size>
<Path>C:\Windows\system32\InputService.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Text InputService Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8c0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\InputLocaleManager.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;InputLocaleManager.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8f0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\EditBufferTestHook.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;EditBufferTestHook.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb9f0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\system32\MSUTB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) сервера MSUTB</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabba70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\MsCtfMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MsCtfMonitor DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabbc20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\PlaySndSrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба PlaySound</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\system32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac7d10000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\KBDUS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>United States Keyboard Layout</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab10000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\WordBreakers.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;WordBreakers.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>38</ProcessIndex>
<ProcessId>3632</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777941176116</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>RuntimeBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\RuntimeBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\RuntimeBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Runtime Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7a45f0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\RuntimeBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Runtime Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\System32\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\mssrch.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe880000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\FeClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT File Encryption Client Interfaces</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe8c0000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\system32\windows.cortana.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.Desktop</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795771229682115</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf9c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\system32\windows.cortana.onecore.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.OneCore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795771234179313</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5ca0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\AppExtension.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API AppExtension</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795771242759756</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7d00000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SYSTEM32\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>39</ProcessIndex>
<ProcessId>3164</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778119045372</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ShellExperienceHost.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe&quot; -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Windows Shell Experience Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ff697570000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Experience Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f760000</BaseAddress>
<Size>3796992</Size>
<Path>C:\Windows\System32\MFMediaEngine.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Media Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaabad0000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\mfsrcsnk.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Source and Sink DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaafe70000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\System32\mfcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Core DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab0be0000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\ShellExperiences\NetworkUX.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab9eb0000</BaseAddress>
<Size>2899968</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.ActionCenter.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActionCenter Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaba180000</BaseAddress>
<Size>7880704</Size>
<Path>C:\Windows\ShellExperiences\StartUI.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Start UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SYSTEM32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd420000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\RTMediaFrame.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime MediaFrame DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe410000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\SYSTEM32\globcollationhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GlobCollationHost</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0080000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\System32\resampledmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Resampler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0110000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\QuickActionsDataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>QuickActionsDataModel</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0160000</BaseAddress>
<Size>491520</Size>
<Path>C:\Windows\ShellExperiences\QuickActions.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac40f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4eb0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5b20000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\CompPkgSup.DLL</Path>
<Version>10.0.14393.969 (rs1_release_inmarket.170315-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Component Package Support DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5e90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\Windows.Media.MediaControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера MediaControl среды выполнения Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>40</ProcessIndex>
<ProcessId>4856</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778391112136</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MSASCuiL.exe</ProcessName>
<ImagePath>C:\Program Files\Windows Defender\MSASCuiL.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Windows Defender\MSASCuiL.exe&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Description>Windows Defender notification icon</Description>
<modulelist>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x23622c70000</BaseAddress>
<Size>733184</Size>
<Path>C:\Program Files\Windows Defender\EppManifest.dll</Path>
<Version>4.10.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль ресурсов настройки пользовательского интерфейса</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ff63bef0000</BaseAddress>
<Size>651264</Size>
<Path>C:\Program Files\Windows Defender\MSASCuiL.exe</Path>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Defender notification icon</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4560000</BaseAddress>
<Size>950272</Size>
<Path>C:\Program Files\Windows Defender\mpclient.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Client Interface</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>41</ProcessIndex>
<ProcessId>4928</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778406250112</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>uTorrent.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe&quot;  /MINIMIZED</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>3.5.4.44498</Version>
<Description>µTorrent</Description>
<modulelist>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>5406720</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</Path>
<Version>3.5.4.44498</Version>
<Company>BitTorrent Inc.</Company>
<Description>µTorrent</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e140000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SysWOW64\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1c0000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\SysWOW64\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6ef20000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70af0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fc0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fd0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fe0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>42</ProcessIndex>
<ProcessId>3608</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778496229053</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ApplicationFrameHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\ApplicationFrameHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\ApplicationFrameHost.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Application Frame Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ff6aa270000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\ApplicationFrameHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Frame Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5240000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\ApplicationFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фрейм приложения</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\system32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\D3D10Warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>43</ProcessIndex>
<ProcessId>5952</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778883326814</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54150_1240996307 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>44</ProcessIndex>
<ProcessId>5800</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765779120650795</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\esent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>45</ProcessIndex>
<ProcessId>340</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765800389528045</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54870_1839591030 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c50000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\Ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>46</ProcessIndex>
<ProcessId>2736</ProcessId>
<ParentProcessId>3976</ParentProcessId>
<ParentProcessIndex>47</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765800903010156</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Taskmgr.exe</ProcessName>
<ImagePath>C:\Windows\System32\Taskmgr.exe</ImagePath>
<CommandLine>&quot;C:\Windows\System32\Taskmgr.exe&quot; /2 </CommandLine>
<CompanyName>Microsoft® Windows® Operating System</CompanyName>
<Version>1, 0, 0, 1</Version>
<Description>Task Manager</Description>
<modulelist>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ff7c2a70000</BaseAddress>
<Size>1286144</Size>
<Path>C:\Windows\System32\Taskmgr.exe</Path>
<Version>1, 0, 0, 1</Version>
<Company>Microsoft® Windows® Operating System</Company>
<Description>Task Manager</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdfa0000</BaseAddress>
<Size>393216</Size>
<Path>C:\Windows\System32\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\System32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>48</ProcessIndex>
<ProcessId>5448</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765800971792901</CreateTime>
<FinishTime>131795770924543695</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>explorer.exe</ProcessName>
<ImagePath>C:\Windows\explorer.exe</ImagePath>
<CommandLine>C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>49</ProcessIndex>
<ProcessId>6724</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803507001117</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHActiveDefense.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe&quot;</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1008</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0xd0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</Path>
<Version>10,0,0,1008</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795771117425875</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>2830336</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Version>1.0</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x3c80000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fb90000</BaseAddress>
<Size>2736128</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\deepscan.dll</Path>
<Version>3, 5, 1, 2130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60190000</BaseAddress>
<Size>475136</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360SafeCamera.tpi</Path>
<Version>2, 0, 0, 1031</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60210000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\jcloudscan.dll</Path>
<Version>1, 0, 0, 1012</Version>
<Company>360.cn</Company>
<Description>360安全卫士 移动云查询模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604a0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appdext.dll</Path>
<Version>1, 0, 0, 1483</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604e0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\DrvUtility.dll</Path>
<Version>1, 0, 0, 1081</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60510000</BaseAddress>
<Size>409600</Size>
<Path>C:\Program Files (x86)\360\Total Security\SafeScan.dll</Path>
<Version>1, 0, 0, 1074</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60580000</BaseAddress>
<Size>204800</Size>
<Path>C:\Program Files (x86)\360\Total Security\ScanStub.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x605c0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360gameidentify.dll</Path>
<Version>1, 0, 1, 1050</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏识别模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60640000</BaseAddress>
<Size>430080</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\Netgm.dll</Path>
<Version>9,0,0,1005</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏模式判断模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60a50000</BaseAddress>
<Size>479232</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\DsSysRepair.dll</Path>
<Version>1, 0, 0, 1062</Version>
<Company>QIHU360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security System Repair Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61000000</BaseAddress>
<Size>184320</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\qutmipc.dll</Path>
<Version>7, 3, 0, 1267</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61030000</BaseAddress>
<Size>262144</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg.dll</Path>
<Version>3, 0, 0, 1160</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x610d0000</BaseAddress>
<Size>1097728</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\SomAdvUtils.dll</Path>
<Version>3, 1, 1, 2020</Version>
<Company>360.cn</Company>
<Description>360 Safeguard PC Boost</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61480000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qex\qex.dll</Path>
<Version>4.1.13.3366</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2017 Antivirus</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x616a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SelfProtectAPI2.dll</Path>
<Version>7, 1, 1, 1033</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61700000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360procmon.dll</Path>
<Version>7, 1, 1, 1221</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61780000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\netdefender.dll</Path>
<Version>1, 0, 0, 1129</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x617e0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appd.dll</Path>
<Version>7, 3, 6, 3113</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360HipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61ab0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\fileMgr.dll</Path>
<Version>7, 3, 0, 1963</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x621a0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\yhregd.dll</Path>
<Version>7, 2, 0, 1903</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62280000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\360SoftMgrS.dll</Path>
<Version>2, 1, 6, 1490</Version>
<Company>360.cn</Company>
<Description>360软件管家 服务模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62470000</BaseAddress>
<Size>405504</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll</Path>
<Version>7, 2, 1, 1279</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x624e0000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\360box.dll</Path>
<Version>2, 0, 0, 1043</Version>
<Company>360.cn</Company>
<Description>360隔离沙箱模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\deepscan\DsRes.dll</Path>
<Version>1,0,0,1012</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security Resource</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b70000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\gamemode.tpi</Path>
<Version>9,0,0,1001</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Game Mode Control</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67130000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\devenum.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечисление устройств.</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\fltlib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6c0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6ea80000</BaseAddress>
<Size>860160</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\QVM\360QVM.dll</Path>
<Version>5.0.2.1003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security QVM Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70210000</BaseAddress>
<Size>966656</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEngine.dll</Path>
<Version>1, 0, 0, 2016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70300000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEI.dll</Path>
<Version>1, 0, 0, 2003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>50</ProcessIndex>
<ProcessId>6340</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765803510844292</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>QHSafeTray.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</ImagePath>
<CommandLine>/showtrayicon</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1024</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0xec0000</BaseAddress>
<Size>2351104</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</Path>
<Version>10,0,0,1024</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x68f0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c480000</BaseAddress>
<Size>245760</Size>
<Path>C:\Program Files (x86)\360\Total Security\PDown.dll</Path>
<Version>1, 3, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Security Center Network Module </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5fe30000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll</Path>
<Version>9,6,0,1001</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60020000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360netctrl.dll</Path>
<Version>5, 3, 15, 2232</Version>
<Company>360.cn</Company>
<Description>360 Total Security NetwokrMonCtrl</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60090000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\netmon.tpi</Path>
<Version>5, 1, 1, 3157</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360安全卫士 流量防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60350000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Program Files (x86)\360\Total Security\ToolBox.dll</Path>
<Version>1, 0, 0, 1094</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x606b0000</BaseAddress>
<Size>598016</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe.dll</Path>
<Version>1, 0, 0, 1120</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x609b0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360GuardBase.dll</Path>
<Version>3, 1, 0, 1060</Version>
<Company>360.cn</Company>
<Description>360保镖</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61070000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SomProxy.dll</Path>
<Version>1, 0, 0, 1900</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x611e0000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360connect.tpi</Path>
<Version>9,2,0,1030</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Connect</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x618c0000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files (x86)\360\Total Security\sites.dll</Path>
<Version>11, 1, 0, 1212</Version>
<Company>360.cn</Company>
<Description>360安全卫士</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360hipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\softmgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\Cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62210000</BaseAddress>
<Size>446464</Size>
<Path>C:\Program Files (x86)\360\Total Security\360TSCommon.dll</Path>
<Version>9, 0, 0, 1016</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62960000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\CleanPlusCache.tpi</Path>
<Version>1, 0, 0, 1004</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>CleanPlusCache</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795771279916892</Timestamp>
<BaseAddress>0x68850000</BaseAddress>
<Size>2764800</Size>
<Path>C:\Windows\SysWOW64\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e6e0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e770000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SysWOW64\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71170000</BaseAddress>
<Size>466944</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\CQhCltHttpW.dll</Path>
<Version>1, 4, 0, 1030</Version>
<Company>QIHU 360 SOFTWARE  CO. LIMITED</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>51</ProcessIndex>
<ProcessId>6860</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803555957830</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHWatchdog.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe&quot; /watch</CommandLine>
<CompanyName>QIHU 360 SOFTWARE CO. LIMITED</CompanyName>
<Version>8,2,0,1000</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0xdf0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</Path>
<Version>8,2,0,1000</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>52</ProcessIndex>
<ProcessId>5924</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765805232900810</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>wmiprvse.exe</ProcessName>
<ImagePath>C:\Windows\sysWOW64\wbem\wmiprvse.exe</ImagePath>
<CommandLine>C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Description>WMI Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x950000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\sysWOW64\wbem\wmiprvse.exe</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Provider Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\storagewmi_passthru.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60160000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x604d0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\delegatorprovider.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>53</ProcessIndex>
<ProcessId>6180</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765807370364309</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>smartscreen.exe</ProcessName>
<ImagePath>C:\Windows\System32\smartscreen.exe</ImagePath>
<CommandLine>C:\Windows\System32\smartscreen.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>SmartScreen</Description>
<modulelist>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ff688690000</BaseAddress>
<Size>2416640</Size>
<Path>C:\Windows\System32\smartscreen.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreen</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaafa00000</BaseAddress>
<Size>2936832</Size>
<Path>C:\Windows\System32\certenroll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент регистрации служб сертификатов Active Directory Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffab2210000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\certca.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ЦС служб сертификации Microsoft® Active Directory</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\SYSTEM32\windows.globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac3290000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\smartscreenps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreenPS</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\System32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\CFGMGR32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>54</ProcessIndex>
<ProcessId>4408</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765812380694767</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x17826230000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1140000</BaseAddress>
<Size>1134592</Size>
<Path>C:\Windows\System32\ReAgent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>C:\Windows\System32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\system32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe000000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\system32\WinSATAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Assessment Tool API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf050000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\sdiageng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема выполнения сценариев диагностики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4ae0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sdiagschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запланированная задача сценариев проверки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4b00000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\MemoryDiagnostic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач средства проверки памяти Windows (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac5c80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\TempSignedLicenseExchangeTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TempSignedLicenseExchangeTask Task</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca200000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\ReAgentTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca210000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\RstrtMgr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер перезапуска</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacac00000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\radarrs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>программа устранения нехватки системных ресурсов Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>55</ProcessIndex>
<ProcessId>6944</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131767576301455145</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SkypeHost.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe&quot; -ServerName:SkypeHost.ServerServer</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>12.1815.210.0</Version>
<Description>Microsoft Skype</Description>
<modulelist>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ff7e8670000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaae130000</BaseAddress>
<Size>22437888</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkyWrap.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabe150000</BaseAddress>
<Size>2691072</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\skypert.dll</Path>
<Version>2018.15.01.31</Version>
<Company></Company>
<Description>SkypeRT shared library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1a80000</BaseAddress>
<Size>978944</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7c80000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>56</ProcessIndex>
<ProcessId>1048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131768729449405953</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>sedsvc.exe</ProcessName>
<ImagePath>C:\Program Files\rempl\sedsvc.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\rempl\sedsvc.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Description>sedsvc</Description>
<modulelist>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ff751430000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\rempl\sedsvc.exe</Path>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>sedsvc</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>57</ProcessIndex>
<ProcessId>7744</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081112364684</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; </CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x11330000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60900000</BaseAddress>
<Size>720896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\urlproc.dll</Path>
<Version>2, 9, 5, 1260</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x68b00000</BaseAddress>
<Size>44998656</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ce30000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6dc80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files (x86)\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6df70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\SysWOW64\shdocvw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e070000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e090000</BaseAddress>
<Size>233472</Size>
<Path>C:\Windows\SysWOW64\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e110000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e120000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multimedia Realtime Runtime</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e2a0000</BaseAddress>
<Size>4440064</Size>
<Path>C:\Windows\SysWOW64\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb60000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb70000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ec40000</BaseAddress>
<Size>442368</Size>
<Path>C:\Windows\SysWOW64\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd00000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd20000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe40000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe50000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SysWOW64\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ff90000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\SysWOW64\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ffe0000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\SysWOW64\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70190000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x701a0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\dllyupdate.dll</Path>
<Version>1.2.0.1831</Version>
<Company>Yandex LLC</Company>
<Description>Yandex updater (CU)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b30000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\WINUSB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows USB Driver User Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b60000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x711f0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>58</ProcessIndex>
<ProcessId>5696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081114193232</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe --type=crashpad-handler &quot;--user-data-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler &quot;--database=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data\Crashpad&quot; &quot;--metrics-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; --url=https://crash-reports.browser.yandex.net/submit --annotation=machine_id=c46245ef0fec9d5c44d2fa20241f2070 --annotation=main_process_pid=7744 --annotation=metrics_client_id=520f4dd3247d4cdfb744f32b1130b1bf --annotation=plat=Win32 --annotation=prod=Yandex --annotation=ver=18.6.1.770 --initial-client-data=0x1c4,0x1cc,0x1d0,0x1c0,0x1d4,0x700b800c,0x700b7ffc,0x700b7fe0,0x1c8</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>59</ProcessIndex>
<ProcessId>4664</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081123844756</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=gpu-process --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --service-request-channel-token=CC1AC8FA9C8EFF1EEBC2375FE4F704C6 --mojo-platform-channel-handle=1588 --ignored=&quot; --type=renderer &quot; /prefetch:2</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ecb0000</BaseAddress>
<Size>2228224</Size>
<Path>C:\Windows\SysWOW64\mfh264enc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation H264 Encoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f250000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\SysWOW64\ddraw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectDraw</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f340000</BaseAddress>
<Size>3784704</Size>
<Path>C:\Windows\SysWOW64\D3DCompiler_47.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D HLSL Compiler</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f6e0000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\SysWOW64\msvproc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Video Processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fbe0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\mf.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff20000</BaseAddress>
<Size>118784</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\swiftshader\libegl.dll</Path>
<Version>4.0.0.3</Version>
<Company></Company>
<Description>SwiftShader libEGL 32-bit Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dxva2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Video Acceleration 2.0 DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x705d0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\DCIMAN32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DCI Manager</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>60</ProcessIndex>
<ProcessId>8968</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081206363215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=183F52B8A6577BFD721F95F3A9641348 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=183F52B8A6577BFD721F95F3A9641348 --renderer-client-id=4 --mojo-platform-channel-handle=2640 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>61</ProcessIndex>
<ProcessId>4992</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081244357280</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=7E8A8199C364F4B0114F2A163B757250 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E8A8199C364F4B0114F2A163B757250 --renderer-client-id=10 --mojo-platform-channel-handle=3904 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>62</ProcessIndex>
<ProcessId>2156</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769082134099148</CreateTime>
<FinishTime>131795770677456415</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>explorer.exe</ProcessName>
<ImagePath>C:\Windows\explorer.exe</ImagePath>
<CommandLine>C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>63</ProcessIndex>
<ProcessId>9504</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956266598229</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgent.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgent.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgent.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>InstallAgent</Description>
<modulelist>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ff63d380000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\InstallAgent.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffabea60000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\VEStoreEventHandlers.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDL Store Event Handlers</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4ad0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\EAMProgressHandler.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>EAMProgressHandler</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>64</ProcessIndex>
<ProcessId>8768</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956321853179</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgentUserBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgentUserBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgentUserBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>InstallAgentUserBroker</Description>
<modulelist>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x22530450000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ff74f890000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\InstallAgentUserBroker.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgentUserBroker</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>65</ProcessIndex>
<ProcessId>9636</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956424585250</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettingsBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\SystemSettingsBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\SystemSettingsBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>System Settings Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ff6015f0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\SystemSettingsBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Broker</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>66</ProcessIndex>
<ProcessId>10592</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956519902643</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettings.exe</ProcessName>
<ImagePath>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</ImagePath>
<CommandLine>&quot;C:\Windows\ImmersiveControlPanel\SystemSettings.exe&quot; -ServerName:microsoft.windows.immersivecontrolpanel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Параметры</Description>
<modulelist>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x18099ef0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\WMI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI DC and DP functionality</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ff7937a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaabce0000</BaseAddress>
<Size>2535424</Size>
<Path>C:\Windows\System32\NetworkMobileSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System settings network mobile handlers group</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac220000</BaseAddress>
<Size>4952064</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Application</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaadd90000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\NetworkDesktopSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Группа обработчиков системных параметров сетевого рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaaf920000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettingsViewModel.Desktop.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings View Model Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0970000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\credprovhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост инфраструктуры поставщика учетных данных</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0a70000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\System32\fhcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигураций истории файлов</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\SYSTEM32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\SYSTEM32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab91d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\ImmersiveControlPanel\Telemetry.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Telemetry Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcc60000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\System32\MiracastReceiver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API приемника Miracast</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2bf0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\EFSUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>EFS Utility Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\SYSTEM32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\wmiclnt.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca560000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\NcaApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Network Connectivity Assistant API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>67</ProcessIndex>
<ProcessId>10964</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794956837373387</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{BA126F01-2166-11D1-B1D0-00805FC1270E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\system32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>68</ProcessIndex>
<ProcessId>8940</ProcessId>
<ParentProcessId>2156</ParentProcessId>
<ParentProcessIndex>62</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956984780982</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Photoshop.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe&quot; &quot;C:\Users\User\Downloads\tlauncher_psd\tlauncher_psd.psd&quot;</CommandLine>
<CompanyName>Adobe Systems, Incorporated</CompanyName>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Description>Adobe Photoshop CC 2017</Description>
<modulelist>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0xb20000</BaseAddress>
<Size>9846784</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\cg.dll</Path>
<Version>3.0.00007</Version>
<Company>NVIDIA Corporation</Company>
<Description>Cg Core Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1490000</BaseAddress>
<Size>3276800</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\libmmd.dll</Path>
<Version>12.0.12.2</Version>
<Company>Intel Corporation</Company>
<Description>Math Library for Intel(r) Compilers (thread-safe)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x10000000</BaseAddress>
<Size>6070272</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\svml_dispmd.dll</Path>
<Version>12.0.12.2</Version>
<Company>Intel Corporation</Company>
<Description>SVML Library for Intel(r) Compilers (thread-safe)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x4fad0000</BaseAddress>
<Size>70561792</Size>
<Path>C:\Program Files\Common Files\Adobe\Plug-Ins\CC\File Formats\Camera Raw.8bi</Path>
<Version>9.8</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Photoshop Camera Raw Plug-in</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5b690000</BaseAddress>
<Size>4763648</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\SVGRE.dll</Path>
<Version>6, 0, 0, 37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>SVGRE 6.0</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5bcf0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AXE8SharedExpat.dll</Path>
<Version>3.8.0.34320</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>AXE Shared EXPAT (UTF-8 native)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5bd30000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\dnssd.dll</Path>
<Version>3,0,0,2</Version>
<Company>Apple Inc.</Company>
<Description>Bonjour Client Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5bd40000</BaseAddress>
<Size>974848</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AXEDOMCore.dll</Path>
<Version>3.8.0.34320</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XML Engine: DOM Core</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5be30000</BaseAddress>
<Size>1306624</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\icucnv40.dll</Path>
<Version>4, 0, 0, 1001</Version>
<Company>IBM Corporation and others</Company>
<Description>IBM ICU Common DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x6a400000</BaseAddress>
<Size>479232</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\cgGL.dll</Path>
<Version>3.0.00007</Version>
<Company>NVIDIA Corporation</Company>
<Description>Cg GL Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\File Formats\PSDX.8bi</Path>
<Version>14.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Photoshop Remix Plug-In</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2eee90000</BaseAddress>
<Size>13922304</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\icudt40.dll</Path>
<Version>4, 0, 0, 1001</Version>
<Company>IBM Corporation and others</Company>
<Description>ICU Data DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f1470000</BaseAddress>
<Size>12288</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PSArt.dll</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Resource DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f3490000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.dll</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Resource DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f3620000</BaseAddress>
<Size>2699264</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PSViews.dll</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Resource DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f93a0000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\WRServices.dll</Path>
<Version>12.0.0.1000</Version>
<Company>WinSoft S.A.</Company>
<Description>WRServices Engine</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f9540000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Linguistics\Providers\Plugins2\WRLiloPlugin.bundle\WRLiloPlugin.dll</Path>
<Version>1.3.6rc1</Version>
<Company>WinSoft SA</Company>
<Description>WR LILO Plugin</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ff6c3030000</BaseAddress>
<Size>182624256</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa0cb0000</BaseAddress>
<Size>1880064</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\aif.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa0e80000</BaseAddress>
<Size>2637824</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\LogSession.dll</Path>
<Version>7.4.1.60.45263</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>LogSession</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa1110000</BaseAddress>
<Size>70823936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\libcef.dll</Path>
<Version>3.2526.1347.gcf20046</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa54a0000</BaseAddress>
<Size>7950336</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\ScriptingSupport.8li</Path>
<Version>18.0.1</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>ScriptingSupport</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa5c40000</BaseAddress>
<Size>2113536</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\AdobeHunspellPlugin.dll</Path>
<Version>11.0.0.22122</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>AdobeHunspellPlugin</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa5e50000</BaseAddress>
<Size>4493312</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\CoolType.dll</Path>
<Version>5.15.00.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>CoolType Typography Engine</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa62a0000</BaseAddress>
<Size>5267456</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AGM.dll</Path>
<Version>4.30.60.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Graphics Manager</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa67b0000</BaseAddress>
<Size>1839104</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ACE.dll</Path>
<Version>2.20.02.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Color Engine</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6980000</BaseAddress>
<Size>1302528</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeXMP.dll</Path>
<Version>5.6-c138 ( 64 bit ), 79.159824, 2016/09/14-01:09:01</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XMP Core 5.6-c138 ( 64 bit )</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6ac0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\MultiProcessor Support.8bx</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6b70000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\MMXCore.8bx</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2093056</Size>
<Path>C:\Windows\system32\wpdshext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки для переносных устройств</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6fd0000</BaseAddress>
<Size>978944</Size>
<Path>C:\Windows\SYSTEM32\MSVCR120.dll</Path>
<Version>12.00.40660.0 built by: VSULDR</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa70c0000</BaseAddress>
<Size>679936</Size>
<Path>C:\Windows\SYSTEM32\MSVCP120.dll</Path>
<Version>12.00.40660.0 built by: VSULDR</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7170000</BaseAddress>
<Size>2826240</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\opencv_imgproc249.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7430000</BaseAddress>
<Size>2564096</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\opencv_core249.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa76b0000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AIDE.dll</Path>
<Version>1.5.0.36540</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Image Decode Encode Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7820000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\tbbmalloc.dll</Path>
<Version>4, 4, 2016, 0412</Version>
<Company>Intel Corporation</Company>
<Description>Scalable Allocator library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7870000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\SYSTEM32\DDRAW.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectDraw</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7b20000</BaseAddress>
<Size>2613248</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeOwl.dll</Path>
<Version>5.2.11</Version>
<Company>Adobe Systems, Incorporated </Company>
<Description>Adobe Owl(64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7da0000</BaseAddress>
<Size>749568</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ScCore.dll</Path>
<Version>4.5.6.4</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Scripting Components Core (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7e60000</BaseAddress>
<Size>18792448</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\mona.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9050000</BaseAddress>
<Size>802816</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ExtendScript.dll</Path>
<Version>4.5.6.4</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe ExtendScript scripting engine (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9120000</BaseAddress>
<Size>5681152</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PlugPlugOwl.dll</Path>
<Version>7.0.0.67</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>PlugPlugOwl Standard Dll (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9690000</BaseAddress>
<Size>5595136</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\MPS.dll</Path>
<Version>5.8.1.37174</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Modular Parsing System</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9bf0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ahclient.dll</Path>
<Version>2.0.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Help Client Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9c50000</BaseAddress>
<Size>569344</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\manta.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9ce0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\tbb.dll</Path>
<Version>4, 4, 2016, 0412</Version>
<Company>Intel Corporation</Company>
<Description>Intel(R) Threading Building Blocks library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9d30000</BaseAddress>
<Size>499712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\VulcanControl.dll</Path>
<Version>__</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Vulcan Application Control Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9db0000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\VulcanMessage5.dll</Path>
<Version>__</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Vulcan Message Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9e50000</BaseAddress>
<Size>1241088</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdbePM.dll</Path>
<Version>2.5.00</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe PatchMatch</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9f80000</BaseAddress>
<Size>167936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\CITThreading.dll</Path>
<Version>2.1.0.1 ( 32 bit Debug)</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>CITTHREADING_NAME, 2.1.0.1 ( 32 bit Debug)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9fb0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\adobe_caps.dll</Path>
<Version>10,0,0,6</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CAPS DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa190000</BaseAddress>
<Size>1191936</Size>
<Path>C:\Windows\SYSTEM32\OPENGL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OpenGL Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa2c0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa5f0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\IMSLib.dll</Path>
<Version>10.0.0.1</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>IMSLib DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa9c0000</BaseAddress>
<Size>9007104</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\File Formats\Dicom.8bi</Path>
<Version>18.0.1</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Dicom Plugin</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaba80000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\GLU32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека подпрограмм OpenGL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaabca0000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PLUGIN.dll</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Plugin Utilities</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaade70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\icm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Color Management Module (CMM)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab06d0000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\c_g18030.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>GB18030 DBCS-Unicode Conversion DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab0b60000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeSVGAGM.dll</Path>
<Version>1.0.0.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe SVG AGM Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab1e60000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeXMPFiles.dll</Path>
<Version>5.7-f022 ( 64 bit ), 79.159824, 2016/09/14-01:09:01</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XMP Files 5.7-f022 ( 64 bit )</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab22e0000</BaseAddress>
<Size>1544192</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Spaces.8li</Path>
<Version>18.0.1</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Spaces</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab3410000</BaseAddress>
<Size>167936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\libglog.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabb070000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobePIP.dll</Path>
<Version>7.4.1.60.45263</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Product Improvement Program</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabb250000</BaseAddress>
<Size>380928</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\BIBUtils.dll</Path>
<Version>1.1.01.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Bravo Interface Binder Utilities</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabcc00000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\SYSTEM32\STI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека устройств неподвижных изображений </Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac0b40000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\dlnashext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLNA Namespace DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1300000</BaseAddress>
<Size>598016</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\BIB.dll</Path>
<Version>1.2.03.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Bravo Interface Binder</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\SYSTEM32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeXMPScript.dll</Path>
<Version>5.2-s002 ( 64 bit ), 79.159824, 2016/09/14-01:09:01</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XMP Script 5.2-s002 ( 64 bit )</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac4c50000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\WSOCK32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6aa0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\amtlib.dll</Path>
<Version>10.0.0.3</Version>
<Company>painter</Company>
<Description>AMTEmu Licensing</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\FastCore.8bx</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac7710000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\wiatrace.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WIA Tracing</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca540000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SYSTEM32\DCIMAN32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DCI Manager</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacac80000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SYSTEM32\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>69</ProcessIndex>
<ProcessId>10000</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957424930105</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>AdobeIPCBroker.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe&quot; &quot;-launchedbyvulcan&quot;</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>5.0.0.76</Version>
<Description>Adobe IPC Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0xbe0000</BaseAddress>
<Size>798720</Size>
<Path>C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe</Path>
<Version>5.0.0.76</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe IPC Broker</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>70</ProcessIndex>
<ProcessId>10064</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957636746019</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Adobe Spaces Helper.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe&quot; --type=renderer --no-sandbox --touch-events=disabled --lang=en-US --lang=ru --locales-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\locales\\&quot; --log-file=&quot;C:\Users\User\AppData\Roaming\Adobe\Adobe Photoshop CC 2017\Logs\debug.log&quot; --resources-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\\&quot; --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;8940.0.1405287427\319210639&quot; /prefetch:673131151</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ff6c2ef0000</BaseAddress>
<Size>1196032</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaa1110000</BaseAddress>
<Size>70823936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\libcef.dll</Path>
<Version>3.2526.1347.gcf20046</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SSPICLI.DLL</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>71</ProcessIndex>
<ProcessId>8596</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957641371503</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Adobe Spaces Helper.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe&quot; --type=renderer --no-sandbox --touch-events=disabled --lang=en-US --lang=ru --locales-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\locales\\&quot; --log-file=&quot;C:\Users\User\AppData\Roaming\Adobe\Adobe Photoshop CC 2017\Logs\debug.log&quot; --resources-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\\&quot; --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;8940.1.1139889345\75461215&quot; /prefetch:673131151</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ff6c2ef0000</BaseAddress>
<Size>1196032</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaa1110000</BaseAddress>
<Size>70823936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\libcef.dll</Path>
<Version>3.2526.1347.gcf20046</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SSPICLI.DLL</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>72</ProcessIndex>
<ProcessId>11172</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957658059215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; &quot;C:\Program Files (x86)\Common Files\Adobe\CEP\extensions\com.adobe.previewHD\PSLoader\loader.html&quot; 2ec98b7b-08f4-4716-915a-e20a700b24cb 8940 PHXS 18.0.1 com.adobe.preview.loader 1 &quot;C:\Program Files (x86)\Common Files\Adobe\CEP\extensions\com.adobe.previewHD&quot; &quot;Photoshop&quot; 16 WyItLWVuYWJsZS1ub2RlanMiXQ== ru_RU 4293980400 1</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>73</ProcessIndex>
<ProcessId>11216</ProcessId>
<ParentProcessId>11172</ParentProcessId>
<ParentProcessIndex>72</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957800622174</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=ru --log-file=&quot;C:\Users\User\AppData\Local\Temp\CEPHtmlEngine7-PHXS-18.0.1-com.adobe.preview.loader.log&quot; --log-severity=error --params_ppid=PHXS --params_ppversion=18.0.1 --params_extensionid=com.adobe.preview.loader --params_loglevel=1 --params_serverid=8940 --params_extensionuuid=2ec98b7b-08f4-4716-915a-e20a700b24cb --params_windowid=70742 --params_commandline=WyItLWVuYWJsZS1ub2RlanMiXQ== --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=11172 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;11172.0.296388529\1274093304&quot; /prefetch:673131151</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x6d990000</BaseAddress>
<Size>3055616</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\ffmpegsumo.dll</Path>
<Version>41.0.2272.104</Version>
<Company>The Chromium Authors</Company>
<Description>Chromium</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>74</ProcessIndex>
<ProcessId>10844</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958201141405</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\extensions\com.adobe.experimentation.extension\index.html&quot; e44c0384-b65f-4f05-a36a-c6092cb32d00 8940 PHXS 18.0.1 com.adobe.experimentation.extension 1 &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\extensions\com.adobe.experimentation.extension&quot; &quot;Photoshop&quot; 16 WyItLWVuYWJsZS1ub2RlanMiXQ== ru_RU 4293980400 1</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>75</ProcessIndex>
<ProcessId>9092</ProcessId>
<ParentProcessId>10844</ParentProcessId>
<ParentProcessIndex>74</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958208470288</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=ru --log-file=&quot;C:\Users\User\AppData\Local\Temp\CEPHtmlEngine7-PHXS-18.0.1-com.adobe.experimentation.extension.log&quot; --log-severity=error --params_ppid=PHXS --params_ppversion=18.0.1 --params_extensionid=com.adobe.experimentation.extension --params_loglevel=1 --params_serverid=8940 --params_extensionuuid=e44c0384-b65f-4f05-a36a-c6092cb32d00 --params_windowid=198892 --params_commandline=WyItLWVuYWJsZS1ub2RlanMiXQ== --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=10844 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;10844.0.379179099\270765323&quot; /prefetch:673131151</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x6d990000</BaseAddress>
<Size>3055616</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\ffmpegsumo.dll</Path>
<Version>41.0.2272.104</Version>
<Company>The Chromium Authors</Company>
<Description>Chromium</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>76</ProcessIndex>
<ProcessId>11496</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958406617238</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SearchUI.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe&quot; -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>Search and Cortana application</Description>
<modulelist>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ff79c3c0000</BaseAddress>
<Size>10706944</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Search and Cortana application</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\SYSTEM32\chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\SYSTEM32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4c70000</BaseAddress>
<Size>4874240</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab52c0000</BaseAddress>
<Size>2445312</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5840000</BaseAddress>
<Size>3108864</Size>
<Path>C:\Windows\System32\Speech_OneCore\Common\sapi_onecore.dll</Path>
<Version>5.3.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Speech API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5db0000</BaseAddress>
<Size>9781248</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9d50000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;CortanaApi.ProxyStub.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe770000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabefa0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\Cortana.Persona.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana.Persona</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac10b0000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\PersonaX.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PersonaX</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\SYSTEM32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3bf0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionMgr.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana Action Manager</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bb0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\windows.cortana.pal.desktop.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.PAL.Desktop</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7c50000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\BingConfigurationClient.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bing Configuration Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\SYSTEM32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>77</ProcessIndex>
<ProcessId>11408</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794962679173110</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>node.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\node.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\node.exe&quot; &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Generator-builtin&quot; --launchreason menu --menu crema-dummy-menu --photoshopVersion 18.0.1 -i \\.\pipe\36b615a8-a6c5-11e8-b291-8ffa7e69373b_i -o \\.\pipe\36b615a8-a6c5-11e8-b291-8ffa7e69373b_o -f &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Generator&quot; -f &quot;C:\Program Files\Common Files\Adobe\Plug-Ins\CC\Generator&quot;</CommandLine>
<CompanyName>Node.js</CompanyName>
<Version>4.3.1</Version>
<Description>Node.js: Server-side JavaScript</Description>
<modulelist>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ff6cbb20000</BaseAddress>
<Size>14237696</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\node.exe</Path>
<Version>4.3.1</Version>
<Company>Node.js</Company>
<Description>Node.js: Server-side JavaScript</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>78</ProcessIndex>
<ProcessId>12164</ProcessId>
<ParentProcessId>11408</ParentProcessId>
<ParentProcessIndex>77</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794962697229215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>conhost.exe</ProcessName>
<ImagePath>C:\Windows\system32\conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0x4</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffabe520000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SYSTEM32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.DLL</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>79</ProcessIndex>
<ProcessId>5612</ProcessId>
<ParentProcessId>904</ParentProcessId>
<ParentProcessIndex>22</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131794965205293998</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>dashost.exe</ProcessName>
<ImagePath>C:\Windows\system32\dashost.exe</ImagePath>
<CommandLine>dashost.exe {609e1ffd-7b4d-4dbc-a36f725917d81f2d}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Device Association Framework Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ff6559c0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\dashost.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Framework Provider Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabb1a0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\DAFWSD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF WSD Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabc970000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\dafupnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF UPnP Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>80</ProcessIndex>
<ProcessId>9720</ProcessId>
<ParentProcessId>9180</ParentProcessId>
<ParentProcessIndex>81</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794969418818027</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Windows10UpgraderApp.exe</ProcessName>
<ImagePath>C:\Windows10Upgrade\Windows10UpgraderApp.exe</ImagePath>
<CommandLine>&quot;C:\Windows10Upgrade\Windows10UpgraderApp.exe&quot;  /Install /ClientID Win10Upgrade:VNL:NHV18:{} /SkipEULA /PostEosUi</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>1.4.9200.22452</Version>
<Description>Помощник по обновлению Windows 10</Description>
<modulelist>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0xb30000</BaseAddress>
<Size>1875968</Size>
<Path>C:\Windows10Upgrade\Windows10UpgraderApp.exe</Path>
<Version>1.4.9200.22452</Version>
<Company>Microsoft Corporation</Company>
<Description>Помощник по обновлению Windows 10</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d6e0000</BaseAddress>
<Size>634880</Size>
<Path>C:\Windows\SysWOW64\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d780000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\SysWOW64\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d860000</BaseAddress>
<Size>1245184</Size>
<Path>C:\Windows\SysWOW64\MFC42u.dll</Path>
<Version>6.06.8063.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека MFCDLL - розничная версия</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6ded0000</BaseAddress>
<Size>630784</Size>
<Path>C:\Windows\SysWOW64\ODBC32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ODBC Driver Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfc0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfd0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SysWOW64\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e010000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows10Upgrade\Downloader.dll</Path>
<Version>1.4.9200.22452 (win8_ldr.180426-0600)</Version>
<Company>Microsoft Corporation</Company>
<Description>Downloader</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e050000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.DLL</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>82</ProcessIndex>
<ProcessId>8944</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795005508439638</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>fontdrvhost.exe</ProcessName>
<ImagePath>C:\Windows\system32\fontdrvhost.exe</ImagePath>
<CommandLine>&quot;fontdrvhost.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Usermode Font Driver Host</Description>
<modulelist>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ff654db0000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\system32\fontdrvhost.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Usermode Font Driver Host</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>83</ProcessIndex>
<ProcessId>6684</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795006053748558</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Microsoft.Photos.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe&quot; -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ff705e40000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bb10000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bc70000</BaseAddress>
<Size>3158016</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bf80000</BaseAddress>
<Size>2994176</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9c260000</BaseAddress>
<Size>20144128</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9d5a0000</BaseAddress>
<Size>29011968</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9fb20000</BaseAddress>
<Size>7950336</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.3_1.3.24201.0_x64__8wekyb3d8bbwe\SharedLibrary.dll</Path>
<Version></Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Shared Framework</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa03f0000</BaseAddress>
<Size>4546560</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\FaceSdkStoreWrapper.dll</Path>
<Version>16.425.0.0</Version>
<Company>Microsoft Corporation</Company>
<Description>FaceSdkStoreWrapper</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa0850000</BaseAddress>
<Size>2371584</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\MediaEngine.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab270000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\System32\Windows.AccountsControl.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Accounts Control</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\Windows.System.Diagnostics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Diagnostics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f60000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\CryptoWinRT.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto WinRT Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9270000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9b40000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x64__8wekyb3d8bbwe\mrt100_app.dll</Path>
<Version>1.4.24201.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabea30000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\Windows.Energy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Energy Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0fa0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1c70000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCOMP140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C/C++ OpenMP Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2c00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\clrcompression.dll</Path>
<Version>1.0.23123.00 built by: PROJECTKREL</Version>
<Company>Microsoft Corporation</Company>
<Description>ClrCompression</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SYSTEM32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\mrt100.dll</Path>
<Version>1.0.24120.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OleAut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>84</ProcessIndex>
<ProcessId>6208</ProcessId>
<ParentProcessId>12140</ParentProcessId>
<ParentProcessIndex>85</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795181740423780</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>OneDrive.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</ImagePath>
<CommandLine> /updateInstalled /background</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>18.131.0701.0007</Version>
<Description>Microsoft OneDrive</Description>
<modulelist>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x11f0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x55a0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSync.Resources.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\MSHTML.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6bab0000</BaseAddress>
<Size>4472832</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Widgets.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d210000</BaseAddress>
<Size>4993024</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Gui.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\Wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ce0000</BaseAddress>
<Size>1519616</Size>
<Path>C:\Windows\SysWOW64\wpc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека параметров родительского контроля</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70f00000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71200000</BaseAddress>
<Size>708608</Size>
<Path>C:\Windows\SysWOW64\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x712b0000</BaseAddress>
<Size>602112</Size>
<Path>C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71350000</BaseAddress>
<Size>2867200</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Quick.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71630000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x716b0000</BaseAddress>
<Size>1294336</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LIBEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x717f0000</BaseAddress>
<Size>2637824</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Qml.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71a80000</BaseAddress>
<Size>4796416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Core.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71f20000</BaseAddress>
<Size>6033408</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SyncEngine.DLL</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Sync Engine</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72530000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72550000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72810000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72820000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SysWOW64\MicrosoftAccountTokenProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Token Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72850000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\SysWOW64\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728b0000</BaseAddress>
<Size>135168</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncFAL.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDriveFile Sync FAL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\SysWOW64\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72bb0000</BaseAddress>
<Size>1105920</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\platforms\qwindows.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e90000</BaseAddress>
<Size>299008</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SSLEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ee0000</BaseAddress>
<Size>950272</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Network.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72fd0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\loadperf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Загрузка и выгрузка счетчиков производительности</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ff0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\pdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль поддержки данных производительности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73040000</BaseAddress>
<Size>253952</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5WinExtras.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73080000</BaseAddress>
<Size>880640</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ADAL.dll</Path>
<Version>1.0.2110.0526</Version>
<Company>Microsoft</Company>
<Description>ADAL.Native</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73160000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WSOCK32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73170000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SysWOW64\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x731d0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\WnsClientApi.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive WNS Client Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73240000</BaseAddress>
<Size>520192</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LogUploader.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive Sync LogUploader Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x732c0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncViews.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Qt Components</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73400000</BaseAddress>
<Size>159744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\UpdateRingSettings.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Ring Settings</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73430000</BaseAddress>
<Size>1748992</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncSessions.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>P2P Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x735e0000</BaseAddress>
<Size>671744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\RemoteAccess.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73690000</BaseAddress>
<Size>188416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Telemetry.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Telemetry Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ETWLog.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>ETW Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736d0000</BaseAddress>
<Size>3600384</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncClient.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Client</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73af0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LoggingPlatform.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Logging Platform</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73dc0000</BaseAddress>
<Size>1171456</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ucrtbase.dll</Path>
<Version>10.0.17134.12 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73fb0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\MSWSOCK.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74090000</BaseAddress>
<Size>462848</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\MSVCP140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\VCRUNTIME140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74220000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>86</ProcessIndex>
<ProcessId>6140</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795747339404666</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=764E64A4EA650A23B18EB059FF0B4B51 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=764E64A4EA650A23B18EB059FF0B4B51 --renderer-client-id=106 --mojo-platform-channel-handle=6612 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>87</ProcessIndex>
<ProcessId>11432</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755605761168</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=9DD318D38190D474A9A0F5AFD262A449 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=9DD318D38190D474A9A0F5AFD262A449 --renderer-client-id=109 --mojo-platform-channel-handle=4152 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>88</ProcessIndex>
<ProcessId>10384</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755746873891</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=7E669976FFDCEE94D9B90B02CADE1179 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E669976FFDCEE94D9B90B02CADE1179 --renderer-client-id=112 --mojo-platform-channel-handle=5412 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>89</ProcessIndex>
<ProcessId>10568</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755818164194</CreateTime>
<FinishTime>131795770840820338</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>explorer.exe</ProcessName>
<ImagePath>C:\Windows\explorer.exe</ImagePath>
<CommandLine>C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>90</ProcessIndex>
<ProcessId>6936</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795756360200321</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --renderer-client-id=116 --mojo-platform-channel-handle=4024 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>91</ProcessIndex>
<ProcessId>11356</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795756462509250</CreateTime>
<FinishTime>131795770879304196</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>explorer.exe</ProcessName>
<ImagePath>C:\Windows\explorer.exe</ImagePath>
<CommandLine>C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>92</ProcessIndex>
<ProcessId>9252</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795764376794664</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>wmiprvse.exe</ProcessName>
<ImagePath>C:\Windows\system32\wbem\wmiprvse.exe</ImagePath>
<CommandLine>C:\Windows\system32\wbem\wmiprvse.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Description>WMI Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ff7fdea0000</BaseAddress>
<Size>516096</Size>
<Path>C:\Windows\system32\wbem\wmiprvse.exe</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Provider Host</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffabee10000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770662992743</Timestamp>
<BaseAddress>0x7ffac1e20000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770663908408</Timestamp>
<BaseAddress>0x7ffac1f50000</BaseAddress>
<Size>471040</Size>
<Path>C:\Windows\System32\wbem\esscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770664479193</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770663594346</Timestamp>
<BaseAddress>0x7ffac7cc0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\wbem\wmiprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770664758405</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wmiclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770663902811</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>93</ProcessIndex>
<ProcessId>8764</ProcessId>
<ParentProcessId>360</ParentProcessId>
<ParentProcessIndex>26</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131795765999556420</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>AUDIODG.EXE</ProcessName>
<ImagePath>C:\Windows\system32\AUDIODG.EXE</ImagePath>
<CommandLine>C:\Windows\system32\AUDIODG.EXE 0x310</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Изоляция графов аудиоустройств Windows </Description>
<modulelist>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ff644450000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\system32\AUDIODG.EXE</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Изоляция графов аудиоустройств Windows </Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffab02b0000</BaseAddress>
<Size>1802240</Size>
<Path>C:\Windows\System32\WMALFXGFXDSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SysFx DSP</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffabc1a0000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\System32\audiokse.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Audio Ks Endpoint</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffabd210000</BaseAddress>
<Size>552960</Size>
<Path>C:\Windows\System32\audioeng.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Audio Engine</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>94</ProcessIndex>
<ProcessId>4580</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795769397390596</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchProtocolHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchProtocolHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchProtocolHost.exe&quot; Global\UsGthrFltPipeMssGthrPipe285_ Global\UsGthrCtrlFltPipeMssGthrPipe285 1 -2147483646 &quot;Software\Microsoft\Windows Search&quot; &quot;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)&quot; &quot;C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc&quot; &quot;DownLevelDaemon&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Protocol Host</Description>
<modulelist>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ff71ad80000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\system32\SearchProtocolHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Protocol Host</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\system32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\mssph.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик протоколов поиска Microsoft</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\Msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>95</ProcessIndex>
<ProcessId>8304</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795770292311800</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k wsappx</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>96</ProcessIndex>
<ProcessId>10360</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795770393041927</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchFilterHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchFilterHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchFilterHost.exe&quot; 0 708 712 720 8192 716 </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Filter Host</Description>
<modulelist>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ff68a750000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\SearchFilterHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Filter Host</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffab8fe0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Program Files\Common Files\Microsoft Shared\Filters\offfiltx.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Office Open XML Format Filter</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\query.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека служебной программы индексирования содержимого</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>97</ProcessIndex>
<ProcessId>84</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795771095730473</CreateTime>
<FinishTime>131795771129561094</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MCLauncher.exe</ProcessName>
<ImagePath>C:\Users\User\Downloads\MCLauncher.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\Downloads\MCLauncher.exe&quot; </CommandLine>
<CompanyName></CompanyName>
<Version>1.0</Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795771100052569</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>2830336</Size>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Version>1.0</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771107990028</Timestamp>
<BaseAddress>0x6c0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771107990477</Timestamp>
<BaseAddress>0x7d0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771107980658</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795771107981450</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795771107993070</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795771113736952</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795771108602128</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771115551275</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795771108103192</Timestamp>
<BaseAddress>0x66680000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771108128503</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771108053759</Timestamp>
<BaseAddress>0x6b830000</BaseAddress>
<Size>2584576</Size>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795771110329320</Timestamp>
<BaseAddress>0x6d180000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795771112527946</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795771108111223</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795771113764461</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795771113778189</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771113752450</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795771113882758</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795771114479545</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771113871825</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795771113645033</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771109643878</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795771113687519</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795771108120411</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795771109630638</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795771111790290</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795771111779368</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795771110706989</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795771108094068</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795771108018712</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795771108065537</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795771108064515</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771108208686</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795771108062855</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771108062126</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795771108070762</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795771108063667</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795771108058408</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771113741177</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795771108054879</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795771108071560</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795771114505987</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795771110692760</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795771108068017</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795771113571954</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795771107999750</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771108066925</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795771113570641</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795771108068870</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795771108061351</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795771108069823</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795771108059372</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795771108075237</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795771108056691</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795771108072455</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795771108055879</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771108066224</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795771108074059</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771108073333</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795771110173939</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795771108057591</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771112512757</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795771108060378</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795771100053240</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795771100052962</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>98</ProcessIndex>
<ProcessId>6080</ProcessId>
<ParentProcessId>84</ParentProcessId>
<ParentProcessIndex>97</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795771125310655</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MCLauncher.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe&quot; </CommandLine>
<CompanyName></CompanyName>
<Version>1.0</Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795771127806606</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>2830336</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Version>1.0</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771129292604</Timestamp>
<BaseAddress>0x750000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771335510731</Timestamp>
<BaseAddress>0x11000000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771334241016</Timestamp>
<BaseAddress>0x12000000</BaseAddress>
<Size>360448</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771129285523</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795771129286235</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795771129295328</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795771135408057</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795771129575672</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129398434</Timestamp>
<BaseAddress>0x66680000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771136825814</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795771129423112</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771129349562</Timestamp>
<BaseAddress>0x6b830000</BaseAddress>
<Size>2584576</Size>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795771329638947</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795771329610149</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795771329592759</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795771136045859</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795771131298623</Timestamp>
<BaseAddress>0x6d180000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795771136082794</Timestamp>
<BaseAddress>0x6dca0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Script Runtime</Description>
</module>
<module>
<Timestamp>131795771133718253</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795771129406131</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795771329618480</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795771329601483</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795771336447829</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771135435621</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795771135446667</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771136073867</Timestamp>
<BaseAddress>0x70e90000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Script Host Runtime Library</Description>
</module>
<module>
<Timestamp>131795771135423397</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795771135552456</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795771136181434</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771328759427</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771135541570</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795771347140137</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795771347110306</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795771135314174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771347090516</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795771347075776</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795771328179609</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795771130913562</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795771135359123</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795771129415027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795771130899582</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795771133098293</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795771132990161</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795771131765102</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795771129389543</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795771129317462</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795771129360685</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795771129360034</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771129496759</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795771129358136</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129357408</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795771129365891</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795771129359203</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795771129353720</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771135412052</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795771129350362</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795771129366695</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795771136054082</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795771131750596</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795771129363162</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795771328737550</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795771135228888</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795771129301509</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771129362062</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795771135227735</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795771129363985</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795771129356607</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795771129364960</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795771129354665</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795771129370252</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795771129352041</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795771129367584</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795771129351257</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771129361361</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795771129369244</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129368545</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795771131168008</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795771129352931</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771133704572</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795771129355632</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795771347076821</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795771127807387</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795771127807116</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>99</ProcessIndex>
<ProcessId>12576</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795771145349737</CreateTime>
<FinishTime>131795771235538758</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795771184507262</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795771185288430</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795771185308436</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771185208723</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795771184866545</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795771185150589</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771184523591</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771184526373</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795771185149095</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795771185289336</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795771184515216</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771185310190</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771185309450</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795771184525473</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795771184867324</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795771184872618</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795771184514352</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771185149852</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771185162968</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795771185148270</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771184524725</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795771185124568</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795771184507503</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>100</ProcessIndex>
<ProcessId>11424</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795771175195605</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>backgroundTaskHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\backgroundTaskHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\backgroundTaskHost.exe&quot; -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Background Task Host</Description>
<modulelist>
<module>
<Timestamp>131795771215003918</Timestamp>
<BaseAddress>0x7ff7e0340000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\backgroundTaskHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Task Host</Description>
</module>
<module>
<Timestamp>131795771218915398</Timestamp>
<BaseAddress>0x7ffab52c0000</BaseAddress>
<Size>2445312</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771248257542</Timestamp>
<BaseAddress>0x7ffab5db0000</BaseAddress>
<Size>9781248</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771221125701</Timestamp>
<BaseAddress>0x7ffab9d50000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771219014731</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795771244982867</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795771253593996</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795771249779530</Timestamp>
<BaseAddress>0x7ffabe770000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771220596574</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795771221984040</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795771229903710</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795771222450040</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795771218944309</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795771217261903</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795771221184651</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795771219025520</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795771248269029</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795771221208674</Timestamp>
<BaseAddress>0x7ffac3bf0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionMgr.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana Action Manager</Description>
</module>
<module>
<Timestamp>131795771244919374</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795771228411342</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795771228399176</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795771238266123</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795771244908192</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795771219005372</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795771218728294</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795771219113271</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795771217463389</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795771229000770</Timestamp>
<BaseAddress>0x7ffac6bb0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\Windows.Cortana.PAL.Desktop.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.PAL.Desktop</Description>
</module>
<module>
<Timestamp>131795771217062375</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795771218870257</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795771221134703</Timestamp>
<BaseAddress>0x7ffac7c50000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\BingConfigurationClient.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bing Configuration Client DLL</Description>
</module>
<module>
<Timestamp>131795771250869876</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795771215247819</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795771246630966</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771218005942</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795771215028077</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795771218142921</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795771218992988</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795771215190452</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795771219041691</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795771248177767</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795771219101100</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795771219186292</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795771219053691</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795771219065792</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771215202412</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795771215165891</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795771228948589</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795771217446746</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795771219027312</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795771216016613</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771215052508</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771215054137</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795771216015001</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795771215602268</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795771228947467</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795771215010911</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771219026473</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795771218982293</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771218945076</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795771215053234</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795771215050566</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795771215009974</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771216015829</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771219028093</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795771216029532</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795771216013945</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771215051746</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795771218916542</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795771251394640</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795771228949614</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795771215191449</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795771215004228</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>101</ProcessIndex>
<ProcessId>12976</ProcessId>
<ParentProcessId>6340</ParentProcessId>
<ParentProcessIndex>50</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795771282376077</CreateTime>
<FinishTime>131795771284328494</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>QHToasts.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHToasts.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHToasts.exe&quot; /riskprompt</CommandLine>
<CompanyName></CompanyName>
<Version>8,6,0,1000</Version>
<Description>Windows 8 Toast Notification</Description>
<modulelist>
<module>
<Timestamp>131795771283557190</Timestamp>
<BaseAddress>0x700000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771282475058</Timestamp>
<BaseAddress>0xae0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHToasts.exe</Path>
<Version>8,6,0,1000</Version>
<Company></Company>
<Description>Windows 8 Toast Notification</Description>
</module>
<module>
<Timestamp>131795771283550335</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795771283551019</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795771283559644</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795771283619746</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795771283577556</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795771283576079</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771283598798</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795771283574107</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771283573256</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795771283589533</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795771283575215</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795771283582521</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771283584139</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795771283590270</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795771283587788</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795771283565831</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771283579022</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795771283583432</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795771283586973</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795771283588610</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795771283585111</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795771283580806</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795771283591137</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795771283580085</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771283578315</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795771283593675</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771283593010</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795771283591957</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795771283581642</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771283586078</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795771282475651</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795771282475383</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>1</ProcessIndex>
<ProcessId>11372</ProcessId>
<ParentProcessId>10560</ParentProcessId>
<ParentProcessIndex>2</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770632346846</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon64.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Temp\Procmon64.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Temp\Procmon64.exe&quot;  /originalpath &quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot;</CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>2</ProcessIndex>
<ProcessId>10560</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770594566098</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon.exe</ProcessName>
<ImagePath>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot; </CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x1000000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x62530000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\RICHED20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cd0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72520000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\Riched32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wrapper Dll for Richedit 1.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>3</ProcessIndex>
<ProcessId>4048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765778109600457</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchIndexer.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchIndexer.exe</ImagePath>
<CommandLine>C:\Windows\system32\SearchIndexer.exe /Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Индексатор службы Microsoft Windows Search</Description>
<modulelist>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ff63db40000</BaseAddress>
<Size>929792</Size>
<Path>C:\Windows\system32\SearchIndexer.exe</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индексатор службы Microsoft Windows Search</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\MSSRCH.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabd990000</BaseAddress>
<Size>720896</Size>
<Path>C:\Windows\system32\ElsLad.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ELS Language Detection</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\Msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>4</ProcessIndex>
<ProcessId>580</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776275984299</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>services.exe</ProcessName>
<ImagePath>C:\Windows\system32\services.exe</ImagePath>
<CommandLine>C:\Windows\system32\services.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Приложение служб и контроллеров</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>6</ProcessIndex>
<ProcessId>664</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776282506625</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k DcomLaunch</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc6a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\SebBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; SEB Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc7e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\SmartCardBackgroundPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartCardBackgroundPolicy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8c0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\CbtBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; CBT Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8d0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\ACPBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; ACP Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc900000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BackgroundMediaPolicy.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Background Media Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\RmClient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca740000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\DAB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL брокера активности компьютера</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacabd0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\OnDemandBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OnDemandBrokerClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacae70000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\systemeventsbrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер системных событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacafc0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy RM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb010000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SYSTEM32\psmserviceexthost.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager PSM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb390000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\psmsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process State Manager (PSM) Service</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb4f0000</BaseAddress>
<Size>794624</Size>
<Path>c:\windows\system32\bisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба инфраструктуры фоновых задач</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb720000</BaseAddress>
<Size>344064</Size>
<Path>c:\windows\system32\mintdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>c:\windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb820000</BaseAddress>
<Size>712704</Size>
<Path>C:\Windows\SYSTEM32\tdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8d0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\umpoext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения службы пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8f0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\umpo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb940000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\umpnpmgr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский режим службы самонастройки (Plug-and-Play)</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>7</ProcessIndex>
<ProcessId>884</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776292813936</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9230000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\bluetoothapis.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Usermode Api host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9580000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\BthRadioMedia.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab95a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WlanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wlan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaba920000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\rmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Radio Manager API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabae80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\NfcRadioMedia.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NFC Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabb8a0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\XboxGipRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Xbox GIP Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc0e0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\WwanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wwan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac78c0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\shacct.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Classes</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7f80000</BaseAddress>
<Size>208896</Size>
<Path>c:\windows\system32\wscsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8490000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\dhcpcore6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8c90000</BaseAddress>
<Size>385024</Size>
<Path>c:\windows\system32\dhcpcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>c:\windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac9c30000</BaseAddress>
<Size>1732608</Size>
<Path>c:\windows\system32\wevtsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба протоколирования событий</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca2a0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\timebrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер событий времени</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca330000</BaseAddress>
<Size>36864</Size>
<Path>c:\windows\system32\nrpsrv.DLL</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Name Resolution Proxy (NRP) RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4d0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lmhsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб транспорта TCPIP NetBios</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>8</ProcessIndex>
<ProcessId>0</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:00000000</AuthenticationId>
<CreateTime>131765775874898587</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>4294967295</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity></Integrity>
<Owner></Owner>
<ProcessName>Idle</ProcessName>
<ImagePath>Idle</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>9</ProcessIndex>
<ProcessId>4</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775907178738</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>System</ProcessName>
<ImagePath>System</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b6e00000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\System32\win32kfull.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Win32k Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7190000</BaseAddress>
<Size>1576960</Size>
<Path>C:\Windows\System32\win32kbase.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Базовый драйвер ядра Win32k</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7320000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\TSDDD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Framebuffer Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7330000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\cdd.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Canonical Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b74a0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\win32k.sys</Path>
<Version>10.0.14393.594 (rs1_release_inmarket.161213-1754)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Multi-User Win32 Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80278934000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\kd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Kernel Debugger</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80279678000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92e00000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\ksecdd.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ee0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\cmimcext.sys</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Configuration Manager Initial Configuration Extension Host Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ef0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\ntosext.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTOS extension host driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92fa0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\drivers\cng.sys</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Cryptography, Next Generation</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93040000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\system32\drivers\Wdf01000.sys</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения платформы драйвера режима ядра</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93120000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\drivers\WDFLDR.SYS</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Mode Driver Framework Loader</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93140000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\Drivers\acpiex.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPIEx Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93170000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\Drivers\WppRecorder.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WPP Trace Recorder</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93180000</BaseAddress>
<Size>733184</Size>
<Path>C:\Windows\System32\drivers\ACPI.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPI драйвер для NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93240000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\WMILIB.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMILIB WMI support library Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93260000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\intelpep.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Power Engine Plugin</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93280000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\drivers\WindowsTrustedRT.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932a0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Service Proxy Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\pcw.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Performance Counters for Windows Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932d0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\msisadrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ISA Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932e0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\isapnp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер шины PNP ISA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932f0000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\drivers\pci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Plug and Play PCI-перечислитель</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93350000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\vdrvroot.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Drive Root Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93370000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\drivers\pdc.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Power Dependency Coordinator Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933a0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\CEA.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation Kernel Mode Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\partmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Partition driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\nvraid.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) RAID Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93420000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\CLASSPNP.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI Class System Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93490000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\vmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Дочерний драйвер шины виртуальной машины Microsoft Hyper-V</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d934c0000</BaseAddress>
<Size>1212416</Size>
<Path>C:\Windows\System32\drivers\NDIS.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS (Network Driver Interface Specification)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d935f0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\drivers\NETIO.SYS</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network I/O Subsystem</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93670000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\hvsocket.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Hyper-V Socket Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\vmbkmcl.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V VMBus KMCL</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\winhv.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Hypervisor Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\pciide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Generic PCI IDE Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936e0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\PCIIDEX.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PCI IDE Bus Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93700000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\drivers\spaceport.sys</Path>
<Version>10.0.14393.1914 (rs1_release_inmarket.171117-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Spaces Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937a0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\intelide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel PCI IDE Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937b0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\volmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937d0000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\drivers\volmgrx.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер расширения диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93830000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\drivers\mountmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер точек подключения</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93850000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\nvstor.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) Sata Performance Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\drivers\storport.sys</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Storage Port Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93910000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\atapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI IDE Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93920000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\System32\drivers\ataport.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93960000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\storahci.sys</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS AHCI Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93990000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\stornvme.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft NVM Express Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\drivers\EhStorClass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enhanced Storage Class driver for IEEE 1667 devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\fileinfo.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FileInfo Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939f0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\Drivers\Wof.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр оверлея Windows</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93a80000</BaseAddress>
<Size>2297856</Size>
<Path>C:\Windows\System32\Drivers\NTFS.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер файловой системы NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\storvsc.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage VSC Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cd0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\Drivers\Fs_Rec.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>File System Recognizer Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93d10000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\System32\drivers\USBPORT.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта USB 1.1 и 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93db0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\mcupdate_GenuineIntel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Microcode Update Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93e50000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\System32\drivers\CLFS.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Common Log File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ec0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\tm.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Transaction Manager Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ef0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\PSHED.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер аппаратных ошибок, специфичных для платформы</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f10000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\BOOTVID.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>VGA Boot Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f20000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\FLTMGR.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер фильтров файловых систем Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\drivers\msrpc.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Remote Procedure Call Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94000000</BaseAddress>
<Size>430080</Size>
<Path>C:\Windows\System32\drivers\fwpkclnt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FWP/IPsec Kernel-Mode API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94070000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\wfplwfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WFP NDIS 6.30 Lightweight Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d940b0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DRIVERS\fvevol.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BitLocker Drive Encryption Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94160000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\volume.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94170000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\System32\drivers\volsnap.sys</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume Shadow Copy driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d941e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\scmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Class Memory Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\drivers\rdyboost.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ReadyBoost Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94250000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\Drivers\mup.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер поставщика множественных UNC</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94280000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\drivers\iorate.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>I/O rate control Filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942a0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\disk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PnP Disk Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942e0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\crashdmp.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crash Dump Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d943c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\drivers\cdrom.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI CD-ROM Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94400000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\drivers\filecrypt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows sandboxing and encryption filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94420000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\tbs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Export driver for kernel mode TPM API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94430000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Null.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NULL Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94440000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Beep.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BEEP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94450000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\BasicDisplay.sys</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94470000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\watchdog.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Watchdog Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94490000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\System32\drivers\dxgkrnl.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Kernel</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\BasicRender.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Render Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\Npfs.SYS</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPFS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94700000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\DRIVERS\tdx.sys</Path>
<Version>10.0.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDI Translation Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94740000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\DRIVERS\netbt.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>MBT Transport driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94790000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\drivers\afd.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер дополнительных функций для Winsock</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94830000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\vwififlt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual WiFi Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94850000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\pacer.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Планировщик пакетов QoS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\drivers\netbios.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetBIOS interface driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d948a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\rdbss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер подсистемы буферизации перенаправленного диска</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94920000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\drivers\csc.sys</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Client Side Caching Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\nsiproxy.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\npsvctrig.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Named pipe service triggers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\gpuenergydrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GPU Energy Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a00000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Drivers\dfsc.sys</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DFS Namespace Client Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a50000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\DRIVERS\ahcache.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Compatibility Cache</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a90000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-Transport Composite Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\kdnic.sys</Path>
<Version>6.01.00.0000 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Kernel Debugger Network Miniport</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ac0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\drivers\umbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User-Mode Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ae0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\i8042prt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта i8042</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b10000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\drivers\kbdclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса клавиатуры</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b30000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\mouclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса мыши</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b80000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\HDAudBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ba0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\drivers\portcls.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Port Class (Class Driver for Port/Miniport Devices)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c10000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\drmk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trusted Audio Drivers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c40000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\drivers\ks.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel CSA Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cb0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\usbohci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OHCI USB Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\CmBatt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Control Method Battery Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cd0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\BATTC.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Class Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ce0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\intelppm.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Processor Device Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d10000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\NdisVirtualBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечислитель виртуальных сетевых адаптеров (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d20000</BaseAddress>
<Size>2588672</Size>
<Path>C:\Windows\System32\drivers\tcpip.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fa0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\swenum.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Plug and Play Software Device Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fb0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\rdpbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft RDP Bus Device driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95200000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\DRIVERS\udfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UDF File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95280000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\Drivers\dump_diskdump.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d952c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\Drivers\dump_storahci.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95310000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\Drivers\dump_dumpfve.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95330000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\system32\drivers\HTTP.sys</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Стек протокола HTTP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95450000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\drivers\WudfPf.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - User-mode Driver Framework Platform Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95470000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\DRIVERS\bowser.sys</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Lan Manager Datagram Receiver Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d954a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT SMB Minirdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95520000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\mpsdrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Protection Service Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95540000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb20.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB 2.0 Redirector</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95580000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\DRIVERS\srvnet.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Network driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d955d0000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\System32\DRIVERS\srv2.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер сервера SMB 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95690000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb10.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB Downlevel SubRdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d956e0000</BaseAddress>
<Size>573440</Size>
<Path>C:\Windows\System32\DRIVERS\srv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95770000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\tcpipreg.sys</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>TCP/IP Registry Compatibility Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95860000</BaseAddress>
<Size>684032</Size>
<Path>C:\Windows\System32\drivers\dxgmms2.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics MMS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95910000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\luafv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра виртуализации файлов LUA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95960000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\storqosflt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр качества обслуживания хранилища</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95980000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\registry.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Registry Containment Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959a0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\drivers\lltdio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Mapper I/O Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959c0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\drivers\mslldp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер протокола Microsoft LLDP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\rspndr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Responder Driver for NDIS 6</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95ae0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\USBD.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Universal Serial Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95af0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\DRIVERS\HdAudio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Function Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95b60000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\ksthunk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Streaming WOW Thunk Service</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95bc0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\HIDPARSE.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hid Parsing Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97020000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\Drivers\360AntiHacker64.sys</Path>
<Version>1.0.0.1149</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络防黑模块</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97060000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\DRIVERS\360AvFlt.sys</Path>
<Version>1.1.0.1056</Version>
<Company>360.cn</Company>
<Description>360杀毒 文件监控驱动</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97080000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\DRIVERS\BAPIDRV64.sys</Path>
<Version>2.0.0.1221</Version>
<Company>360.cn</Company>
<Description>BAPIDRV</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d970c0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\drivers\360netmon.sys</Path>
<Version>2.1.11.5195</Version>
<Company>360.cn</Company>
<Description>360netmon</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97120000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\system32\DRIVERS\360Box64.sys</Path>
<Version>2.1.0.1253</Version>
<Company>360.cn</Company>
<Description>360Box64</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97180000</BaseAddress>
<Size>811008</Size>
<Path>C:\Windows\system32\DRIVERS\360FsFlt.sys</Path>
<Version>6.9.1.1751</Version>
<Company>360.cn</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97330000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\hidusb.sys</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>USB Miniport Driver for Input Devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97350000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\HIDCLASS.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека классов HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97380000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\mouhid.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра мыши HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97390000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\rassstp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS SSTP Miniport Call Manager</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973b0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\DRIVERS\NDProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\drivers\AgileVpn.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер вызовов минипорта RAS Agile VPN</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97420000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\drivers\rasl2tp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS L2TP mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97460000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\raspptp.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Peer-to-Peer Tunneling Protocol</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974a0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\raspppoe.sys</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS PPPoE mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\DRIVERS\ndistapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS 3.0 connection wrapper driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974d0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\drivers\ndiswan.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS PPP Framing Driver (Strong Encryption)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97510000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\DRIVERS\wanarp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS Remote Access and Routing ARP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97550000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\E1G6032E.sys</Path>
<Version>8.4.13.0 built by: WinDDK</Version>
<Company>Intel Corporation</Company>
<Description>Intel(R) PRO/1000 Adapter NDIS 6 deserialized driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97580000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\tunnel.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер интерфейса туннеля (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97600000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\Drivers\PROCMON24.SYS</Path>
<Version>3.10</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97a60000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\system32\drivers\peauth.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Protected Environment Authentication and Authorization Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b30000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\Ndu.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Network Data Usage Monitoring Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b60000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\drivers\mmcss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMCSS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97bb0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\condrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Driver</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>10</ProcessIndex>
<ProcessId>320</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775908989732</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>smss.exe</ProcessName>
<ImagePath>C:\Windows\System32\smss.exe</ImagePath>
<CommandLine>\SystemRoot\System32\smss.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер сеанса  Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>11</ProcessIndex>
<ProcessId>3108</ProcessId>
<ParentProcessId>3092</ParentProcessId>
<ParentProcessIndex>12</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777624392598</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Explorer.EXE</ProcessName>
<ImagePath>C:\Windows\Explorer.EXE</ImagePath>
<CommandLine>C:\Windows\Explorer.EXE</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x31b0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5db0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Program Files\Uninstall Tool\utshellext.dll</Path>
<Version>1.1.0.15</Version>
<Company>CrystalIDEA Software</Company>
<Description>Uninstall Tool Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x81a0000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\MICROS~1\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x8cb0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5bf70000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_08e394a1a83e212f\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\Notepad++\NppShell_06.dll</Path>
<Version>0.1</Version>
<Company></Company>
<Description>ShellHandler for Notepad++ (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\Explorer.EXE</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2093056</Size>
<Path>C:\Windows\system32\wpdshext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки для переносных устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab350000</BaseAddress>
<Size>1683456</Size>
<Path>C:\Windows\System32\comsvcs.dll</Path>
<Version>2001.12.10941.16384 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Services</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab4f0000</BaseAddress>
<Size>1400832</Size>
<Path>C:\Windows\system32\connect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Мастера подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab650000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\system32\rasgcw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Страницы мастера RAS</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\System32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\system32\ieframe.DLL</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0df0000</BaseAddress>
<Size>1626112</Size>
<Path>C:\Windows\SYSTEM32\d3d9.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 9 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0f80000</BaseAddress>
<Size>1777664</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoViewer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Просмотр фотографий Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab27c0000</BaseAddress>
<Size>516096</Size>
<Path>C:\Windows\System32\imapi2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>IMAPI версии 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2840000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\bthprops.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложение панели управления Bluetooth</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2880000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\cscobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Внутрипроцессный COM-объект используемый клиентами CSC API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab29a0000</BaseAddress>
<Size>1912832</Size>
<Path>C:\Windows\System32\pnidui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Значок сетевой системы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2b80000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\system32\SettingMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Change Monitor</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2bc0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\PortableDeviceTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device (Parameter) Types Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab34f0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\System32\Actioncenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5120000</BaseAddress>
<Size>1691648</Size>
<Path>C:\Windows\system32\BatMeter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Meter Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\MsftEdit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7e40000</BaseAddress>
<Size>3420160</Size>
<Path>C:\Windows\System32\SyncCenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр синхронизации Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\system32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\system32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab99b0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\dxp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки компонента Device Stage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9ba0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\SYSTEM32\searchfolder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SearchFolder</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabac60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\EhStorAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Enhanced Storage API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae20000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msiltcfg.dll</Path>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer Configuration API Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaea0000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\system32\SHDOCVW.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\SYSTEM32\settingsynccore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SYSTEM32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SYSTEM32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd3c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\InputSwitch.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переключатель ввода Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd670000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\framedynos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI SDK Provider Framework</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd6c0000</BaseAddress>
<Size>1306624</Size>
<Path>C:\Windows\System32\werconcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PRS CPL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd800000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\NPSMDesktopProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Библиотека DLL локального поставщика рабочего стола NPSM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabda60000</BaseAddress>
<Size>1241088</Size>
<Path>C:\Windows\System32\wscui.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdeb0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\wpdshserviceobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device Shell Service Object</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabded0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\stobject.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Объект службы оболочки Systray</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe470000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\wscinterop.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Health Center WSC Interop</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe580000</BaseAddress>
<Size>831488</Size>
<Path>C:\Program Files (x86)\360\Total Security\MenuEx64.dll</Path>
<Version>9, 6, 0, 1001</Version>
<Company></Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe650000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\system32\zipfldr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сжатые ZIP-папки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9a0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\Syncreg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Synchronization Framework Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\system32\NetworkExplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0b0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\playtomenu.dll</Path>
<Version>12.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека меню функции &quot;Передать на устройство&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\System32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf590000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\syncui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Портфель Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfba0000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\WSCAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\MICROS~1\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b40000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\dlnashext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLNA Namespace DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\srchadmin.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры индексирования</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0f60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SYSTEM32\CHARTV.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Chart View</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1cc0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.Sockets.PushEnabledApplication DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac27a0000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.111.0603.0006\amd64\FileSyncShell64.dll</Path>
<Version>18.111.0603.0006</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac32e0000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\twext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Свойства: Предыдущие версии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3350000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\OLEACCHOOKS.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Event Hooks Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\dsreg.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5140000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\AboveLockAppHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AboveLockAppHost</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5190000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\NotificationController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5570000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\system32\twinui.pcshell.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Twinui.PCShell</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac55d0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\windows.immersiveshell.serviceprovider.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.ImmersiveShell.ServiceProvider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\system32\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5c70000</BaseAddress>
<Size>65536</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoBase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Base Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6650000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\npsm.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPSM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac78f0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\hgcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Панель управления домашней группы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d40000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\SYNCENG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Briefcase Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d90000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\SYSTEM32\SndVolSSO.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Громкость SCA </Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7f50000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\acppage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека расширений для вкладки &quot;Совместимость&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\SYSTEM32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795773562346782</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\ploptin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Prelaunch OptIn</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ea0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\hcproviders.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщики компонента &quot;Центр безопасности и обслуживания&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca190000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\WorkFoldersShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки рабочих папок (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac80000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SYSTEM32\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>13</ProcessIndex>
<ProcessId>404</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776186257169</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>15</ProcessIndex>
<ProcessId>468</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776223665667</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>17</ProcessIndex>
<ProcessId>484</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226419105</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>wininit.exe</ProcessName>
<ImagePath>C:\Windows\system32\wininit.exe</ImagePath>
<CommandLine>wininit.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Автозагрузка приложений Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>18</ProcessIndex>
<ProcessId>520</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226825613</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>winlogon.exe</ProcessName>
<ImagePath>C:\Windows\system32\winlogon.exe</ImagePath>
<CommandLine>winlogon.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Программа входа в систему Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ff7b5570000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\winlogon.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа входа в систему Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaee0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\dwminit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMInit</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacafa0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\UXINIT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows User Experience Session Initialization Dll</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>19</ProcessIndex>
<ProcessId>588</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776277547408</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>lsass.exe</ProcessName>
<ImagePath>C:\Windows\system32\lsass.exe</ImagePath>
<CommandLine>C:\Windows\system32\lsass.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Description>Local Security Authority Process</Description>
<modulelist>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x222e3610000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\msprivs.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переводы привилегий Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ff6b2d20000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\lsass.exe</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Security Authority Process</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffab9170000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\vaultsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба диспетчера учетных данных</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf170000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\hmkd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows HMAC Key Derivation API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf190000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\ngcpopkeysrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Passport Proof-of-possession Key Service</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\keyiso.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба изоляции ключей CNG</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SYSTEM32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf270000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SecureTimeAggregator.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Secure Time Aggregator</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb9b0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\scecli.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент редактора конфигураций безопасности</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\SspiSrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA SSPI RPC interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\dpapisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DPAPI Server</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbad0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\efslsaext.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA extension for EFS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbb70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wdigest.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Digest Access</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc00000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\MicrosoftAccountCloudAP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MicrosoftAccount Cloud AP Plugin</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc50000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\cloudAP.DLL</Path>
<Version>10.0.14393.1358 (rs1_release.170602-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cloud AP Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbcb0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\system32\pku2u.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pku2u Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd00000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\tspkg.DLL</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Web Service Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe30000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\gmsaclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;gmsaclient.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe60000</BaseAddress>
<Size>843776</Size>
<Path>C:\Windows\system32\netlogon.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека службы Net Logon</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc030000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\KerbClientShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kerberos Client Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc180000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\negoexts.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NegoExtender Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\JOINUTIL.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\netprovfw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Provisioning Service Framework DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc260000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\SYSTEM32\samsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сервера диспетчера учетных записей</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc380000</BaseAddress>
<Size>1527808</Size>
<Path>C:\Windows\system32\lsasrv.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера LSA</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>20</ProcessIndex>
<ProcessId>704</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776284978539</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k RPCSS</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8250000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\wshhyperv.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V Winsock2 Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6a0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\RpcRtRemote.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote RPC Extension</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\rpcepmap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сопоставитель конечных точек RPC
</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>21</ProcessIndex>
<ProcessId>808</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0000c8d4</AuthenticationId>
<CreateTime>131765776288401882</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>Window Manager\DWM-1</Owner>
<ProcessName>dwm.exe</ProcessName>
<ImagePath>C:\Windows\system32\dwm.exe</ImagePath>
<CommandLine>&quot;dwm.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер окон рабочего стола</Description>
<modulelist>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ff683990000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\dwm.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\system32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7b70000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\System32\Windows.Gaming.Input.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Gaming Input API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\avrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9a30000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SYSTEM32\ism32k.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca110000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\dwmghost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMGhost</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca8d0000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\system32\dwmcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека ядра Microsoft DWM</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacac90000</BaseAddress>
<Size>856064</Size>
<Path>C:\Windows\SYSTEM32\udwm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\dwmredir.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компонент перенаправления диспетчера окон рабочего стола Microsoft</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>22</ProcessIndex>
<ProcessId>904</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776293087855</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x259b0640000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\SFC.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab830000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\netman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>c:\windows\system32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>c:\windows\system32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab1260000</BaseAddress>
<Size>10350592</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll</Path>
<Version>4.7.2117.0 built by: NET47REL1LAST</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Common Language Runtime - WorkStation</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>c:\windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabfa00000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\SYSTEM32\MSVCR120_CLR0400.dll</Path>
<Version>12.00.52519.0 built by: VSWINSERVICING</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\MSI.DLL</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0fc0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\spp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих точек защиты Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1010000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\system32\MSCOREE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac10f0000</BaseAddress>
<Size>421888</Size>
<Path>c:\windows\system32\storsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы хранения</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1240000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll</Path>
<Version>4.7.2623.0 built by: NET471REL1LAST_C</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2420000</BaseAddress>
<Size>466944</Size>
<Path>c:\windows\system32\das.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сопоставления устройств</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac41c0000</BaseAddress>
<Size>139264</Size>
<Path>c:\windows\system32\trkwks.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент отслеживания изменившихся связей</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4650000</BaseAddress>
<Size>516096</Size>
<Path>c:\windows\system32\pcasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба помощника по совместимости программ</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Assembly manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b50000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\dssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы NT для службы совместного доступа к данным</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6120000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\sysmain.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост службы Superfetch</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b10000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\SYSTEM32\WUDFPlatform.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - библиотека платформ пользовательского режима</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b50000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\wudfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation (WDF) - служба среды выполнения платформы драйвера режима пользователя</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9800000</BaseAddress>
<Size>376832</Size>
<Path>c:\windows\system32\audioendpointbuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство построения конечных точек Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9de0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\portabledeviceconnectapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Portable Device Connection API Components</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SYSTEM32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca2d0000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\ncbservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Посредник подключений к сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>c:\windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca710000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\pcadm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Diagnostic Module</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\system32\SXS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>c:\windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>23</ProcessIndex>
<ProcessId>96</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776304995849</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2510000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\energyprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2580000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\ncuprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Connectivity Statistics Provider for System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2b90000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\nduprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик сетевой статистики для службы отслеживания использования ресурсов системы</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bb0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\appsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bd0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\eeprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy Estimator SRUM provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2c20000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\wfapigp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall GPO Helper dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2d70000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\wpnsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SRUM provider for WPN</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3310000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\srumsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3730000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\pnpts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PlugPlay Troubleshooter</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3bd0000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\ncdautosetup.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы автоматической настройки сетевых устройств</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac41f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\adhapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD harvest sites and subnets API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4500000</BaseAddress>
<Size>200704</Size>
<Path>c:\windows\system32\dps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба политики диагностики WDI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4cd0000</BaseAddress>
<Size>933888</Size>
<Path>c:\windows\system32\mpssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба защиты (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6740000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\dtsh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API состояния общего доступа и обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac74b0000</BaseAddress>
<Size>827392</Size>
<Path>c:\windows\system32\bfe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба базовой фильтрации</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\coremessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\system32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\CFGMGR32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>24</ProcessIndex>
<ProcessId>348</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776305446235</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k netsvcs</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaa0aa0000</BaseAddress>
<Size>2138112</Size>
<Path>c:\windows\system32\wlidsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба учетных записей Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0750000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\system32\rascustom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль настраиваемых протоколов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab07b0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\vpnike.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>VPNIKE Protocol Engine - Test dll</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab09b0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\system32\rasppp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access PPP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0a00000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\rastapi.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access TAPI Compliance Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab3440000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\rasmans.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер подключений удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4c50000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\eappprxy.dll</Path>
<Version>10.0.14393.187 (rs1_release_inmarket.160906-1818)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft EAPHost Peer Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab9a90000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\dmEnrollEngine.DLL</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enroll Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabc210000</BaseAddress>
<Size>2355200</Size>
<Path>c:\windows\system32\wuaueng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Агент Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabdf60000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\raschap.dll</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>Удаленные доступ через PPP CHAP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4a0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\appinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о приложении</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabed80000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\system32\wbem\wbemess.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee10000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee30000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\system32\wbem\wmiprvsd.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf090000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>c:\windows\system32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfda0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\wbem\ncprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Non-COM WMI Event Provision APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0000000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wbem\repdrvfs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Repository Driver</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\shacctprofile.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Profile Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1530000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SYSTEM32\dpx.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft(R) Delta Package Expander</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1900000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\appxapplicabilityblob.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Appx Applicability Blob DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1970000</BaseAddress>
<Size>1073152</Size>
<Path>c:\windows\system32\qmgr.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фоновая интеллектуальная служба передачи</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1c30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\DMProcessXMLFiltered.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmprocessxmlfiltered</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1cf0000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\SYSTEM32\wuuhext.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update Agent plugin for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1df0000</BaseAddress>
<Size>61440</Size>
<Path>c:\windows\system32\NCI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CoInstaller: NET</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e20000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f10000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\DMCmnUtils.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmcmnutils</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f50000</BaseAddress>
<Size>471040</Size>
<Path>C:\Windows\system32\wbem\esscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20f0000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\CLUSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API кластера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2210000</BaseAddress>
<Size>1351680</Size>
<Path>C:\Windows\system32\wbem\wbemcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инструментарий управления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2370000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\adhsvc.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD Harvest Sites and Subnets Service</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2390000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\httpprxm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager</Description>
</module>
<module>
<Timestamp>131795775850813653</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac24a0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\system32\RESUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служебной программы ресурсов кластера (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795775850596192</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2640000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\wmidcom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2670000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\miutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура управления</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac26f0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\sscoreext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Core DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2720000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SYSTEM32\WPTaskScheduler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WP Task Scheduler DLL</Description>
</module>
<module>
<Timestamp>131795775850744400</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2770000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\SSCORE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основная DLL-библиотека службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2940000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CSystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Classic System Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>c:\windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a40000</BaseAddress>
<Size>974848</Size>
<Path>c:\windows\system32\iphlpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Эта служба предоставляет автоматическое подключение IPv6 в сети IPv4.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c60000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\WDSCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Panther Engine Module</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\system32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3740000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3b40000</BaseAddress>
<Size>245760</Size>
<Path>c:\windows\system32\wbem\wmisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3fa0000</BaseAddress>
<Size>331776</Size>
<Path>c:\windows\system32\srvsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) ресурсов для службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4160000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\wpnservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба системы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4480000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\taskcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оснастка обратной совместимости диспетчера задач</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4540000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\ProximityServicePAL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service PAL</Description>
</module>
<module>
<Timestamp>131795775380234927</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4cc0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ProximityCommonPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Common PAL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4dc0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\ProximityCommon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Универсальная реализация близкого взаимодействия</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4ee0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\ProximityService.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service Implementation</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5ef0000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\System32\MbaeApiPublic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Mobile Broadband Account API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7700000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\CredentialMigrationHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Migration Handler</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\sqmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SQM Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d60000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\UpdatePolicy.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Policy Reader</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e90000</BaseAddress>
<Size>749568</Size>
<Path>c:\windows\system32\FVEAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows BitLocker Drive Encryption API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac82d0000</BaseAddress>
<Size>643072</Size>
<Path>c:\windows\system32\shsvcs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8590000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\LocationWinPalMisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Location Platform Abstraction Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac85c0000</BaseAddress>
<Size>1810432</Size>
<Path>c:\windows\system32\LocationFramework.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа географического положения Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8780000</BaseAddress>
<Size>274432</Size>
<Path>c:\windows\system32\UBPM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL единого диспетчера фоновых процессов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8b60000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\schedsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac91c0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\profsvcext.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvcExt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92a0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\sens.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба уведомления о системных событиях (SENS)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\themeservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы темы оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9420000</BaseAddress>
<Size>380928</Size>
<Path>c:\windows\system32\profsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvc</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9a70000</BaseAddress>
<Size>1257472</Size>
<Path>c:\windows\system32\gpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca700000</BaseAddress>
<Size>32768</Size>
<Path>c:\windows\system32\DABAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Desktop Activity Broker API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca720000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\bitsigd.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service IGD Support</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacab70000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба географического положения</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac40000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\seclogon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL службы вторичного входа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac50000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\bitsperf.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Perfmon Counter Access</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\MSWSOCK.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>25</ProcessIndex>
<ProcessId>372</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776305463443</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>c:\windows\system32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab91f0000</BaseAddress>
<Size>233472</Size>
<Path>c:\windows\system32\sstpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обеспечивает возможность использования SSTP для подключения к удаленным компьютерам с помощью VPN.</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabc610000</BaseAddress>
<Size>540672</Size>
<Path>c:\windows\system32\w32time.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба времени Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabef00000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\cdpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба CDP Майкрософт (R)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05e0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\sbservicetrigger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Socket Broker Service Trigger</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4130000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\fdphost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба размещения поставщиков функций обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4200000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\perftrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Performance PerfTrack</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5b80000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\AuthBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API WinRT для веб-проверки подлинности</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66e0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\fdssdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery SSDP Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6960000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\fdwsd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery WS Discovery Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac76d0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\vmictimeprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Machine Integration Component Time Sync Provider Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7a10000</BaseAddress>
<Size>544768</Size>
<Path>c:\windows\system32\netprofmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер списка сетей</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7f70000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\licensemanagersvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManagerSvc</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90a0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\nsisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RPC-сервер интерфейса сохранения сети</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac91f0000</BaseAddress>
<Size>172032</Size>
<Path>c:\windows\system32\FontProvider.dll</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Font Provider Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9860000</BaseAddress>
<Size>1896448</Size>
<Path>c:\windows\system32\fntcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэша шрифтов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>c:\windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>26</ProcessIndex>
<ProcessId>360</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311216195</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffabaad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\deviceaccess.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Broker And Policy COM Server</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac7e70000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\coreaudiopolicymanagerext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;coreaudiopolicymanagerext.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac87d0000</BaseAddress>
<Size>237568</Size>
<Path>c:\windows\system32\AUDIOSRVPOLICYMANAGER.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Audio Service Policy Manager</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac90d0000</BaseAddress>
<Size>978944</Size>
<Path>c:\windows\system32\audiosrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\POWRPROF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>27</ProcessIndex>
<ProcessId>1040</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311708649</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8820000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SYSTEM32\cmintegrator.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>cmintegrator.dll</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8c50000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wcmcsp.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Service Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8fe0000</BaseAddress>
<Size>737280</Size>
<Path>c:\windows\system32\wcmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы диспетчера подключений Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>28</ProcessIndex>
<ProcessId>1068</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776312395030</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\CRYPTNET.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\cryptcatsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Catalog Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65f0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\crypttpmeksvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic TPM Endorsement Key Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6680000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\cryptsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6f00000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\wkssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы рабочей станции</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79e0000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\netjoin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL присоединения к домену</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\WlanApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7c00000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\ssdpapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8260000</BaseAddress>
<Size>425984</Size>
<Path>c:\windows\system32\ncsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индикатор работоспособности сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8370000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\nlasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о подключенных сетях 2</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8410000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dnsext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DNS extension DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SYSTEM32\Fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8830000</BaseAddress>
<Size>290816</Size>
<Path>c:\windows\system32\dnsrslvr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэширующего сопоставителя DNS</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\JoinUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>29</ProcessIndex>
<ProcessId>1248</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776322176070</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>spoolsv.exe</ProcessName>
<ImagePath>C:\Windows\System32\spoolsv.exe</ImagePath>
<CommandLine>C:\Windows\System32\spoolsv.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер очереди печати</Description>
<modulelist>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ff639680000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\spoolsv.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер очереди печати</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffab8a60000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaba980000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\jscript.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabb7d0000</BaseAddress>
<Size>851968</Size>
<Path>C:\Windows\System32\win32spl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик печати с исполнением на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\prntvpt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Ticket Services Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd70000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_53d78f68bc1697cc\Amd64\PrintConfig.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc0c0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPFILEQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPFILEQ</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc590000</BaseAddress>
<Size>118784</Size>
<Path>C:\Program Files\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc5b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\amsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Anti-Malware Scan Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd040000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdPnp.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pnp Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd060000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\WSDMon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер порта принтера WSD</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd100000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\usbmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Standard Dynamic Printing Port Monitor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd160000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\wsnmp32.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft WinSNMP v2.0 Manager API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd2a0000</BaseAddress>
<Size>1159168</Size>
<Path>C:\Windows\System32\localspl.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека локального диспетчера очереди</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabde60000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\System32\tcpmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека монитора портов TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe3f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\spool\PRTPROCS\x64\winprint.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Print Processor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe6c0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\PrintIsolationProxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Sandbox COM Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe8a0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\snmpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SNMP Utility Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe980000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\SPOOLSS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Spooler SubSystem DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f00000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\FXSMON.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft  Fax Print Monitor</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac4e90000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\wshirda.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Sockets Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac7e00000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\inetpp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Internet Print Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>30</ProcessIndex>
<ProcessId>1512</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776336551242</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffabe9f0000</BaseAddress>
<Size>258048</Size>
<Path>c:\windows\system32\ssdpsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы SSDP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69b0000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\fdrespub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба публикации ресурсов обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>c:\windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>31</ProcessIndex>
<ProcessId>1556</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776339471770</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k utcsvc</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x272f9bf0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf140000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\CourtesyEngine.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Feedback Courtesy Engine DLL Server</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfde0000</BaseAddress>
<Size>143360</Size>
<Path>c:\windows\system32\CRYPTXML.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API-интерфейс XML DigSig</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\Netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\DSREG.DLL</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac5fd0000</BaseAddress>
<Size>1056768</Size>
<Path>c:\windows\system32\WindowsPerformanceRecorderControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Performance Recorder Control Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>c:\windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6210000</BaseAddress>
<Size>2007040</Size>
<Path>c:\windows\system32\diagtrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диагностическое отслеживание Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795775838362137</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795775839498740</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>32</ProcessIndex>
<ProcessId>1636</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776343009549</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k appmodel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>c:\windows\system32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3c10000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\tileobjserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер моделей данных плиток</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>c:\windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>c:\windows\system32\windows.staterepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>33</ProcessIndex>
<ProcessId>1744</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776348255325</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>MemCompression</ProcessName>
<ImagePath>MemCompression</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>34</ProcessIndex>
<ProcessId>2100</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776438403561</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffabff90000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\ipsecsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows IPsec SPD Server DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac1e00000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\FwRemoteSvr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall Remote APIs Server</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>35</ProcessIndex>
<ProcessId>2648</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777555980720</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>sihost.exe</ProcessName>
<ImagePath>C:\Windows\system32\sihost.exe</ImagePath>
<CommandLine>sihost.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Shell Infrastructure Host</Description>
<modulelist>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ff7bbae0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\sihost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Infrastructure Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb910000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\container.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Containers</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb970000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\daxexec.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>daxexec</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc450000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\system32\ShareHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShareHost</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc800000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\windowmanagement.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Window Management</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc850000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\AppointmentActivation.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL for AppointmentActivation</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc8b0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\NotificationPlatformComponent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationPlatformComponent</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc9a0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\activationmanager.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Activation Manager</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabca10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\ClipboardServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Modern Clipboard</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcde0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Windows\System32\modernexecserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Modern Execution</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcf10000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\desktopshellext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DesktopHost Extensions</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\system32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>36</ProcessIndex>
<ProcessId>840</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777563791648</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k UnistackSvcGroup</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf6a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\PhoneUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Phone utilities</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf700000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\System32\PIMSTORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>POOM</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab05d0000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\AccountAccessor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync data model to access accounts</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab0630000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\SyncController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SyncController for managing sync of mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb20000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\CEMAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CEMAPI</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcd80000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\cdpusersvc.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP User Components</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabd630000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\MCCSEngineShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Utilies shared among OneSync engines</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabdde0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\SYNCUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabed20000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\aphostservice.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>c:\windows\system32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4100000</BaseAddress>
<Size>151552</Size>
<Path>c:\windows\system32\NetworkHelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac97b0000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\InprocLogger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>In-proc Private Event Trace Logger</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca1d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\UserDataTypeHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Type Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca270000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\UserDataLanguageUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Language-related helper functions for user data</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca520000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\APHostClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service RPC Client </Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacabf0000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\MCCSPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform abstraction layer dll for MCCS</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacac20000</BaseAddress>
<Size>86016</Size>
<Path>c:\windows\system32\UserDataPlatformHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>37</ProcessIndex>
<ProcessId>528</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777565618284</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\system32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb440000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\system32\MTFServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;MTFServer.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb510000</BaseAddress>
<Size>2854912</Size>
<Path>C:\Windows\system32\InputService.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Text InputService Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8c0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\InputLocaleManager.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;InputLocaleManager.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8f0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\EditBufferTestHook.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;EditBufferTestHook.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb9f0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\system32\MSUTB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) сервера MSUTB</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabba70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\MsCtfMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MsCtfMonitor DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabbc20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\PlaySndSrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба PlaySound</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\system32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac7d10000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\KBDUS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>United States Keyboard Layout</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab10000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\WordBreakers.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;WordBreakers.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>38</ProcessIndex>
<ProcessId>3632</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777941176116</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>RuntimeBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\RuntimeBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\RuntimeBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Runtime Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7a45f0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\RuntimeBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Runtime Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\System32\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\mssrch.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe880000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\FeClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT File Encryption Client Interfaces</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe8c0000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\system32\windows.cortana.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.Desktop</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795771229682115</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf9c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\system32\windows.cortana.onecore.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.OneCore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795771234179313</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5ca0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\AppExtension.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API AppExtension</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795771242759756</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7d00000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SYSTEM32\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>39</ProcessIndex>
<ProcessId>3164</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778119045372</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ShellExperienceHost.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe&quot; -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Windows Shell Experience Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ff697570000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Experience Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f760000</BaseAddress>
<Size>3796992</Size>
<Path>C:\Windows\System32\MFMediaEngine.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Media Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaabad0000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\mfsrcsnk.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Source and Sink DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaafe70000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\System32\mfcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Core DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab0be0000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\ShellExperiences\NetworkUX.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab9eb0000</BaseAddress>
<Size>2899968</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.ActionCenter.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActionCenter Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaba180000</BaseAddress>
<Size>7880704</Size>
<Path>C:\Windows\ShellExperiences\StartUI.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Start UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SYSTEM32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd420000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\RTMediaFrame.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime MediaFrame DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe410000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\SYSTEM32\globcollationhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GlobCollationHost</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0080000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\System32\resampledmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Resampler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0110000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\QuickActionsDataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>QuickActionsDataModel</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0160000</BaseAddress>
<Size>491520</Size>
<Path>C:\Windows\ShellExperiences\QuickActions.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac40f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4eb0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5b20000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\CompPkgSup.DLL</Path>
<Version>10.0.14393.969 (rs1_release_inmarket.170315-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Component Package Support DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5e90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\Windows.Media.MediaControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера MediaControl среды выполнения Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>40</ProcessIndex>
<ProcessId>4856</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778391112136</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MSASCuiL.exe</ProcessName>
<ImagePath>C:\Program Files\Windows Defender\MSASCuiL.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Windows Defender\MSASCuiL.exe&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Description>Windows Defender notification icon</Description>
<modulelist>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x23622c70000</BaseAddress>
<Size>733184</Size>
<Path>C:\Program Files\Windows Defender\EppManifest.dll</Path>
<Version>4.10.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль ресурсов настройки пользовательского интерфейса</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ff63bef0000</BaseAddress>
<Size>651264</Size>
<Path>C:\Program Files\Windows Defender\MSASCuiL.exe</Path>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Defender notification icon</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4560000</BaseAddress>
<Size>950272</Size>
<Path>C:\Program Files\Windows Defender\mpclient.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Client Interface</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>41</ProcessIndex>
<ProcessId>4928</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778406250112</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>uTorrent.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe&quot;  /MINIMIZED</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>3.5.4.44498</Version>
<Description>µTorrent</Description>
<modulelist>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>5406720</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</Path>
<Version>3.5.4.44498</Version>
<Company>BitTorrent Inc.</Company>
<Description>µTorrent</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e140000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SysWOW64\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1c0000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\SysWOW64\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6ef20000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70af0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fc0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fd0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fe0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>42</ProcessIndex>
<ProcessId>3608</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778496229053</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ApplicationFrameHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\ApplicationFrameHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\ApplicationFrameHost.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Application Frame Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ff6aa270000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\ApplicationFrameHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Frame Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5240000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\ApplicationFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фрейм приложения</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\system32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\D3D10Warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>43</ProcessIndex>
<ProcessId>5952</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778883326814</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54150_1240996307 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>44</ProcessIndex>
<ProcessId>5800</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765779120650795</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\esent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>45</ProcessIndex>
<ProcessId>340</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765800389528045</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54870_1839591030 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c50000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\Ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>46</ProcessIndex>
<ProcessId>2736</ProcessId>
<ParentProcessId>3976</ParentProcessId>
<ParentProcessIndex>47</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765800903010156</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Taskmgr.exe</ProcessName>
<ImagePath>C:\Windows\System32\Taskmgr.exe</ImagePath>
<CommandLine>&quot;C:\Windows\System32\Taskmgr.exe&quot; /2 </CommandLine>
<CompanyName>Microsoft® Windows® Operating System</CompanyName>
<Version>1, 0, 0, 1</Version>
<Description>Task Manager</Description>
<modulelist>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ff7c2a70000</BaseAddress>
<Size>1286144</Size>
<Path>C:\Windows\System32\Taskmgr.exe</Path>
<Version>1, 0, 0, 1</Version>
<Company>Microsoft® Windows® Operating System</Company>
<Description>Task Manager</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdfa0000</BaseAddress>
<Size>393216</Size>
<Path>C:\Windows\System32\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\System32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>49</ProcessIndex>
<ProcessId>6724</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803507001117</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHActiveDefense.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe&quot;</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1008</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0xd0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</Path>
<Version>10,0,0,1008</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795771117425875</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>2830336</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Version>1.0</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x3c80000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fb90000</BaseAddress>
<Size>2736128</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\deepscan.dll</Path>
<Version>3, 5, 1, 2130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60190000</BaseAddress>
<Size>475136</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360SafeCamera.tpi</Path>
<Version>2, 0, 0, 1031</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60210000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\jcloudscan.dll</Path>
<Version>1, 0, 0, 1012</Version>
<Company>360.cn</Company>
<Description>360安全卫士 移动云查询模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604a0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appdext.dll</Path>
<Version>1, 0, 0, 1483</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604e0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\DrvUtility.dll</Path>
<Version>1, 0, 0, 1081</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60510000</BaseAddress>
<Size>409600</Size>
<Path>C:\Program Files (x86)\360\Total Security\SafeScan.dll</Path>
<Version>1, 0, 0, 1074</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60580000</BaseAddress>
<Size>204800</Size>
<Path>C:\Program Files (x86)\360\Total Security\ScanStub.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x605c0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360gameidentify.dll</Path>
<Version>1, 0, 1, 1050</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏识别模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60640000</BaseAddress>
<Size>430080</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\Netgm.dll</Path>
<Version>9,0,0,1005</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏模式判断模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60a50000</BaseAddress>
<Size>479232</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\DsSysRepair.dll</Path>
<Version>1, 0, 0, 1062</Version>
<Company>QIHU360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security System Repair Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61000000</BaseAddress>
<Size>184320</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\qutmipc.dll</Path>
<Version>7, 3, 0, 1267</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61030000</BaseAddress>
<Size>262144</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg.dll</Path>
<Version>3, 0, 0, 1160</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x610d0000</BaseAddress>
<Size>1097728</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\SomAdvUtils.dll</Path>
<Version>3, 1, 1, 2020</Version>
<Company>360.cn</Company>
<Description>360 Safeguard PC Boost</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61480000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qex\qex.dll</Path>
<Version>4.1.13.3366</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2017 Antivirus</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x616a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SelfProtectAPI2.dll</Path>
<Version>7, 1, 1, 1033</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61700000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360procmon.dll</Path>
<Version>7, 1, 1, 1221</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61780000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\netdefender.dll</Path>
<Version>1, 0, 0, 1129</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x617e0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appd.dll</Path>
<Version>7, 3, 6, 3113</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360HipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61ab0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\fileMgr.dll</Path>
<Version>7, 3, 0, 1963</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x621a0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\yhregd.dll</Path>
<Version>7, 2, 0, 1903</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62280000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\360SoftMgrS.dll</Path>
<Version>2, 1, 6, 1490</Version>
<Company>360.cn</Company>
<Description>360软件管家 服务模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62470000</BaseAddress>
<Size>405504</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll</Path>
<Version>7, 2, 1, 1279</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x624e0000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\360box.dll</Path>
<Version>2, 0, 0, 1043</Version>
<Company>360.cn</Company>
<Description>360隔离沙箱模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\deepscan\DsRes.dll</Path>
<Version>1,0,0,1012</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security Resource</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b70000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\gamemode.tpi</Path>
<Version>9,0,0,1001</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Game Mode Control</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67130000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\devenum.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечисление устройств.</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\fltlib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6c0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6ea80000</BaseAddress>
<Size>860160</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\QVM\360QVM.dll</Path>
<Version>5.0.2.1003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security QVM Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70210000</BaseAddress>
<Size>966656</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEngine.dll</Path>
<Version>1, 0, 0, 2016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70300000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEI.dll</Path>
<Version>1, 0, 0, 2003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>50</ProcessIndex>
<ProcessId>6340</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765803510844292</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>QHSafeTray.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</ImagePath>
<CommandLine>/showtrayicon</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1024</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0xec0000</BaseAddress>
<Size>2351104</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</Path>
<Version>10,0,0,1024</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x68f0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c480000</BaseAddress>
<Size>245760</Size>
<Path>C:\Program Files (x86)\360\Total Security\PDown.dll</Path>
<Version>1, 3, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Security Center Network Module </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5fe30000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll</Path>
<Version>9,6,0,1001</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60020000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360netctrl.dll</Path>
<Version>5, 3, 15, 2232</Version>
<Company>360.cn</Company>
<Description>360 Total Security NetwokrMonCtrl</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60090000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\netmon.tpi</Path>
<Version>5, 1, 1, 3157</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360安全卫士 流量防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60350000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Program Files (x86)\360\Total Security\ToolBox.dll</Path>
<Version>1, 0, 0, 1094</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x606b0000</BaseAddress>
<Size>598016</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe.dll</Path>
<Version>1, 0, 0, 1120</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x609b0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360GuardBase.dll</Path>
<Version>3, 1, 0, 1060</Version>
<Company>360.cn</Company>
<Description>360保镖</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61070000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SomProxy.dll</Path>
<Version>1, 0, 0, 1900</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x611e0000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360connect.tpi</Path>
<Version>9,2,0,1030</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Connect</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x618c0000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files (x86)\360\Total Security\sites.dll</Path>
<Version>11, 1, 0, 1212</Version>
<Company>360.cn</Company>
<Description>360安全卫士</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360hipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\softmgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\Cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62210000</BaseAddress>
<Size>446464</Size>
<Path>C:\Program Files (x86)\360\Total Security\360TSCommon.dll</Path>
<Version>9, 0, 0, 1016</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62960000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\CleanPlusCache.tpi</Path>
<Version>1, 0, 0, 1004</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>CleanPlusCache</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795771279916892</Timestamp>
<BaseAddress>0x68850000</BaseAddress>
<Size>2764800</Size>
<Path>C:\Windows\SysWOW64\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e6e0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e770000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SysWOW64\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71170000</BaseAddress>
<Size>466944</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\CQhCltHttpW.dll</Path>
<Version>1, 4, 0, 1030</Version>
<Company>QIHU 360 SOFTWARE  CO. LIMITED</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>51</ProcessIndex>
<ProcessId>6860</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803555957830</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHWatchdog.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe&quot; /watch</CommandLine>
<CompanyName>QIHU 360 SOFTWARE CO. LIMITED</CompanyName>
<Version>8,2,0,1000</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0xdf0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</Path>
<Version>8,2,0,1000</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>52</ProcessIndex>
<ProcessId>5924</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765805232900810</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>wmiprvse.exe</ProcessName>
<ImagePath>C:\Windows\sysWOW64\wbem\wmiprvse.exe</ImagePath>
<CommandLine>C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Description>WMI Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x950000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\sysWOW64\wbem\wmiprvse.exe</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Provider Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\storagewmi_passthru.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60160000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x604d0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\delegatorprovider.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>53</ProcessIndex>
<ProcessId>6180</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765807370364309</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>smartscreen.exe</ProcessName>
<ImagePath>C:\Windows\System32\smartscreen.exe</ImagePath>
<CommandLine>C:\Windows\System32\smartscreen.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>SmartScreen</Description>
<modulelist>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ff688690000</BaseAddress>
<Size>2416640</Size>
<Path>C:\Windows\System32\smartscreen.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreen</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaafa00000</BaseAddress>
<Size>2936832</Size>
<Path>C:\Windows\System32\certenroll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент регистрации служб сертификатов Active Directory Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffab2210000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\certca.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ЦС служб сертификации Microsoft® Active Directory</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\SYSTEM32\windows.globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac3290000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\smartscreenps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreenPS</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\System32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\CFGMGR32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>54</ProcessIndex>
<ProcessId>4408</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765812380694767</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x17826230000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1140000</BaseAddress>
<Size>1134592</Size>
<Path>C:\Windows\System32\ReAgent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>C:\Windows\System32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\system32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe000000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\system32\WinSATAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Assessment Tool API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf050000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\sdiageng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема выполнения сценариев диагностики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4ae0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sdiagschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запланированная задача сценариев проверки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4b00000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\MemoryDiagnostic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач средства проверки памяти Windows (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac5c80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\TempSignedLicenseExchangeTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TempSignedLicenseExchangeTask Task</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca200000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\ReAgentTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca210000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\RstrtMgr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер перезапуска</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacac00000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\radarrs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>программа устранения нехватки системных ресурсов Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>55</ProcessIndex>
<ProcessId>6944</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131767576301455145</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SkypeHost.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe&quot; -ServerName:SkypeHost.ServerServer</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>12.1815.210.0</Version>
<Description>Microsoft Skype</Description>
<modulelist>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ff7e8670000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaae130000</BaseAddress>
<Size>22437888</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkyWrap.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabe150000</BaseAddress>
<Size>2691072</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\skypert.dll</Path>
<Version>2018.15.01.31</Version>
<Company></Company>
<Description>SkypeRT shared library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1a80000</BaseAddress>
<Size>978944</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7c80000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>56</ProcessIndex>
<ProcessId>1048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131768729449405953</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>sedsvc.exe</ProcessName>
<ImagePath>C:\Program Files\rempl\sedsvc.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\rempl\sedsvc.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Description>sedsvc</Description>
<modulelist>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ff751430000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\rempl\sedsvc.exe</Path>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>sedsvc</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>57</ProcessIndex>
<ProcessId>7744</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081112364684</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; </CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x11330000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60900000</BaseAddress>
<Size>720896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\urlproc.dll</Path>
<Version>2, 9, 5, 1260</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x68b00000</BaseAddress>
<Size>44998656</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ce30000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6dc80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files (x86)\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6df70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\SysWOW64\shdocvw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e070000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e090000</BaseAddress>
<Size>233472</Size>
<Path>C:\Windows\SysWOW64\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e110000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e120000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multimedia Realtime Runtime</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e2a0000</BaseAddress>
<Size>4440064</Size>
<Path>C:\Windows\SysWOW64\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb60000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb70000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ec40000</BaseAddress>
<Size>442368</Size>
<Path>C:\Windows\SysWOW64\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd00000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd20000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe40000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe50000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SysWOW64\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ff90000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\SysWOW64\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ffe0000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\SysWOW64\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70190000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x701a0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\dllyupdate.dll</Path>
<Version>1.2.0.1831</Version>
<Company>Yandex LLC</Company>
<Description>Yandex updater (CU)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b30000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\WINUSB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows USB Driver User Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b60000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x711f0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>58</ProcessIndex>
<ProcessId>5696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081114193232</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe --type=crashpad-handler &quot;--user-data-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler &quot;--database=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data\Crashpad&quot; &quot;--metrics-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; --url=https://crash-reports.browser.yandex.net/submit --annotation=machine_id=c46245ef0fec9d5c44d2fa20241f2070 --annotation=main_process_pid=7744 --annotation=metrics_client_id=520f4dd3247d4cdfb744f32b1130b1bf --annotation=plat=Win32 --annotation=prod=Yandex --annotation=ver=18.6.1.770 --initial-client-data=0x1c4,0x1cc,0x1d0,0x1c0,0x1d4,0x700b800c,0x700b7ffc,0x700b7fe0,0x1c8</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>59</ProcessIndex>
<ProcessId>4664</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081123844756</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=gpu-process --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --service-request-channel-token=CC1AC8FA9C8EFF1EEBC2375FE4F704C6 --mojo-platform-channel-handle=1588 --ignored=&quot; --type=renderer &quot; /prefetch:2</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ecb0000</BaseAddress>
<Size>2228224</Size>
<Path>C:\Windows\SysWOW64\mfh264enc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation H264 Encoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f250000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\SysWOW64\ddraw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectDraw</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f340000</BaseAddress>
<Size>3784704</Size>
<Path>C:\Windows\SysWOW64\D3DCompiler_47.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D HLSL Compiler</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f6e0000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\SysWOW64\msvproc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Video Processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fbe0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\mf.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff20000</BaseAddress>
<Size>118784</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\swiftshader\libegl.dll</Path>
<Version>4.0.0.3</Version>
<Company></Company>
<Description>SwiftShader libEGL 32-bit Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dxva2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Video Acceleration 2.0 DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x705d0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\DCIMAN32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DCI Manager</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>60</ProcessIndex>
<ProcessId>8968</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081206363215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=183F52B8A6577BFD721F95F3A9641348 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=183F52B8A6577BFD721F95F3A9641348 --renderer-client-id=4 --mojo-platform-channel-handle=2640 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>61</ProcessIndex>
<ProcessId>4992</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081244357280</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=7E8A8199C364F4B0114F2A163B757250 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E8A8199C364F4B0114F2A163B757250 --renderer-client-id=10 --mojo-platform-channel-handle=3904 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>63</ProcessIndex>
<ProcessId>9504</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956266598229</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgent.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgent.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgent.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>InstallAgent</Description>
<modulelist>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ff63d380000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\InstallAgent.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffabea60000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\VEStoreEventHandlers.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDL Store Event Handlers</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4ad0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\EAMProgressHandler.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>EAMProgressHandler</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>64</ProcessIndex>
<ProcessId>8768</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956321853179</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgentUserBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgentUserBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgentUserBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>InstallAgentUserBroker</Description>
<modulelist>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x22530450000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ff74f890000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\InstallAgentUserBroker.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgentUserBroker</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>65</ProcessIndex>
<ProcessId>9636</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956424585250</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettingsBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\SystemSettingsBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\SystemSettingsBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>System Settings Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ff6015f0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\SystemSettingsBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Broker</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>66</ProcessIndex>
<ProcessId>10592</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956519902643</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettings.exe</ProcessName>
<ImagePath>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</ImagePath>
<CommandLine>&quot;C:\Windows\ImmersiveControlPanel\SystemSettings.exe&quot; -ServerName:microsoft.windows.immersivecontrolpanel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Параметры</Description>
<modulelist>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x18099ef0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\WMI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI DC and DP functionality</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ff7937a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaabce0000</BaseAddress>
<Size>2535424</Size>
<Path>C:\Windows\System32\NetworkMobileSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System settings network mobile handlers group</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac220000</BaseAddress>
<Size>4952064</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Application</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaadd90000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\NetworkDesktopSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Группа обработчиков системных параметров сетевого рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaaf920000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettingsViewModel.Desktop.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings View Model Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0970000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\credprovhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост инфраструктуры поставщика учетных данных</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0a70000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\System32\fhcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигураций истории файлов</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\SYSTEM32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\SYSTEM32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab91d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\ImmersiveControlPanel\Telemetry.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Telemetry Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcc60000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\System32\MiracastReceiver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API приемника Miracast</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2bf0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\EFSUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>EFS Utility Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\SYSTEM32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\wmiclnt.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca560000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\NcaApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Network Connectivity Assistant API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>67</ProcessIndex>
<ProcessId>10964</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794956837373387</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{BA126F01-2166-11D1-B1D0-00805FC1270E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\system32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>68</ProcessIndex>
<ProcessId>8940</ProcessId>
<ParentProcessId>2156</ParentProcessId>
<ParentProcessIndex>62</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956984780982</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Photoshop.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe&quot; &quot;C:\Users\User\Downloads\tlauncher_psd\tlauncher_psd.psd&quot;</CommandLine>
<CompanyName>Adobe Systems, Incorporated</CompanyName>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Description>Adobe Photoshop CC 2017</Description>
<modulelist>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0xb20000</BaseAddress>
<Size>9846784</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\cg.dll</Path>
<Version>3.0.00007</Version>
<Company>NVIDIA Corporation</Company>
<Description>Cg Core Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1490000</BaseAddress>
<Size>3276800</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\libmmd.dll</Path>
<Version>12.0.12.2</Version>
<Company>Intel Corporation</Company>
<Description>Math Library for Intel(r) Compilers (thread-safe)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x10000000</BaseAddress>
<Size>6070272</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\svml_dispmd.dll</Path>
<Version>12.0.12.2</Version>
<Company>Intel Corporation</Company>
<Description>SVML Library for Intel(r) Compilers (thread-safe)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x4fad0000</BaseAddress>
<Size>70561792</Size>
<Path>C:\Program Files\Common Files\Adobe\Plug-Ins\CC\File Formats\Camera Raw.8bi</Path>
<Version>9.8</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Photoshop Camera Raw Plug-in</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5b690000</BaseAddress>
<Size>4763648</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\SVGRE.dll</Path>
<Version>6, 0, 0, 37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>SVGRE 6.0</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5bcf0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AXE8SharedExpat.dll</Path>
<Version>3.8.0.34320</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>AXE Shared EXPAT (UTF-8 native)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5bd30000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\dnssd.dll</Path>
<Version>3,0,0,2</Version>
<Company>Apple Inc.</Company>
<Description>Bonjour Client Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5bd40000</BaseAddress>
<Size>974848</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AXEDOMCore.dll</Path>
<Version>3.8.0.34320</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XML Engine: DOM Core</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5be30000</BaseAddress>
<Size>1306624</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\icucnv40.dll</Path>
<Version>4, 0, 0, 1001</Version>
<Company>IBM Corporation and others</Company>
<Description>IBM ICU Common DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x6a400000</BaseAddress>
<Size>479232</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\cgGL.dll</Path>
<Version>3.0.00007</Version>
<Company>NVIDIA Corporation</Company>
<Description>Cg GL Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\File Formats\PSDX.8bi</Path>
<Version>14.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Photoshop Remix Plug-In</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2eee90000</BaseAddress>
<Size>13922304</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\icudt40.dll</Path>
<Version>4, 0, 0, 1001</Version>
<Company>IBM Corporation and others</Company>
<Description>ICU Data DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f1470000</BaseAddress>
<Size>12288</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PSArt.dll</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Resource DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f3490000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.dll</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Resource DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f3620000</BaseAddress>
<Size>2699264</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PSViews.dll</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Resource DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f93a0000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\WRServices.dll</Path>
<Version>12.0.0.1000</Version>
<Company>WinSoft S.A.</Company>
<Description>WRServices Engine</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f9540000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Linguistics\Providers\Plugins2\WRLiloPlugin.bundle\WRLiloPlugin.dll</Path>
<Version>1.3.6rc1</Version>
<Company>WinSoft SA</Company>
<Description>WR LILO Plugin</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ff6c3030000</BaseAddress>
<Size>182624256</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa0cb0000</BaseAddress>
<Size>1880064</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\aif.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa0e80000</BaseAddress>
<Size>2637824</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\LogSession.dll</Path>
<Version>7.4.1.60.45263</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>LogSession</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa1110000</BaseAddress>
<Size>70823936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\libcef.dll</Path>
<Version>3.2526.1347.gcf20046</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa54a0000</BaseAddress>
<Size>7950336</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\ScriptingSupport.8li</Path>
<Version>18.0.1</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>ScriptingSupport</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa5c40000</BaseAddress>
<Size>2113536</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\AdobeHunspellPlugin.dll</Path>
<Version>11.0.0.22122</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>AdobeHunspellPlugin</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa5e50000</BaseAddress>
<Size>4493312</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\CoolType.dll</Path>
<Version>5.15.00.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>CoolType Typography Engine</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa62a0000</BaseAddress>
<Size>5267456</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AGM.dll</Path>
<Version>4.30.60.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Graphics Manager</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa67b0000</BaseAddress>
<Size>1839104</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ACE.dll</Path>
<Version>2.20.02.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Color Engine</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6980000</BaseAddress>
<Size>1302528</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeXMP.dll</Path>
<Version>5.6-c138 ( 64 bit ), 79.159824, 2016/09/14-01:09:01</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XMP Core 5.6-c138 ( 64 bit )</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6ac0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\MultiProcessor Support.8bx</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6b70000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\MMXCore.8bx</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2093056</Size>
<Path>C:\Windows\system32\wpdshext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки для переносных устройств</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6fd0000</BaseAddress>
<Size>978944</Size>
<Path>C:\Windows\SYSTEM32\MSVCR120.dll</Path>
<Version>12.00.40660.0 built by: VSULDR</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa70c0000</BaseAddress>
<Size>679936</Size>
<Path>C:\Windows\SYSTEM32\MSVCP120.dll</Path>
<Version>12.00.40660.0 built by: VSULDR</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7170000</BaseAddress>
<Size>2826240</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\opencv_imgproc249.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7430000</BaseAddress>
<Size>2564096</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\opencv_core249.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa76b0000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AIDE.dll</Path>
<Version>1.5.0.36540</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Image Decode Encode Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7820000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\tbbmalloc.dll</Path>
<Version>4, 4, 2016, 0412</Version>
<Company>Intel Corporation</Company>
<Description>Scalable Allocator library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7870000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\SYSTEM32\DDRAW.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectDraw</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7b20000</BaseAddress>
<Size>2613248</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeOwl.dll</Path>
<Version>5.2.11</Version>
<Company>Adobe Systems, Incorporated </Company>
<Description>Adobe Owl(64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7da0000</BaseAddress>
<Size>749568</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ScCore.dll</Path>
<Version>4.5.6.4</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Scripting Components Core (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7e60000</BaseAddress>
<Size>18792448</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\mona.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9050000</BaseAddress>
<Size>802816</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ExtendScript.dll</Path>
<Version>4.5.6.4</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe ExtendScript scripting engine (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9120000</BaseAddress>
<Size>5681152</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PlugPlugOwl.dll</Path>
<Version>7.0.0.67</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>PlugPlugOwl Standard Dll (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9690000</BaseAddress>
<Size>5595136</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\MPS.dll</Path>
<Version>5.8.1.37174</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Modular Parsing System</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9bf0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ahclient.dll</Path>
<Version>2.0.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Help Client Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9c50000</BaseAddress>
<Size>569344</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\manta.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9ce0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\tbb.dll</Path>
<Version>4, 4, 2016, 0412</Version>
<Company>Intel Corporation</Company>
<Description>Intel(R) Threading Building Blocks library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9d30000</BaseAddress>
<Size>499712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\VulcanControl.dll</Path>
<Version>__</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Vulcan Application Control Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9db0000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\VulcanMessage5.dll</Path>
<Version>__</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Vulcan Message Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9e50000</BaseAddress>
<Size>1241088</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdbePM.dll</Path>
<Version>2.5.00</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe PatchMatch</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9f80000</BaseAddress>
<Size>167936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\CITThreading.dll</Path>
<Version>2.1.0.1 ( 32 bit Debug)</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>CITTHREADING_NAME, 2.1.0.1 ( 32 bit Debug)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9fb0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\adobe_caps.dll</Path>
<Version>10,0,0,6</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CAPS DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa190000</BaseAddress>
<Size>1191936</Size>
<Path>C:\Windows\SYSTEM32\OPENGL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OpenGL Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa2c0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa5f0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\IMSLib.dll</Path>
<Version>10.0.0.1</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>IMSLib DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa9c0000</BaseAddress>
<Size>9007104</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\File Formats\Dicom.8bi</Path>
<Version>18.0.1</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Dicom Plugin</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaba80000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\GLU32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека подпрограмм OpenGL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaabca0000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PLUGIN.dll</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Plugin Utilities</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaade70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\icm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Color Management Module (CMM)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab06d0000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\c_g18030.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>GB18030 DBCS-Unicode Conversion DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab0b60000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeSVGAGM.dll</Path>
<Version>1.0.0.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe SVG AGM Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab1e60000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeXMPFiles.dll</Path>
<Version>5.7-f022 ( 64 bit ), 79.159824, 2016/09/14-01:09:01</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XMP Files 5.7-f022 ( 64 bit )</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab22e0000</BaseAddress>
<Size>1544192</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Spaces.8li</Path>
<Version>18.0.1</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Spaces</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab3410000</BaseAddress>
<Size>167936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\libglog.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabb070000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobePIP.dll</Path>
<Version>7.4.1.60.45263</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Product Improvement Program</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabb250000</BaseAddress>
<Size>380928</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\BIBUtils.dll</Path>
<Version>1.1.01.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Bravo Interface Binder Utilities</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabcc00000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\SYSTEM32\STI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека устройств неподвижных изображений </Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac0b40000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\dlnashext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLNA Namespace DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1300000</BaseAddress>
<Size>598016</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\BIB.dll</Path>
<Version>1.2.03.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Bravo Interface Binder</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\SYSTEM32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeXMPScript.dll</Path>
<Version>5.2-s002 ( 64 bit ), 79.159824, 2016/09/14-01:09:01</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XMP Script 5.2-s002 ( 64 bit )</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac4c50000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\WSOCK32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6aa0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\amtlib.dll</Path>
<Version>10.0.0.3</Version>
<Company>painter</Company>
<Description>AMTEmu Licensing</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\FastCore.8bx</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac7710000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\wiatrace.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WIA Tracing</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca540000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SYSTEM32\DCIMAN32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DCI Manager</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacac80000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SYSTEM32\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>69</ProcessIndex>
<ProcessId>10000</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957424930105</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>AdobeIPCBroker.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe&quot; &quot;-launchedbyvulcan&quot;</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>5.0.0.76</Version>
<Description>Adobe IPC Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0xbe0000</BaseAddress>
<Size>798720</Size>
<Path>C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe</Path>
<Version>5.0.0.76</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe IPC Broker</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>70</ProcessIndex>
<ProcessId>10064</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957636746019</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Adobe Spaces Helper.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe&quot; --type=renderer --no-sandbox --touch-events=disabled --lang=en-US --lang=ru --locales-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\locales\\&quot; --log-file=&quot;C:\Users\User\AppData\Roaming\Adobe\Adobe Photoshop CC 2017\Logs\debug.log&quot; --resources-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\\&quot; --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;8940.0.1405287427\319210639&quot; /prefetch:673131151</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ff6c2ef0000</BaseAddress>
<Size>1196032</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaa1110000</BaseAddress>
<Size>70823936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\libcef.dll</Path>
<Version>3.2526.1347.gcf20046</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SSPICLI.DLL</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>71</ProcessIndex>
<ProcessId>8596</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957641371503</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Adobe Spaces Helper.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe&quot; --type=renderer --no-sandbox --touch-events=disabled --lang=en-US --lang=ru --locales-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\locales\\&quot; --log-file=&quot;C:\Users\User\AppData\Roaming\Adobe\Adobe Photoshop CC 2017\Logs\debug.log&quot; --resources-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\\&quot; --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;8940.1.1139889345\75461215&quot; /prefetch:673131151</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ff6c2ef0000</BaseAddress>
<Size>1196032</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaa1110000</BaseAddress>
<Size>70823936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\libcef.dll</Path>
<Version>3.2526.1347.gcf20046</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SSPICLI.DLL</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>72</ProcessIndex>
<ProcessId>11172</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957658059215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; &quot;C:\Program Files (x86)\Common Files\Adobe\CEP\extensions\com.adobe.previewHD\PSLoader\loader.html&quot; 2ec98b7b-08f4-4716-915a-e20a700b24cb 8940 PHXS 18.0.1 com.adobe.preview.loader 1 &quot;C:\Program Files (x86)\Common Files\Adobe\CEP\extensions\com.adobe.previewHD&quot; &quot;Photoshop&quot; 16 WyItLWVuYWJsZS1ub2RlanMiXQ== ru_RU 4293980400 1</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>73</ProcessIndex>
<ProcessId>11216</ProcessId>
<ParentProcessId>11172</ParentProcessId>
<ParentProcessIndex>72</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957800622174</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=ru --log-file=&quot;C:\Users\User\AppData\Local\Temp\CEPHtmlEngine7-PHXS-18.0.1-com.adobe.preview.loader.log&quot; --log-severity=error --params_ppid=PHXS --params_ppversion=18.0.1 --params_extensionid=com.adobe.preview.loader --params_loglevel=1 --params_serverid=8940 --params_extensionuuid=2ec98b7b-08f4-4716-915a-e20a700b24cb --params_windowid=70742 --params_commandline=WyItLWVuYWJsZS1ub2RlanMiXQ== --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=11172 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;11172.0.296388529\1274093304&quot; /prefetch:673131151</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x6d990000</BaseAddress>
<Size>3055616</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\ffmpegsumo.dll</Path>
<Version>41.0.2272.104</Version>
<Company>The Chromium Authors</Company>
<Description>Chromium</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>74</ProcessIndex>
<ProcessId>10844</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958201141405</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\extensions\com.adobe.experimentation.extension\index.html&quot; e44c0384-b65f-4f05-a36a-c6092cb32d00 8940 PHXS 18.0.1 com.adobe.experimentation.extension 1 &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\extensions\com.adobe.experimentation.extension&quot; &quot;Photoshop&quot; 16 WyItLWVuYWJsZS1ub2RlanMiXQ== ru_RU 4293980400 1</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>75</ProcessIndex>
<ProcessId>9092</ProcessId>
<ParentProcessId>10844</ParentProcessId>
<ParentProcessIndex>74</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958208470288</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=ru --log-file=&quot;C:\Users\User\AppData\Local\Temp\CEPHtmlEngine7-PHXS-18.0.1-com.adobe.experimentation.extension.log&quot; --log-severity=error --params_ppid=PHXS --params_ppversion=18.0.1 --params_extensionid=com.adobe.experimentation.extension --params_loglevel=1 --params_serverid=8940 --params_extensionuuid=e44c0384-b65f-4f05-a36a-c6092cb32d00 --params_windowid=198892 --params_commandline=WyItLWVuYWJsZS1ub2RlanMiXQ== --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=10844 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;10844.0.379179099\270765323&quot; /prefetch:673131151</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x6d990000</BaseAddress>
<Size>3055616</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\ffmpegsumo.dll</Path>
<Version>41.0.2272.104</Version>
<Company>The Chromium Authors</Company>
<Description>Chromium</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>76</ProcessIndex>
<ProcessId>11496</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958406617238</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SearchUI.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe&quot; -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>Search and Cortana application</Description>
<modulelist>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ff79c3c0000</BaseAddress>
<Size>10706944</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Search and Cortana application</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\SYSTEM32\chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\SYSTEM32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4c70000</BaseAddress>
<Size>4874240</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab52c0000</BaseAddress>
<Size>2445312</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5840000</BaseAddress>
<Size>3108864</Size>
<Path>C:\Windows\System32\Speech_OneCore\Common\sapi_onecore.dll</Path>
<Version>5.3.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Speech API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5db0000</BaseAddress>
<Size>9781248</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9d50000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;CortanaApi.ProxyStub.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe770000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabefa0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\Cortana.Persona.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana.Persona</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac10b0000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\PersonaX.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PersonaX</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\SYSTEM32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3bf0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionMgr.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana Action Manager</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bb0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\windows.cortana.pal.desktop.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.PAL.Desktop</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7c50000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\BingConfigurationClient.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bing Configuration Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\SYSTEM32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>77</ProcessIndex>
<ProcessId>11408</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794962679173110</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>node.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\node.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\node.exe&quot; &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Generator-builtin&quot; --launchreason menu --menu crema-dummy-menu --photoshopVersion 18.0.1 -i \\.\pipe\36b615a8-a6c5-11e8-b291-8ffa7e69373b_i -o \\.\pipe\36b615a8-a6c5-11e8-b291-8ffa7e69373b_o -f &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Generator&quot; -f &quot;C:\Program Files\Common Files\Adobe\Plug-Ins\CC\Generator&quot;</CommandLine>
<CompanyName>Node.js</CompanyName>
<Version>4.3.1</Version>
<Description>Node.js: Server-side JavaScript</Description>
<modulelist>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ff6cbb20000</BaseAddress>
<Size>14237696</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\node.exe</Path>
<Version>4.3.1</Version>
<Company>Node.js</Company>
<Description>Node.js: Server-side JavaScript</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>78</ProcessIndex>
<ProcessId>12164</ProcessId>
<ParentProcessId>11408</ParentProcessId>
<ParentProcessIndex>77</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794962697229215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>conhost.exe</ProcessName>
<ImagePath>C:\Windows\system32\conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0x4</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffabe520000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SYSTEM32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.DLL</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>79</ProcessIndex>
<ProcessId>5612</ProcessId>
<ParentProcessId>904</ParentProcessId>
<ParentProcessIndex>22</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131794965205293998</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>dashost.exe</ProcessName>
<ImagePath>C:\Windows\system32\dashost.exe</ImagePath>
<CommandLine>dashost.exe {609e1ffd-7b4d-4dbc-a36f725917d81f2d}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Device Association Framework Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ff6559c0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\dashost.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Framework Provider Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabb1a0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\DAFWSD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF WSD Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabc970000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\dafupnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF UPnP Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>80</ProcessIndex>
<ProcessId>9720</ProcessId>
<ParentProcessId>9180</ParentProcessId>
<ParentProcessIndex>81</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794969418818027</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Windows10UpgraderApp.exe</ProcessName>
<ImagePath>C:\Windows10Upgrade\Windows10UpgraderApp.exe</ImagePath>
<CommandLine>&quot;C:\Windows10Upgrade\Windows10UpgraderApp.exe&quot;  /Install /ClientID Win10Upgrade:VNL:NHV18:{} /SkipEULA /PostEosUi</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>1.4.9200.22452</Version>
<Description>Помощник по обновлению Windows 10</Description>
<modulelist>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0xb30000</BaseAddress>
<Size>1875968</Size>
<Path>C:\Windows10Upgrade\Windows10UpgraderApp.exe</Path>
<Version>1.4.9200.22452</Version>
<Company>Microsoft Corporation</Company>
<Description>Помощник по обновлению Windows 10</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d6e0000</BaseAddress>
<Size>634880</Size>
<Path>C:\Windows\SysWOW64\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d780000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\SysWOW64\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d860000</BaseAddress>
<Size>1245184</Size>
<Path>C:\Windows\SysWOW64\MFC42u.dll</Path>
<Version>6.06.8063.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека MFCDLL - розничная версия</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6ded0000</BaseAddress>
<Size>630784</Size>
<Path>C:\Windows\SysWOW64\ODBC32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ODBC Driver Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfc0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfd0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SysWOW64\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e010000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows10Upgrade\Downloader.dll</Path>
<Version>1.4.9200.22452 (win8_ldr.180426-0600)</Version>
<Company>Microsoft Corporation</Company>
<Description>Downloader</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e050000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.DLL</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>82</ProcessIndex>
<ProcessId>8944</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795005508439638</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>fontdrvhost.exe</ProcessName>
<ImagePath>C:\Windows\system32\fontdrvhost.exe</ImagePath>
<CommandLine>&quot;fontdrvhost.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Usermode Font Driver Host</Description>
<modulelist>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ff654db0000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\system32\fontdrvhost.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Usermode Font Driver Host</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>83</ProcessIndex>
<ProcessId>6684</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795006053748558</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Microsoft.Photos.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe&quot; -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ff705e40000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bb10000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bc70000</BaseAddress>
<Size>3158016</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bf80000</BaseAddress>
<Size>2994176</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9c260000</BaseAddress>
<Size>20144128</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9d5a0000</BaseAddress>
<Size>29011968</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9fb20000</BaseAddress>
<Size>7950336</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.3_1.3.24201.0_x64__8wekyb3d8bbwe\SharedLibrary.dll</Path>
<Version></Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Shared Framework</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa03f0000</BaseAddress>
<Size>4546560</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\FaceSdkStoreWrapper.dll</Path>
<Version>16.425.0.0</Version>
<Company>Microsoft Corporation</Company>
<Description>FaceSdkStoreWrapper</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa0850000</BaseAddress>
<Size>2371584</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\MediaEngine.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab270000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\System32\Windows.AccountsControl.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Accounts Control</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\Windows.System.Diagnostics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Diagnostics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f60000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\CryptoWinRT.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto WinRT Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9270000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9b40000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x64__8wekyb3d8bbwe\mrt100_app.dll</Path>
<Version>1.4.24201.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabea30000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\Windows.Energy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Energy Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0fa0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1c70000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCOMP140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C/C++ OpenMP Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2c00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\clrcompression.dll</Path>
<Version>1.0.23123.00 built by: PROJECTKREL</Version>
<Company>Microsoft Corporation</Company>
<Description>ClrCompression</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SYSTEM32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\mrt100.dll</Path>
<Version>1.0.24120.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OleAut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>84</ProcessIndex>
<ProcessId>6208</ProcessId>
<ParentProcessId>12140</ParentProcessId>
<ParentProcessIndex>85</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795181740423780</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>OneDrive.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</ImagePath>
<CommandLine> /updateInstalled /background</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>18.131.0701.0007</Version>
<Description>Microsoft OneDrive</Description>
<modulelist>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x11f0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x55a0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSync.Resources.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\MSHTML.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6bab0000</BaseAddress>
<Size>4472832</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Widgets.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d210000</BaseAddress>
<Size>4993024</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Gui.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\Wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ce0000</BaseAddress>
<Size>1519616</Size>
<Path>C:\Windows\SysWOW64\wpc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека параметров родительского контроля</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70f00000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71200000</BaseAddress>
<Size>708608</Size>
<Path>C:\Windows\SysWOW64\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x712b0000</BaseAddress>
<Size>602112</Size>
<Path>C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71350000</BaseAddress>
<Size>2867200</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Quick.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71630000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x716b0000</BaseAddress>
<Size>1294336</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LIBEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x717f0000</BaseAddress>
<Size>2637824</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Qml.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71a80000</BaseAddress>
<Size>4796416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Core.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71f20000</BaseAddress>
<Size>6033408</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SyncEngine.DLL</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Sync Engine</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72530000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72550000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72810000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72820000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SysWOW64\MicrosoftAccountTokenProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Token Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72850000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\SysWOW64\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728b0000</BaseAddress>
<Size>135168</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncFAL.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDriveFile Sync FAL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\SysWOW64\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72bb0000</BaseAddress>
<Size>1105920</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\platforms\qwindows.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e90000</BaseAddress>
<Size>299008</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SSLEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ee0000</BaseAddress>
<Size>950272</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Network.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72fd0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\loadperf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Загрузка и выгрузка счетчиков производительности</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ff0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\pdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль поддержки данных производительности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73040000</BaseAddress>
<Size>253952</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5WinExtras.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73080000</BaseAddress>
<Size>880640</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ADAL.dll</Path>
<Version>1.0.2110.0526</Version>
<Company>Microsoft</Company>
<Description>ADAL.Native</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73160000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WSOCK32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73170000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SysWOW64\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x731d0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\WnsClientApi.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive WNS Client Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73240000</BaseAddress>
<Size>520192</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LogUploader.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive Sync LogUploader Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x732c0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncViews.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Qt Components</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73400000</BaseAddress>
<Size>159744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\UpdateRingSettings.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Ring Settings</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73430000</BaseAddress>
<Size>1748992</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncSessions.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>P2P Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x735e0000</BaseAddress>
<Size>671744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\RemoteAccess.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73690000</BaseAddress>
<Size>188416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Telemetry.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Telemetry Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ETWLog.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>ETW Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736d0000</BaseAddress>
<Size>3600384</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncClient.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Client</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73af0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LoggingPlatform.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Logging Platform</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73dc0000</BaseAddress>
<Size>1171456</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ucrtbase.dll</Path>
<Version>10.0.17134.12 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73fb0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\MSWSOCK.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74090000</BaseAddress>
<Size>462848</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\MSVCP140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\VCRUNTIME140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74220000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>86</ProcessIndex>
<ProcessId>6140</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795747339404666</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=764E64A4EA650A23B18EB059FF0B4B51 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=764E64A4EA650A23B18EB059FF0B4B51 --renderer-client-id=106 --mojo-platform-channel-handle=6612 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>87</ProcessIndex>
<ProcessId>11432</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755605761168</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=9DD318D38190D474A9A0F5AFD262A449 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=9DD318D38190D474A9A0F5AFD262A449 --renderer-client-id=109 --mojo-platform-channel-handle=4152 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>88</ProcessIndex>
<ProcessId>10384</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755746873891</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=7E669976FFDCEE94D9B90B02CADE1179 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E669976FFDCEE94D9B90B02CADE1179 --renderer-client-id=112 --mojo-platform-channel-handle=5412 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>90</ProcessIndex>
<ProcessId>6936</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795756360200321</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --renderer-client-id=116 --mojo-platform-channel-handle=4024 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>92</ProcessIndex>
<ProcessId>9252</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795764376794664</CreateTime>
<FinishTime>131795777590883773</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>wmiprvse.exe</ProcessName>
<ImagePath>C:\Windows\system32\wbem\wmiprvse.exe</ImagePath>
<CommandLine>C:\Windows\system32\wbem\wmiprvse.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Description>WMI Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ff7fdea0000</BaseAddress>
<Size>516096</Size>
<Path>C:\Windows\system32\wbem\wmiprvse.exe</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Provider Host</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffabee10000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770662992743</Timestamp>
<BaseAddress>0x7ffac1e20000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770663908408</Timestamp>
<BaseAddress>0x7ffac1f50000</BaseAddress>
<Size>471040</Size>
<Path>C:\Windows\System32\wbem\esscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770664479193</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770663594346</Timestamp>
<BaseAddress>0x7ffac7cc0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\wbem\wmiprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770664758405</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wmiclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770663902811</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661522</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>93</ProcessIndex>
<ProcessId>8764</ProcessId>
<ParentProcessId>360</ParentProcessId>
<ParentProcessIndex>26</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131795765999556420</CreateTime>
<FinishTime>131795773594672986</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>AUDIODG.EXE</ProcessName>
<ImagePath>C:\Windows\system32\AUDIODG.EXE</ImagePath>
<CommandLine>C:\Windows\system32\AUDIODG.EXE 0x310</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Изоляция графов аудиоустройств Windows </Description>
<modulelist>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ff644450000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\system32\AUDIODG.EXE</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Изоляция графов аудиоустройств Windows </Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffab02b0000</BaseAddress>
<Size>1802240</Size>
<Path>C:\Windows\System32\WMALFXGFXDSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SysFx DSP</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffabc1a0000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\System32\audiokse.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Audio Ks Endpoint</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffabd210000</BaseAddress>
<Size>552960</Size>
<Path>C:\Windows\System32\audioeng.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Audio Engine</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661619</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>94</ProcessIndex>
<ProcessId>4580</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795769397390596</CreateTime>
<FinishTime>131795772585329431</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchProtocolHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchProtocolHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchProtocolHost.exe&quot; Global\UsGthrFltPipeMssGthrPipe285_ Global\UsGthrCtrlFltPipeMssGthrPipe285 1 -2147483646 &quot;Software\Microsoft\Windows Search&quot; &quot;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)&quot; &quot;C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc&quot; &quot;DownLevelDaemon&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Protocol Host</Description>
<modulelist>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ff71ad80000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\system32\SearchProtocolHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Protocol Host</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\system32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\mssph.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик протоколов поиска Microsoft</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\Msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795772585257264</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661738</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>95</ProcessIndex>
<ProcessId>8304</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795770292311800</CreateTime>
<FinishTime>131795773336859980</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k wsappx</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>96</ProcessIndex>
<ProcessId>10360</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795770393041927</CreateTime>
<FinishTime>131795772585920370</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchFilterHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchFilterHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchFilterHost.exe&quot; 0 708 712 720 8192 716 </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Filter Host</Description>
<modulelist>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ff68a750000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\SearchFilterHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Filter Host</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffab8fe0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Program Files\Common Files\Microsoft Shared\Filters\offfiltx.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Office Open XML Format Filter</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\query.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека служебной программы индексирования содержимого</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661946</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>98</ProcessIndex>
<ProcessId>6080</ProcessId>
<ParentProcessId>84</ParentProcessId>
<ParentProcessIndex>97</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795771125310655</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MCLauncher.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe&quot; </CommandLine>
<CompanyName></CompanyName>
<Version>1.0</Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795771127806606</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>2830336</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Version>1.0</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771129292604</Timestamp>
<BaseAddress>0x750000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771335510731</Timestamp>
<BaseAddress>0x11000000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771334241016</Timestamp>
<BaseAddress>0x12000000</BaseAddress>
<Size>360448</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771129285523</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795771129286235</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795771129295328</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795771135408057</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795771129575672</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129398434</Timestamp>
<BaseAddress>0x66680000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771136825814</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795771129423112</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771129349562</Timestamp>
<BaseAddress>0x6b830000</BaseAddress>
<Size>2584576</Size>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795771329638947</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795771329610149</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795771329592759</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795771136045859</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795771131298623</Timestamp>
<BaseAddress>0x6d180000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795771136082794</Timestamp>
<BaseAddress>0x6dca0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Script Runtime</Description>
</module>
<module>
<Timestamp>131795771133718253</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795771129406131</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795771329618480</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795771329601483</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795771336447829</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771135435621</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795771135446667</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771136073867</Timestamp>
<BaseAddress>0x70e90000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Script Host Runtime Library</Description>
</module>
<module>
<Timestamp>131795771135423397</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795771135552456</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795771136181434</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771328759427</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771135541570</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795771347140137</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795771347110306</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795771135314174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771347090516</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795771347075776</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795771328179609</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795771130913562</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795771135359123</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795771129415027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795771130899582</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795771133098293</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795771132990161</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795771131765102</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795771129389543</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795771129317462</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795771129360685</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795771129360034</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771129496759</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795771129358136</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129357408</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795771129365891</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795771129359203</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795771129353720</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771135412052</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795771129350362</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795771129366695</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795771136054082</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795771131750596</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795771129363162</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795771328737550</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795771135228888</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795771129301509</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771129362062</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795771135227735</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795771129363985</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795771129356607</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795771129364960</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795771129354665</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795771129370252</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795771129352041</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795771129367584</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795771129351257</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771129361361</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795771129369244</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129368545</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795771131168008</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795771129352931</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771133704572</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795771129355632</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795771347076821</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795771127807387</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795771127807116</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>100</ProcessIndex>
<ProcessId>11424</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795771175195605</CreateTime>
<FinishTime>131795772369655492</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>backgroundTaskHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\backgroundTaskHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\backgroundTaskHost.exe&quot; -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Background Task Host</Description>
<modulelist>
<module>
<Timestamp>131795771215003918</Timestamp>
<BaseAddress>0x7ff7e0340000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\backgroundTaskHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Task Host</Description>
</module>
<module>
<Timestamp>131795771218915398</Timestamp>
<BaseAddress>0x7ffab52c0000</BaseAddress>
<Size>2445312</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771248257542</Timestamp>
<BaseAddress>0x7ffab5db0000</BaseAddress>
<Size>9781248</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771221125701</Timestamp>
<BaseAddress>0x7ffab9d50000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771219014731</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795771244982867</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795771253593996</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795771249779530</Timestamp>
<BaseAddress>0x7ffabe770000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771220596574</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795771221984040</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795771229903710</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795771222450040</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795771218944309</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795771217261903</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795771221184651</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795771219025520</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795771248269029</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795771221208674</Timestamp>
<BaseAddress>0x7ffac3bf0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionMgr.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana Action Manager</Description>
</module>
<module>
<Timestamp>131795771244919374</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795771228411342</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795771228399176</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795771238266123</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795771244908192</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795771219005372</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795771218728294</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795771219113271</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795771217463389</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795771229000770</Timestamp>
<BaseAddress>0x7ffac6bb0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\Windows.Cortana.PAL.Desktop.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.PAL.Desktop</Description>
</module>
<module>
<Timestamp>131795771217062375</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795771218870257</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795771221134703</Timestamp>
<BaseAddress>0x7ffac7c50000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\BingConfigurationClient.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bing Configuration Client DLL</Description>
</module>
<module>
<Timestamp>131795771250869876</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795771215247819</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795771246630966</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771218005942</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795771215028077</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795771218142921</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795771218992988</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795771215190452</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795771219041691</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795771248177767</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795771219101100</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795771219186292</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795771219053691</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795771219065792</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771215202412</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795771215165891</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795771228948589</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795771217446746</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795771219027312</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795771216016613</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771215052508</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771215054137</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795771216015001</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795771215602268</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795771228947467</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795771215010911</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771219026473</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795771218982293</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771218945076</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795771215053234</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795771215050566</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795771215009974</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771216015829</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771219028093</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795771216029532</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795771216013945</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771215051746</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795771218916542</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795771251394640</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795771228949614</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795771215191449</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795771215004228</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>102</ProcessIndex>
<ProcessId>5352</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777512297277</CreateTime>
<FinishTime>131795777577947395</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=utility --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --lang=ru --service-sandbox-type=utility --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --service-request-channel-token=DEB3ACFB74E724388EDD708B8EC58AAC --process-name=&quot;Data Decoder Service&quot; --mojo-platform-channel-handle=6360 --ignored=&quot; --type=renderer &quot; /prefetch:8</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777515297838</Timestamp>
<BaseAddress>0x1030000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777512642132</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777515299019</Timestamp>
<BaseAddress>0x5480000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777524260638</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777515289424</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777515290624</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777515302177</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777515363490</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777524463548</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777524511218</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777524499734</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777524575772</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777524451950</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777524589185</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777524415365</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777524378747</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777524559678</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777524390458</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777515438231</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777524487452</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777524529620</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777524402307</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777524475450</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777524546438</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777515456134</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777515414823</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777524365005</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777515403765</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777515426052</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777515327766</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777515326697</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777515482316</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777515341101</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777515339815</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777515351055</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777515325414</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777515346736</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777515330858</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777515322779</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777515352322</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777524351432</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777524349996</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777515342564</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777524352750</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777515310300</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777515324131</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777524354141</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777515321247</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777515338333</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777515343891</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777515334745</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777515349559</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777515353626</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777515348271</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777515329268</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777524348384</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777524346680</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777515378789</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777515345356</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777524340305</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777515336197</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777524530922</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777512642733</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777512642464</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>103</ProcessIndex>
<ProcessId>12928</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777540701988</CreateTime>
<FinishTime>131795777572368143</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=EF6B4169C61A7709F19FAC37385B88FF --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=EF6B4169C61A7709F19FAC37385B88FF --renderer-client-id=118 --mojo-platform-channel-handle=5600 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777544816074</Timestamp>
<BaseAddress>0x1000000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777540824769</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777544817293</Timestamp>
<BaseAddress>0x5540000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777545695386</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777544807438</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777544808477</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777544820274</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777547474848</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777547451922</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777547398829</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777547412145</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777547425421</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777547366131</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777547383954</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777544902779</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777547050478</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777547101720</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777547089255</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777547163695</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777547039183</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777547181182</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777547026978</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777545741840</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777547147720</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777546997974</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777545424927</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777547076749</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777547113614</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777547011732</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777547062273</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777547131578</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777547437013</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777545453020</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777544956879</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777545724538</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777544945423</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777544971328</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777544856995</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777544855901</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777545476966</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777544877442</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777544875993</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777544888660</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777544854319</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777544883634</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777544859849</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777544851504</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777544889990</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777545711131</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777545709724</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777544879143</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777545712278</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777544828669</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777544852958</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777545713874</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777544844417</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777544874425</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777544880528</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777544863758</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777544886945</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777544891320</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777544885513</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777544858181</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777545707510</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777545706130</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777544920230</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777544881947</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777545700210</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777544871942</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777547117462</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777540825345</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777540825087</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>104</ProcessIndex>
<ProcessId>12696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777567759490</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=E83DB721798C8A70C76CD26F6F4EE1BC --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=E83DB721798C8A70C76CD26F6F4EE1BC --renderer-client-id=119 --mojo-platform-channel-handle=7052 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777567991690</Timestamp>
<BaseAddress>0xc00000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777567961139</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777569452751</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777567980184</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777567981270</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777567994943</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777570994535</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777570968696</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777570908362</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777570920904</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777570943637</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777570874151</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777570891841</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777568100773</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777570569484</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777570619251</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777570607590</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777570676211</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777570557202</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777570691164</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777570539079</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777569494420</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777570658737</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777569526517</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777569154123</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777570594964</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777570630821</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777570523174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777570582120</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777570646486</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777570953652</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777569213807</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777568156054</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777569481011</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777568142933</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777568179155</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777568043561</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777568042430</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777569239058</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777568075566</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777568073430</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777568086784</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777568041126</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777568081914</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777568046844</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777568038347</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777568088134</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777569468247</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777569466798</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777568077279</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777569469408</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777568024100</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777568039823</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777569470854</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777568036731</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777568054568</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777568078714</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777568050811</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777568084892</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777568089486</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777568083413</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777568044758</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777569464930</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777569463567</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777568116745</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777568080182</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777569457550</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777568052363</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777570632192</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777567961904</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777567961630</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>105</ProcessIndex>
<ProcessId>3772</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777578913885</CreateTime>
<FinishTime>131795777634085840</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=utility --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --lang=ru --service-sandbox-type=utility --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --service-request-channel-token=ABCF409A7678936923419CA50C501EDC --process-name=&quot;Data Decoder Service&quot; --mojo-platform-channel-handle=744 --ignored=&quot; --type=renderer &quot; /prefetch:8</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777579128753</Timestamp>
<BaseAddress>0xe30000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777579111989</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777580914723</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777579118940</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777579120176</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777579131942</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777579219043</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777582176680</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777582226861</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777582214961</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777582297546</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777582164864</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777582309468</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777582100365</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777580956121</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777582281413</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777580978864</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777579935579</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777582202045</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777582242381</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777582086365</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777582188438</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777582258004</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777579955314</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777579287925</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777580942792</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777579276056</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777579299716</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777579160232</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777579159124</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777579983324</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777579173778</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777579172440</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777579184306</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777579157794</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777579179147</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777579163189</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777579153905</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777579185555</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777580930349</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777580928881</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777579175221</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777580931410</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777579141102</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777579155226</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777580932676</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777579152298</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777579171004</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777579176504</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777579167353</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777579182821</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777579186833</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777579180890</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777579161706</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777580927138</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777580925844</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777579235572</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777579177837</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777580919815</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777579168782</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777582243780</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777579113116</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777579112823</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>106</ProcessIndex>
<ProcessId>5556</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777595302537</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=3ADFA2396247AD5E547F61590603D06D --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=3ADFA2396247AD5E547F61590603D06D --renderer-client-id=121 --mojo-platform-channel-handle=6636 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777595490187</Timestamp>
<BaseAddress>0x1020000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595475498</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595491301</Timestamp>
<BaseAddress>0x5550000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777596381097</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595481485</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777595482474</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777595494304</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777597543015</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777597521210</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777597472595</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777597484525</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777597497517</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777597428793</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777597448444</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777595565558</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777597103476</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777597165296</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777597153510</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777597221087</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777597072535</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777597233493</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777597059294</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777596424202</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777597205195</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777596436120</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777596128973</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777597128037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777597177209</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777597044137</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777597116160</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777597192860</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777597506812</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777596148547</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777595627397</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777596410831</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777595610560</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777595638942</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777595529014</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777595527983</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777596182171</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777595541526</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777595540326</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777595551866</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777595526606</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777595547732</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777595531563</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777595524005</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777595553384</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777596396507</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777596394953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777595543299</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777596397607</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777595508927</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595525398</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777596398892</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777595522182</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777595538927</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777595544568</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777595535397</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777595550455</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777595554628</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777595549128</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777595530150</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777596393437</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777596392132</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777595583766</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777595545878</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777596385979</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777595536930</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777597178434</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777595476066</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777595475814</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>107</ProcessIndex>
<ProcessId>12560</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777638339022</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=utility --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --lang=ru --service-sandbox-type=utility --utility-allowed-dir=&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data\file_rating&quot; --utility-enable-file-rating --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --service-request-channel-token=641C5D89318E923EF94DCE862505059D --process-name=&quot;Антивирусная проверка загруженных файлов&quot; --mojo-platform-channel-handle=6132 --ignored=&quot; --type=renderer &quot; /prefetch:8</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777638514999</Timestamp>
<BaseAddress>0x9a0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777638499252</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777640777675</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777638505336</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777638506616</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777638520771</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777643013198</Timestamp>
<BaseAddress>0x68970000</BaseAddress>
<Size>1605632</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\7z.dll</Path>
<Version>16.04</Version>
<Company>Igor Pavlov</Company>
<Description>7z Plugin</Description>
</module>
<module>
<Timestamp>131795777644063584</Timestamp>
<BaseAddress>0x6cea0000</BaseAddress>
<Size>741376</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\unpacki.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795777644499194</Timestamp>
<BaseAddress>0x6d050000</BaseAddress>
<Size>188416</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\ph.dll</Path>
<Version>1.0.0.3</Version>
<Company>Yandex LLC</Company>
<Description>PH</Description>
</module>
<module>
<Timestamp>131795777638678022</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777641007171</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777641094369</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777641078940</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777641162760</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777640993878</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777641193425</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777640980953</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777640934358</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777641144289</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777640949510</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777638805651</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777641060291</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777641111375</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777640964374</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777641045959</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777641129849</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777638824119</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777638777842</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777640905386</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777638757989</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777638790654</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777638640639</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777638639616</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777638865082</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777638653602</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777638652361</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777638664931</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777638638334</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777638660518</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777638643504</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777638635699</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777638666147</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777640885499</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777640884150</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777638655024</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777640887705</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777638622442</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777638636998</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777640890927</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777638634183</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777638650757</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777638657739</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777638647299</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777638663396</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777638667522</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777638661911</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777638641764</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777640882612</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777640878814</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777638718043</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777638659168</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777640867696</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777638648757</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777641112838</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777638499795</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777638499542</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>108</ProcessIndex>
<ProcessId>2436</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795777644009218</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchProtocolHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchProtocolHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchProtocolHost.exe&quot; Global\UsGthrFltPipeMssGthrPipe286_ Global\UsGthrCtrlFltPipeMssGthrPipe286 1 -2147483646 &quot;Software\Microsoft\Windows Search&quot; &quot;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)&quot; &quot;C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc&quot; &quot;DownLevelDaemon&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Protocol Host</Description>
<modulelist>
<module>
<Timestamp>131795777645159014</Timestamp>
<BaseAddress>0x7ff71ad80000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\SearchProtocolHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Protocol Host</Description>
</module>
<module>
<Timestamp>131795777646253333</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\System32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795777674143166</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795777653911361</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795777653958760</Timestamp>
<BaseAddress>0x7ffac7cd0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\mssph.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик протоколов поиска Microsoft</Description>
</module>
<module>
<Timestamp>131795777646404209</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795777672706217</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777662406241</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795777654238495</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\authz.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795777646239073</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777646227946</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777646240001</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777646230573</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777646209419</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777646219266</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777646236729</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777646225633</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777646226951</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777646182523</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777646208766</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777672880184</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777672879070</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777646208012</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777646218296</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777646204698</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777648403085</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777646181578</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777646229758</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777646359182</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777646231420</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777646217468</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777646223693</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777651470786</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777646228871</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777646224544</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777645159316</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>109</ProcessIndex>
<ProcessId>12008</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795777651421021</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchFilterHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchFilterHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchFilterHost.exe&quot; 0 708 712 720 8192 716 </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Filter Host</Description>
<modulelist>
<module>
<Timestamp>131795777651457218</Timestamp>
<BaseAddress>0x7ff68a750000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\SearchFilterHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Filter Host</Description>
</module>
<module>
<Timestamp>131795777652430059</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\System32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795777653510417</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795777652527425</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777652473355</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777652337295</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777652352101</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777652470728</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777653516465</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777652314737</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777652336608</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777652335832</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777652348843</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777652333560</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777653216837</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777652313695</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777652472487</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777652465968</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777652468742</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777652346577</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777652353955</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777652357088</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777651457501</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>1</ProcessIndex>
<ProcessId>11372</ProcessId>
<ParentProcessId>10560</ParentProcessId>
<ParentProcessIndex>2</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770632346846</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon64.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Temp\Procmon64.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Temp\Procmon64.exe&quot;  /originalpath &quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot;</CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>2</ProcessIndex>
<ProcessId>10560</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770594566098</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon.exe</ProcessName>
<ImagePath>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot; </CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x1000000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x62530000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\RICHED20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cd0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72520000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\Riched32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wrapper Dll for Richedit 1.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>3</ProcessIndex>
<ProcessId>4048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765778109600457</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchIndexer.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchIndexer.exe</ImagePath>
<CommandLine>C:\Windows\system32\SearchIndexer.exe /Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Индексатор службы Microsoft Windows Search</Description>
<modulelist>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ff63db40000</BaseAddress>
<Size>929792</Size>
<Path>C:\Windows\system32\SearchIndexer.exe</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индексатор службы Microsoft Windows Search</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\MSSRCH.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabd990000</BaseAddress>
<Size>720896</Size>
<Path>C:\Windows\system32\ElsLad.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ELS Language Detection</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\Msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>4</ProcessIndex>
<ProcessId>580</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776275984299</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>services.exe</ProcessName>
<ImagePath>C:\Windows\system32\services.exe</ImagePath>
<CommandLine>C:\Windows\system32\services.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Приложение служб и контроллеров</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>6</ProcessIndex>
<ProcessId>664</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776282506625</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k DcomLaunch</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc6a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\SebBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; SEB Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc7e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\SmartCardBackgroundPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartCardBackgroundPolicy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8c0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\CbtBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; CBT Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8d0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\ACPBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; ACP Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc900000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BackgroundMediaPolicy.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Background Media Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\RmClient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca740000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\DAB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL брокера активности компьютера</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacabd0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\OnDemandBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OnDemandBrokerClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacae70000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\systemeventsbrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер системных событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacafc0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy RM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb010000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SYSTEM32\psmserviceexthost.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager PSM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb390000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\psmsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process State Manager (PSM) Service</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb4f0000</BaseAddress>
<Size>794624</Size>
<Path>c:\windows\system32\bisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба инфраструктуры фоновых задач</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb720000</BaseAddress>
<Size>344064</Size>
<Path>c:\windows\system32\mintdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>c:\windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb820000</BaseAddress>
<Size>712704</Size>
<Path>C:\Windows\SYSTEM32\tdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8d0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\umpoext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения службы пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8f0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\umpo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb940000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\umpnpmgr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский режим службы самонастройки (Plug-and-Play)</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>7</ProcessIndex>
<ProcessId>884</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776292813936</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9230000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\bluetoothapis.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Usermode Api host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9580000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\BthRadioMedia.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab95a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WlanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wlan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaba920000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\rmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Radio Manager API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabae80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\NfcRadioMedia.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NFC Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabb8a0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\XboxGipRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Xbox GIP Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc0e0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\WwanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wwan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac78c0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\shacct.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Classes</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7f80000</BaseAddress>
<Size>208896</Size>
<Path>c:\windows\system32\wscsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8490000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\dhcpcore6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8c90000</BaseAddress>
<Size>385024</Size>
<Path>c:\windows\system32\dhcpcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>c:\windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac9c30000</BaseAddress>
<Size>1732608</Size>
<Path>c:\windows\system32\wevtsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба протоколирования событий</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca2a0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\timebrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер событий времени</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca330000</BaseAddress>
<Size>36864</Size>
<Path>c:\windows\system32\nrpsrv.DLL</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Name Resolution Proxy (NRP) RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4d0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lmhsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб транспорта TCPIP NetBios</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>8</ProcessIndex>
<ProcessId>0</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:00000000</AuthenticationId>
<CreateTime>131765775874898587</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>4294967295</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity></Integrity>
<Owner></Owner>
<ProcessName>Idle</ProcessName>
<ImagePath>Idle</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>9</ProcessIndex>
<ProcessId>4</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775907178738</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>System</ProcessName>
<ImagePath>System</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b6e00000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\System32\win32kfull.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Win32k Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7190000</BaseAddress>
<Size>1576960</Size>
<Path>C:\Windows\System32\win32kbase.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Базовый драйвер ядра Win32k</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7320000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\TSDDD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Framebuffer Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7330000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\cdd.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Canonical Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b74a0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\win32k.sys</Path>
<Version>10.0.14393.594 (rs1_release_inmarket.161213-1754)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Multi-User Win32 Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80278934000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\kd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Kernel Debugger</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80279678000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92e00000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\ksecdd.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ee0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\cmimcext.sys</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Configuration Manager Initial Configuration Extension Host Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ef0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\ntosext.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTOS extension host driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92fa0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\drivers\cng.sys</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Cryptography, Next Generation</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93040000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\system32\drivers\Wdf01000.sys</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения платформы драйвера режима ядра</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93120000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\drivers\WDFLDR.SYS</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Mode Driver Framework Loader</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93140000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\Drivers\acpiex.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPIEx Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93170000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\Drivers\WppRecorder.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WPP Trace Recorder</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93180000</BaseAddress>
<Size>733184</Size>
<Path>C:\Windows\System32\drivers\ACPI.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPI драйвер для NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93240000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\WMILIB.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMILIB WMI support library Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93260000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\intelpep.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Power Engine Plugin</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93280000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\drivers\WindowsTrustedRT.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932a0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Service Proxy Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\pcw.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Performance Counters for Windows Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932d0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\msisadrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ISA Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932e0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\isapnp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер шины PNP ISA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932f0000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\drivers\pci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Plug and Play PCI-перечислитель</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93350000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\vdrvroot.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Drive Root Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93370000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\drivers\pdc.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Power Dependency Coordinator Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933a0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\CEA.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation Kernel Mode Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\partmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Partition driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\nvraid.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) RAID Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93420000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\CLASSPNP.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI Class System Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93490000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\vmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Дочерний драйвер шины виртуальной машины Microsoft Hyper-V</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d934c0000</BaseAddress>
<Size>1212416</Size>
<Path>C:\Windows\System32\drivers\NDIS.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS (Network Driver Interface Specification)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d935f0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\drivers\NETIO.SYS</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network I/O Subsystem</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93670000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\hvsocket.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Hyper-V Socket Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\vmbkmcl.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V VMBus KMCL</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\winhv.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Hypervisor Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\pciide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Generic PCI IDE Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936e0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\PCIIDEX.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PCI IDE Bus Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93700000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\drivers\spaceport.sys</Path>
<Version>10.0.14393.1914 (rs1_release_inmarket.171117-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Spaces Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937a0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\intelide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel PCI IDE Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937b0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\volmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937d0000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\drivers\volmgrx.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер расширения диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93830000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\drivers\mountmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер точек подключения</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93850000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\nvstor.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) Sata Performance Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\drivers\storport.sys</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Storage Port Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93910000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\atapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI IDE Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93920000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\System32\drivers\ataport.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93960000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\storahci.sys</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS AHCI Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93990000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\stornvme.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft NVM Express Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\drivers\EhStorClass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enhanced Storage Class driver for IEEE 1667 devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\fileinfo.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FileInfo Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939f0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\Drivers\Wof.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр оверлея Windows</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93a80000</BaseAddress>
<Size>2297856</Size>
<Path>C:\Windows\System32\Drivers\NTFS.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер файловой системы NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\storvsc.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage VSC Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cd0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\Drivers\Fs_Rec.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>File System Recognizer Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93d10000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\System32\drivers\USBPORT.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта USB 1.1 и 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93db0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\mcupdate_GenuineIntel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Microcode Update Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93e50000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\System32\drivers\CLFS.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Common Log File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ec0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\tm.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Transaction Manager Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ef0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\PSHED.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер аппаратных ошибок, специфичных для платформы</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f10000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\BOOTVID.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>VGA Boot Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f20000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\FLTMGR.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер фильтров файловых систем Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\drivers\msrpc.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Remote Procedure Call Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94000000</BaseAddress>
<Size>430080</Size>
<Path>C:\Windows\System32\drivers\fwpkclnt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FWP/IPsec Kernel-Mode API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94070000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\wfplwfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WFP NDIS 6.30 Lightweight Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d940b0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DRIVERS\fvevol.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BitLocker Drive Encryption Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94160000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\volume.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94170000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\System32\drivers\volsnap.sys</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume Shadow Copy driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d941e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\scmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Class Memory Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\drivers\rdyboost.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ReadyBoost Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94250000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\Drivers\mup.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер поставщика множественных UNC</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94280000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\drivers\iorate.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>I/O rate control Filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942a0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\disk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PnP Disk Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942e0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\crashdmp.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crash Dump Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d943c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\drivers\cdrom.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI CD-ROM Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94400000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\drivers\filecrypt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows sandboxing and encryption filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94420000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\tbs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Export driver for kernel mode TPM API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94430000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Null.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NULL Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94440000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Beep.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BEEP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94450000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\BasicDisplay.sys</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94470000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\watchdog.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Watchdog Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94490000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\System32\drivers\dxgkrnl.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Kernel</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\BasicRender.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Render Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\Npfs.SYS</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPFS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94700000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\DRIVERS\tdx.sys</Path>
<Version>10.0.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDI Translation Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94740000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\DRIVERS\netbt.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>MBT Transport driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94790000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\drivers\afd.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер дополнительных функций для Winsock</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94830000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\vwififlt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual WiFi Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94850000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\pacer.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Планировщик пакетов QoS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\drivers\netbios.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetBIOS interface driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d948a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\rdbss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер подсистемы буферизации перенаправленного диска</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94920000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\drivers\csc.sys</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Client Side Caching Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\nsiproxy.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\npsvctrig.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Named pipe service triggers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\gpuenergydrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GPU Energy Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a00000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Drivers\dfsc.sys</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DFS Namespace Client Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a50000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\DRIVERS\ahcache.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Compatibility Cache</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a90000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-Transport Composite Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\kdnic.sys</Path>
<Version>6.01.00.0000 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Kernel Debugger Network Miniport</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ac0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\drivers\umbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User-Mode Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ae0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\i8042prt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта i8042</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b10000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\drivers\kbdclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса клавиатуры</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b30000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\mouclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса мыши</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b80000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\HDAudBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ba0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\drivers\portcls.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Port Class (Class Driver for Port/Miniport Devices)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c10000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\drmk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trusted Audio Drivers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c40000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\drivers\ks.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel CSA Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cb0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\usbohci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OHCI USB Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\CmBatt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Control Method Battery Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cd0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\BATTC.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Class Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ce0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\intelppm.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Processor Device Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d10000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\NdisVirtualBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечислитель виртуальных сетевых адаптеров (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d20000</BaseAddress>
<Size>2588672</Size>
<Path>C:\Windows\System32\drivers\tcpip.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fa0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\swenum.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Plug and Play Software Device Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fb0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\rdpbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft RDP Bus Device driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95200000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\DRIVERS\udfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UDF File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95280000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\Drivers\dump_diskdump.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d952c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\Drivers\dump_storahci.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95310000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\Drivers\dump_dumpfve.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95330000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\system32\drivers\HTTP.sys</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Стек протокола HTTP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95450000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\drivers\WudfPf.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - User-mode Driver Framework Platform Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95470000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\DRIVERS\bowser.sys</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Lan Manager Datagram Receiver Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d954a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT SMB Minirdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95520000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\mpsdrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Protection Service Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95540000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb20.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB 2.0 Redirector</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95580000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\DRIVERS\srvnet.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Network driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d955d0000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\System32\DRIVERS\srv2.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер сервера SMB 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95690000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb10.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB Downlevel SubRdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d956e0000</BaseAddress>
<Size>573440</Size>
<Path>C:\Windows\System32\DRIVERS\srv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95770000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\tcpipreg.sys</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>TCP/IP Registry Compatibility Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95860000</BaseAddress>
<Size>684032</Size>
<Path>C:\Windows\System32\drivers\dxgmms2.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics MMS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95910000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\luafv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра виртуализации файлов LUA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95960000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\storqosflt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр качества обслуживания хранилища</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95980000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\registry.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Registry Containment Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959a0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\drivers\lltdio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Mapper I/O Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959c0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\drivers\mslldp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер протокола Microsoft LLDP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\rspndr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Responder Driver for NDIS 6</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95ae0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\USBD.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Universal Serial Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95af0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\DRIVERS\HdAudio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Function Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95b60000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\ksthunk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Streaming WOW Thunk Service</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95bc0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\HIDPARSE.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hid Parsing Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97020000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\Drivers\360AntiHacker64.sys</Path>
<Version>1.0.0.1149</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络防黑模块</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97060000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\DRIVERS\360AvFlt.sys</Path>
<Version>1.1.0.1056</Version>
<Company>360.cn</Company>
<Description>360杀毒 文件监控驱动</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97080000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\DRIVERS\BAPIDRV64.sys</Path>
<Version>2.0.0.1221</Version>
<Company>360.cn</Company>
<Description>BAPIDRV</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d970c0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\drivers\360netmon.sys</Path>
<Version>2.1.11.5195</Version>
<Company>360.cn</Company>
<Description>360netmon</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97120000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\system32\DRIVERS\360Box64.sys</Path>
<Version>2.1.0.1253</Version>
<Company>360.cn</Company>
<Description>360Box64</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97180000</BaseAddress>
<Size>811008</Size>
<Path>C:\Windows\system32\DRIVERS\360FsFlt.sys</Path>
<Version>6.9.1.1751</Version>
<Company>360.cn</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97330000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\hidusb.sys</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>USB Miniport Driver for Input Devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97350000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\HIDCLASS.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека классов HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97380000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\mouhid.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра мыши HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97390000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\rassstp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS SSTP Miniport Call Manager</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973b0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\DRIVERS\NDProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\drivers\AgileVpn.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер вызовов минипорта RAS Agile VPN</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97420000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\drivers\rasl2tp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS L2TP mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97460000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\raspptp.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Peer-to-Peer Tunneling Protocol</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974a0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\raspppoe.sys</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS PPPoE mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\DRIVERS\ndistapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS 3.0 connection wrapper driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974d0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\drivers\ndiswan.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS PPP Framing Driver (Strong Encryption)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97510000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\DRIVERS\wanarp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS Remote Access and Routing ARP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97550000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\E1G6032E.sys</Path>
<Version>8.4.13.0 built by: WinDDK</Version>
<Company>Intel Corporation</Company>
<Description>Intel(R) PRO/1000 Adapter NDIS 6 deserialized driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97580000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\tunnel.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер интерфейса туннеля (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97600000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\Drivers\PROCMON24.SYS</Path>
<Version>3.10</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97a60000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\system32\drivers\peauth.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Protected Environment Authentication and Authorization Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b30000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\Ndu.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Network Data Usage Monitoring Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b60000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\drivers\mmcss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMCSS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97bb0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\condrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Driver</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>10</ProcessIndex>
<ProcessId>320</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775908989732</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>smss.exe</ProcessName>
<ImagePath>C:\Windows\System32\smss.exe</ImagePath>
<CommandLine>\SystemRoot\System32\smss.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер сеанса  Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>11</ProcessIndex>
<ProcessId>3108</ProcessId>
<ParentProcessId>3092</ParentProcessId>
<ParentProcessIndex>12</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777624392598</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Explorer.EXE</ProcessName>
<ImagePath>C:\Windows\Explorer.EXE</ImagePath>
<CommandLine>C:\Windows\Explorer.EXE</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x31b0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5db0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Program Files\Uninstall Tool\utshellext.dll</Path>
<Version>1.1.0.15</Version>
<Company>CrystalIDEA Software</Company>
<Description>Uninstall Tool Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x81a0000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\MICROS~1\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x8cb0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5bf70000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_08e394a1a83e212f\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\Notepad++\NppShell_06.dll</Path>
<Version>0.1</Version>
<Company></Company>
<Description>ShellHandler for Notepad++ (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\Explorer.EXE</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2093056</Size>
<Path>C:\Windows\system32\wpdshext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки для переносных устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab350000</BaseAddress>
<Size>1683456</Size>
<Path>C:\Windows\System32\comsvcs.dll</Path>
<Version>2001.12.10941.16384 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Services</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab4f0000</BaseAddress>
<Size>1400832</Size>
<Path>C:\Windows\system32\connect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Мастера подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab650000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\system32\rasgcw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Страницы мастера RAS</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\System32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\system32\ieframe.DLL</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0df0000</BaseAddress>
<Size>1626112</Size>
<Path>C:\Windows\SYSTEM32\d3d9.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 9 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0f80000</BaseAddress>
<Size>1777664</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoViewer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Просмотр фотографий Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab27c0000</BaseAddress>
<Size>516096</Size>
<Path>C:\Windows\System32\imapi2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>IMAPI версии 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2840000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\bthprops.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложение панели управления Bluetooth</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2880000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\cscobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Внутрипроцессный COM-объект используемый клиентами CSC API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab29a0000</BaseAddress>
<Size>1912832</Size>
<Path>C:\Windows\System32\pnidui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Значок сетевой системы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2b80000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\system32\SettingMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Change Monitor</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2bc0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\PortableDeviceTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device (Parameter) Types Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab34f0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\System32\Actioncenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5120000</BaseAddress>
<Size>1691648</Size>
<Path>C:\Windows\system32\BatMeter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Meter Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\MsftEdit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7e40000</BaseAddress>
<Size>3420160</Size>
<Path>C:\Windows\System32\SyncCenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр синхронизации Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\system32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\system32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab99b0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\dxp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки компонента Device Stage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9ba0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\SYSTEM32\searchfolder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SearchFolder</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabac60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\EhStorAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Enhanced Storage API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae20000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msiltcfg.dll</Path>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer Configuration API Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaea0000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\system32\SHDOCVW.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\SYSTEM32\settingsynccore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SYSTEM32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SYSTEM32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd3c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\InputSwitch.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переключатель ввода Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd670000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\framedynos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI SDK Provider Framework</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd6c0000</BaseAddress>
<Size>1306624</Size>
<Path>C:\Windows\System32\werconcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PRS CPL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd800000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\NPSMDesktopProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Библиотека DLL локального поставщика рабочего стола NPSM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabda60000</BaseAddress>
<Size>1241088</Size>
<Path>C:\Windows\System32\wscui.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdeb0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\wpdshserviceobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device Shell Service Object</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabded0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\stobject.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Объект службы оболочки Systray</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe470000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\wscinterop.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Health Center WSC Interop</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe580000</BaseAddress>
<Size>831488</Size>
<Path>C:\Program Files (x86)\360\Total Security\MenuEx64.dll</Path>
<Version>9, 6, 0, 1001</Version>
<Company></Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe650000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\system32\zipfldr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сжатые ZIP-папки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9a0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\Syncreg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Synchronization Framework Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\system32\NetworkExplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0b0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\playtomenu.dll</Path>
<Version>12.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека меню функции &quot;Передать на устройство&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\System32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf590000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\syncui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Портфель Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfba0000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\WSCAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\MICROS~1\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b40000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\dlnashext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLNA Namespace DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\srchadmin.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры индексирования</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0f60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SYSTEM32\CHARTV.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Chart View</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1cc0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.Sockets.PushEnabledApplication DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac27a0000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.111.0603.0006\amd64\FileSyncShell64.dll</Path>
<Version>18.111.0603.0006</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac32e0000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\twext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Свойства: Предыдущие версии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3350000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\OLEACCHOOKS.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Event Hooks Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\dsreg.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5140000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\AboveLockAppHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AboveLockAppHost</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5190000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\NotificationController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5570000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\system32\twinui.pcshell.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Twinui.PCShell</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac55d0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\windows.immersiveshell.serviceprovider.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.ImmersiveShell.ServiceProvider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\system32\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5c70000</BaseAddress>
<Size>65536</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoBase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Base Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6650000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\npsm.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPSM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac78f0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\hgcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Панель управления домашней группы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d40000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\SYNCENG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Briefcase Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d90000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\SYSTEM32\SndVolSSO.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Громкость SCA </Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7f50000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\acppage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека расширений для вкладки &quot;Совместимость&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\SYSTEM32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795778062352400</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\ploptin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Prelaunch OptIn</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ea0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\hcproviders.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщики компонента &quot;Центр безопасности и обслуживания&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca190000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\WorkFoldersShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки рабочих папок (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac80000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SYSTEM32\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>13</ProcessIndex>
<ProcessId>404</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776186257169</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>15</ProcessIndex>
<ProcessId>468</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776223665667</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>17</ProcessIndex>
<ProcessId>484</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226419105</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>wininit.exe</ProcessName>
<ImagePath>C:\Windows\system32\wininit.exe</ImagePath>
<CommandLine>wininit.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Автозагрузка приложений Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>18</ProcessIndex>
<ProcessId>520</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226825613</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>winlogon.exe</ProcessName>
<ImagePath>C:\Windows\system32\winlogon.exe</ImagePath>
<CommandLine>winlogon.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Программа входа в систему Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ff7b5570000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\winlogon.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа входа в систему Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaee0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\dwminit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMInit</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacafa0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\UXINIT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows User Experience Session Initialization Dll</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>19</ProcessIndex>
<ProcessId>588</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776277547408</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>lsass.exe</ProcessName>
<ImagePath>C:\Windows\system32\lsass.exe</ImagePath>
<CommandLine>C:\Windows\system32\lsass.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Description>Local Security Authority Process</Description>
<modulelist>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x222e3610000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\msprivs.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переводы привилегий Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ff6b2d20000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\lsass.exe</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Security Authority Process</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffab9170000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\vaultsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба диспетчера учетных данных</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf170000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\hmkd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows HMAC Key Derivation API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf190000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\ngcpopkeysrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Passport Proof-of-possession Key Service</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\keyiso.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба изоляции ключей CNG</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SYSTEM32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf270000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SecureTimeAggregator.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Secure Time Aggregator</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb9b0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\scecli.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент редактора конфигураций безопасности</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\SspiSrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA SSPI RPC interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\dpapisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DPAPI Server</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbad0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\efslsaext.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA extension for EFS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbb70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wdigest.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Digest Access</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc00000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\MicrosoftAccountCloudAP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MicrosoftAccount Cloud AP Plugin</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc50000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\cloudAP.DLL</Path>
<Version>10.0.14393.1358 (rs1_release.170602-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cloud AP Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbcb0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\system32\pku2u.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pku2u Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd00000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\tspkg.DLL</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Web Service Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe30000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\gmsaclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;gmsaclient.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe60000</BaseAddress>
<Size>843776</Size>
<Path>C:\Windows\system32\netlogon.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека службы Net Logon</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc030000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\KerbClientShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kerberos Client Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc180000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\negoexts.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NegoExtender Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\JOINUTIL.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\netprovfw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Provisioning Service Framework DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc260000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\SYSTEM32\samsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сервера диспетчера учетных записей</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc380000</BaseAddress>
<Size>1527808</Size>
<Path>C:\Windows\system32\lsasrv.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера LSA</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>20</ProcessIndex>
<ProcessId>704</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776284978539</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k RPCSS</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8250000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\wshhyperv.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V Winsock2 Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6a0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\RpcRtRemote.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote RPC Extension</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\rpcepmap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сопоставитель конечных точек RPC
</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>21</ProcessIndex>
<ProcessId>808</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0000c8d4</AuthenticationId>
<CreateTime>131765776288401882</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>Window Manager\DWM-1</Owner>
<ProcessName>dwm.exe</ProcessName>
<ImagePath>C:\Windows\system32\dwm.exe</ImagePath>
<CommandLine>&quot;dwm.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер окон рабочего стола</Description>
<modulelist>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ff683990000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\dwm.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\system32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7b70000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\System32\Windows.Gaming.Input.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Gaming Input API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\avrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9a30000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SYSTEM32\ism32k.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca110000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\dwmghost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMGhost</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca8d0000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\system32\dwmcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека ядра Microsoft DWM</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacac90000</BaseAddress>
<Size>856064</Size>
<Path>C:\Windows\SYSTEM32\udwm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\dwmredir.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компонент перенаправления диспетчера окон рабочего стола Microsoft</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>22</ProcessIndex>
<ProcessId>904</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776293087855</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x259b0640000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\SFC.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab830000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\netman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>c:\windows\system32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>c:\windows\system32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab1260000</BaseAddress>
<Size>10350592</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll</Path>
<Version>4.7.2117.0 built by: NET47REL1LAST</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Common Language Runtime - WorkStation</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>c:\windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795778252487651</Timestamp>
<BaseAddress>0x7ffabc160000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\System32\aeinv.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Inventory Component</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778007496118</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabfa00000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\SYSTEM32\MSVCR120_CLR0400.dll</Path>
<Version>12.00.52519.0 built by: VSWINSERVICING</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\MSI.DLL</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0fc0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\spp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих точек защиты Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1010000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\system32\MSCOREE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac10f0000</BaseAddress>
<Size>421888</Size>
<Path>c:\windows\system32\storsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы хранения</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1240000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll</Path>
<Version>4.7.2623.0 built by: NET471REL1LAST_C</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2420000</BaseAddress>
<Size>466944</Size>
<Path>c:\windows\system32\das.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сопоставления устройств</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795778007645121</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac41c0000</BaseAddress>
<Size>139264</Size>
<Path>c:\windows\system32\trkwks.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент отслеживания изменившихся связей</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4650000</BaseAddress>
<Size>516096</Size>
<Path>c:\windows\system32\pcasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба помощника по совместимости программ</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Assembly manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b50000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\dssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы NT для службы совместного доступа к данным</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6120000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\sysmain.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост службы Superfetch</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b10000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\SYSTEM32\WUDFPlatform.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - библиотека платформ пользовательского режима</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b50000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\wudfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation (WDF) - служба среды выполнения платформы драйвера режима пользователя</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9800000</BaseAddress>
<Size>376832</Size>
<Path>c:\windows\system32\audioendpointbuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство построения конечных точек Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9de0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\portabledeviceconnectapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Portable Device Connection API Components</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SYSTEM32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca2d0000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\ncbservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Посредник подключений к сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>c:\windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca710000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\pcadm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Diagnostic Module</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\system32\SXS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>c:\windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>23</ProcessIndex>
<ProcessId>96</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776304995849</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2510000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\energyprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2580000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\ncuprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Connectivity Statistics Provider for System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2b90000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\nduprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик сетевой статистики для службы отслеживания использования ресурсов системы</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bb0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\appsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bd0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\eeprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy Estimator SRUM provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2c20000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\wfapigp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall GPO Helper dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2d70000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\wpnsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SRUM provider for WPN</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3310000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\srumsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3730000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\pnpts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PlugPlay Troubleshooter</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3bd0000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\ncdautosetup.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы автоматической настройки сетевых устройств</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac41f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\adhapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD harvest sites and subnets API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4500000</BaseAddress>
<Size>200704</Size>
<Path>c:\windows\system32\dps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба политики диагностики WDI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4cd0000</BaseAddress>
<Size>933888</Size>
<Path>c:\windows\system32\mpssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба защиты (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6740000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\dtsh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API состояния общего доступа и обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac74b0000</BaseAddress>
<Size>827392</Size>
<Path>c:\windows\system32\bfe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба базовой фильтрации</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\coremessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\system32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\CFGMGR32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>24</ProcessIndex>
<ProcessId>348</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776305446235</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k netsvcs</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaa0aa0000</BaseAddress>
<Size>2138112</Size>
<Path>c:\windows\system32\wlidsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба учетных записей Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0750000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\system32\rascustom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль настраиваемых протоколов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab07b0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\vpnike.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>VPNIKE Protocol Engine - Test dll</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab09b0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\system32\rasppp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access PPP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0a00000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\rastapi.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access TAPI Compliance Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab3440000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\rasmans.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер подключений удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4c50000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\eappprxy.dll</Path>
<Version>10.0.14393.187 (rs1_release_inmarket.160906-1818)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft EAPHost Peer Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab9a90000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\dmEnrollEngine.DLL</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enroll Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabc210000</BaseAddress>
<Size>2355200</Size>
<Path>c:\windows\system32\wuaueng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Агент Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabdf60000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\raschap.dll</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>Удаленные доступ через PPP CHAP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4a0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\appinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о приложении</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabed80000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\system32\wbem\wbemess.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee10000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee30000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\system32\wbem\wmiprvsd.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf090000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>c:\windows\system32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfda0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\wbem\ncprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Non-COM WMI Event Provision APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0000000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wbem\repdrvfs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Repository Driver</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\shacctprofile.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Profile Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1530000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SYSTEM32\dpx.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft(R) Delta Package Expander</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1900000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\appxapplicabilityblob.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Appx Applicability Blob DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1970000</BaseAddress>
<Size>1073152</Size>
<Path>c:\windows\system32\qmgr.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фоновая интеллектуальная служба передачи</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1c30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\DMProcessXMLFiltered.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmprocessxmlfiltered</Description>
</module>
<module>
<Timestamp>131795779661934902</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1cf0000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\SYSTEM32\wuuhext.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update Agent plugin for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1df0000</BaseAddress>
<Size>61440</Size>
<Path>c:\windows\system32\NCI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CoInstaller: NET</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e20000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f10000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\DMCmnUtils.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmcmnutils</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f50000</BaseAddress>
<Size>471040</Size>
<Path>C:\Windows\system32\wbem\esscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20f0000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\CLUSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API кластера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2210000</BaseAddress>
<Size>1351680</Size>
<Path>C:\Windows\system32\wbem\wbemcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инструментарий управления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2370000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\adhsvc.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD Harvest Sites and Subnets Service</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2390000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\httpprxm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager</Description>
</module>
<module>
<Timestamp>131795775850813653</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac24a0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\system32\RESUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служебной программы ресурсов кластера (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795775850596192</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2640000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\wmidcom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2670000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\miutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура управления</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac26f0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\sscoreext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Core DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2720000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SYSTEM32\WPTaskScheduler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WP Task Scheduler DLL</Description>
</module>
<module>
<Timestamp>131795775850744400</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2770000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\SSCORE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основная DLL-библиотека службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2940000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CSystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Classic System Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>c:\windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a40000</BaseAddress>
<Size>974848</Size>
<Path>c:\windows\system32\iphlpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Эта служба предоставляет автоматическое подключение IPv6 в сети IPv4.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c60000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\WDSCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Panther Engine Module</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\system32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3740000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3b40000</BaseAddress>
<Size>245760</Size>
<Path>c:\windows\system32\wbem\wmisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3fa0000</BaseAddress>
<Size>331776</Size>
<Path>c:\windows\system32\srvsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) ресурсов для службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4160000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\wpnservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба системы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4480000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\taskcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оснастка обратной совместимости диспетчера задач</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4540000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\ProximityServicePAL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service PAL</Description>
</module>
<module>
<Timestamp>131795775380234927</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4cc0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ProximityCommonPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Common PAL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4dc0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\ProximityCommon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Универсальная реализация близкого взаимодействия</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4ee0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\ProximityService.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service Implementation</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5ef0000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\System32\MbaeApiPublic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Mobile Broadband Account API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7700000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\CredentialMigrationHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Migration Handler</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\sqmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SQM Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d60000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\UpdatePolicy.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Policy Reader</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e90000</BaseAddress>
<Size>749568</Size>
<Path>c:\windows\system32\FVEAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows BitLocker Drive Encryption API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac82d0000</BaseAddress>
<Size>643072</Size>
<Path>c:\windows\system32\shsvcs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8590000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\LocationWinPalMisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Location Platform Abstraction Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac85c0000</BaseAddress>
<Size>1810432</Size>
<Path>c:\windows\system32\LocationFramework.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа географического положения Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8780000</BaseAddress>
<Size>274432</Size>
<Path>c:\windows\system32\UBPM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL единого диспетчера фоновых процессов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8b60000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\schedsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac91c0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\profsvcext.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvcExt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92a0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\sens.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба уведомления о системных событиях (SENS)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\themeservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы темы оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9420000</BaseAddress>
<Size>380928</Size>
<Path>c:\windows\system32\profsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvc</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9a70000</BaseAddress>
<Size>1257472</Size>
<Path>c:\windows\system32\gpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca700000</BaseAddress>
<Size>32768</Size>
<Path>c:\windows\system32\DABAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Desktop Activity Broker API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca720000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\bitsigd.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service IGD Support</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacab70000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба географического положения</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac40000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\seclogon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL службы вторичного входа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac50000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\bitsperf.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Perfmon Counter Access</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\MSWSOCK.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>25</ProcessIndex>
<ProcessId>372</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776305463443</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>c:\windows\system32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab91f0000</BaseAddress>
<Size>233472</Size>
<Path>c:\windows\system32\sstpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обеспечивает возможность использования SSTP для подключения к удаленным компьютерам с помощью VPN.</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabc610000</BaseAddress>
<Size>540672</Size>
<Path>c:\windows\system32\w32time.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба времени Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabef00000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\cdpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба CDP Майкрософт (R)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05e0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\sbservicetrigger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Socket Broker Service Trigger</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4130000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\fdphost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба размещения поставщиков функций обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4200000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\perftrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Performance PerfTrack</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5b80000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\AuthBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API WinRT для веб-проверки подлинности</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66e0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\fdssdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery SSDP Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6960000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\fdwsd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery WS Discovery Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac76d0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\vmictimeprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Machine Integration Component Time Sync Provider Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7a10000</BaseAddress>
<Size>544768</Size>
<Path>c:\windows\system32\netprofmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер списка сетей</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7f70000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\licensemanagersvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManagerSvc</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90a0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\nsisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RPC-сервер интерфейса сохранения сети</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac91f0000</BaseAddress>
<Size>172032</Size>
<Path>c:\windows\system32\FontProvider.dll</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Font Provider Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9860000</BaseAddress>
<Size>1896448</Size>
<Path>c:\windows\system32\fntcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэша шрифтов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>c:\windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>26</ProcessIndex>
<ProcessId>360</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311216195</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffabaad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\deviceaccess.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Broker And Policy COM Server</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac7e70000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\coreaudiopolicymanagerext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;coreaudiopolicymanagerext.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac87d0000</BaseAddress>
<Size>237568</Size>
<Path>c:\windows\system32\AUDIOSRVPOLICYMANAGER.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Audio Service Policy Manager</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac90d0000</BaseAddress>
<Size>978944</Size>
<Path>c:\windows\system32\audiosrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\POWRPROF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>27</ProcessIndex>
<ProcessId>1040</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311708649</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8820000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SYSTEM32\cmintegrator.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>cmintegrator.dll</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8c50000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wcmcsp.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Service Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8fe0000</BaseAddress>
<Size>737280</Size>
<Path>c:\windows\system32\wcmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы диспетчера подключений Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>28</ProcessIndex>
<ProcessId>1068</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776312395030</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\CRYPTNET.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\cryptcatsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Catalog Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65f0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\crypttpmeksvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic TPM Endorsement Key Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6680000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\cryptsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6f00000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\wkssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы рабочей станции</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79e0000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\netjoin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL присоединения к домену</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\WlanApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7c00000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\ssdpapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8260000</BaseAddress>
<Size>425984</Size>
<Path>c:\windows\system32\ncsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индикатор работоспособности сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8370000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\nlasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о подключенных сетях 2</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8410000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dnsext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DNS extension DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SYSTEM32\Fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8830000</BaseAddress>
<Size>290816</Size>
<Path>c:\windows\system32\dnsrslvr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэширующего сопоставителя DNS</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\JoinUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>29</ProcessIndex>
<ProcessId>1248</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776322176070</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>spoolsv.exe</ProcessName>
<ImagePath>C:\Windows\System32\spoolsv.exe</ImagePath>
<CommandLine>C:\Windows\System32\spoolsv.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер очереди печати</Description>
<modulelist>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ff639680000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\spoolsv.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер очереди печати</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffab8a60000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaba980000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\jscript.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabb7d0000</BaseAddress>
<Size>851968</Size>
<Path>C:\Windows\System32\win32spl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик печати с исполнением на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\prntvpt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Ticket Services Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd70000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_53d78f68bc1697cc\Amd64\PrintConfig.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc0c0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPFILEQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPFILEQ</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc590000</BaseAddress>
<Size>118784</Size>
<Path>C:\Program Files\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc5b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\amsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Anti-Malware Scan Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd040000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdPnp.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pnp Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd060000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\WSDMon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер порта принтера WSD</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd100000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\usbmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Standard Dynamic Printing Port Monitor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd160000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\wsnmp32.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft WinSNMP v2.0 Manager API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd2a0000</BaseAddress>
<Size>1159168</Size>
<Path>C:\Windows\System32\localspl.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека локального диспетчера очереди</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabde60000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\System32\tcpmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека монитора портов TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe3f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\spool\PRTPROCS\x64\winprint.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Print Processor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe6c0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\PrintIsolationProxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Sandbox COM Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe8a0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\snmpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SNMP Utility Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe980000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\SPOOLSS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Spooler SubSystem DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f00000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\FXSMON.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft  Fax Print Monitor</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac4e90000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\wshirda.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Sockets Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac7e00000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\inetpp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Internet Print Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>30</ProcessIndex>
<ProcessId>1512</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776336551242</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffabe9f0000</BaseAddress>
<Size>258048</Size>
<Path>c:\windows\system32\ssdpsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы SSDP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69b0000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\fdrespub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба публикации ресурсов обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>c:\windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>31</ProcessIndex>
<ProcessId>1556</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776339471770</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k utcsvc</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x272f9bf0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf140000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\CourtesyEngine.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Feedback Courtesy Engine DLL Server</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfde0000</BaseAddress>
<Size>143360</Size>
<Path>c:\windows\system32\CRYPTXML.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API-интерфейс XML DigSig</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\Netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\DSREG.DLL</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac5fd0000</BaseAddress>
<Size>1056768</Size>
<Path>c:\windows\system32\WindowsPerformanceRecorderControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Performance Recorder Control Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>c:\windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6210000</BaseAddress>
<Size>2007040</Size>
<Path>c:\windows\system32\diagtrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диагностическое отслеживание Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795775838362137</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795775839498740</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>32</ProcessIndex>
<ProcessId>1636</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776343009549</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k appmodel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>c:\windows\system32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3c10000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\tileobjserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер моделей данных плиток</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>c:\windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>c:\windows\system32\windows.staterepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>33</ProcessIndex>
<ProcessId>1744</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776348255325</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>MemCompression</ProcessName>
<ImagePath>MemCompression</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>34</ProcessIndex>
<ProcessId>2100</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776438403561</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffabff90000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\ipsecsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows IPsec SPD Server DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac1e00000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\FwRemoteSvr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall Remote APIs Server</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>35</ProcessIndex>
<ProcessId>2648</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777555980720</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>sihost.exe</ProcessName>
<ImagePath>C:\Windows\system32\sihost.exe</ImagePath>
<CommandLine>sihost.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Shell Infrastructure Host</Description>
<modulelist>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ff7bbae0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\sihost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Infrastructure Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb910000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\container.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Containers</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb970000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\daxexec.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>daxexec</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc450000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\system32\ShareHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShareHost</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc800000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\windowmanagement.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Window Management</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc850000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\AppointmentActivation.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL for AppointmentActivation</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc8b0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\NotificationPlatformComponent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationPlatformComponent</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc9a0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\activationmanager.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Activation Manager</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabca10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\ClipboardServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Modern Clipboard</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcde0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Windows\System32\modernexecserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Modern Execution</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcf10000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\desktopshellext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DesktopHost Extensions</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\system32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>36</ProcessIndex>
<ProcessId>840</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777563791648</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k UnistackSvcGroup</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf6a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\PhoneUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Phone utilities</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf700000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\System32\PIMSTORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>POOM</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab05d0000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\AccountAccessor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync data model to access accounts</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab0630000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\SyncController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SyncController for managing sync of mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb20000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\CEMAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CEMAPI</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcd80000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\cdpusersvc.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP User Components</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabd630000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\MCCSEngineShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Utilies shared among OneSync engines</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabdde0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\SYNCUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabed20000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\aphostservice.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>c:\windows\system32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4100000</BaseAddress>
<Size>151552</Size>
<Path>c:\windows\system32\NetworkHelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac97b0000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\InprocLogger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>In-proc Private Event Trace Logger</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca1d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\UserDataTypeHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Type Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca270000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\UserDataLanguageUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Language-related helper functions for user data</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca520000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\APHostClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service RPC Client </Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacabf0000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\MCCSPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform abstraction layer dll for MCCS</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacac20000</BaseAddress>
<Size>86016</Size>
<Path>c:\windows\system32\UserDataPlatformHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>37</ProcessIndex>
<ProcessId>528</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777565618284</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\system32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb440000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\system32\MTFServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;MTFServer.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb510000</BaseAddress>
<Size>2854912</Size>
<Path>C:\Windows\system32\InputService.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Text InputService Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8c0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\InputLocaleManager.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;InputLocaleManager.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8f0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\EditBufferTestHook.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;EditBufferTestHook.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb9f0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\system32\MSUTB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) сервера MSUTB</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabba70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\MsCtfMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MsCtfMonitor DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabbc20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\PlaySndSrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба PlaySound</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\system32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac7d10000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\KBDUS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>United States Keyboard Layout</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab10000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\WordBreakers.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;WordBreakers.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>38</ProcessIndex>
<ProcessId>3632</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777941176116</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>RuntimeBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\RuntimeBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\RuntimeBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Runtime Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7a45f0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\RuntimeBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Runtime Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\System32\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\mssrch.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe880000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\FeClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT File Encryption Client Interfaces</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe8c0000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\system32\windows.cortana.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.Desktop</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795771229682115</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf9c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\system32\windows.cortana.onecore.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.OneCore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795779561161209</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795771234179313</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5ca0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\AppExtension.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API AppExtension</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795771242759756</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7d00000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SYSTEM32\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>39</ProcessIndex>
<ProcessId>3164</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778119045372</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ShellExperienceHost.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe&quot; -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Windows Shell Experience Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ff697570000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Experience Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f760000</BaseAddress>
<Size>3796992</Size>
<Path>C:\Windows\System32\MFMediaEngine.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Media Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaabad0000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\mfsrcsnk.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Source and Sink DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaafe70000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\System32\mfcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Core DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab0be0000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\ShellExperiences\NetworkUX.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab9eb0000</BaseAddress>
<Size>2899968</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.ActionCenter.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActionCenter Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaba180000</BaseAddress>
<Size>7880704</Size>
<Path>C:\Windows\ShellExperiences\StartUI.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Start UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SYSTEM32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd420000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\RTMediaFrame.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime MediaFrame DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe410000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\SYSTEM32\globcollationhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GlobCollationHost</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0080000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\System32\resampledmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Resampler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0110000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\QuickActionsDataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>QuickActionsDataModel</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0160000</BaseAddress>
<Size>491520</Size>
<Path>C:\Windows\ShellExperiences\QuickActions.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac40f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4eb0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5b20000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\CompPkgSup.DLL</Path>
<Version>10.0.14393.969 (rs1_release_inmarket.170315-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Component Package Support DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5e90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\Windows.Media.MediaControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера MediaControl среды выполнения Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>40</ProcessIndex>
<ProcessId>4856</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778391112136</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MSASCuiL.exe</ProcessName>
<ImagePath>C:\Program Files\Windows Defender\MSASCuiL.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Windows Defender\MSASCuiL.exe&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Description>Windows Defender notification icon</Description>
<modulelist>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x23622c70000</BaseAddress>
<Size>733184</Size>
<Path>C:\Program Files\Windows Defender\EppManifest.dll</Path>
<Version>4.10.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль ресурсов настройки пользовательского интерфейса</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ff63bef0000</BaseAddress>
<Size>651264</Size>
<Path>C:\Program Files\Windows Defender\MSASCuiL.exe</Path>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Defender notification icon</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4560000</BaseAddress>
<Size>950272</Size>
<Path>C:\Program Files\Windows Defender\mpclient.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Client Interface</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>41</ProcessIndex>
<ProcessId>4928</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778406250112</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>uTorrent.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe&quot;  /MINIMIZED</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>3.5.4.44498</Version>
<Description>µTorrent</Description>
<modulelist>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>5406720</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</Path>
<Version>3.5.4.44498</Version>
<Company>BitTorrent Inc.</Company>
<Description>µTorrent</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e140000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SysWOW64\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1c0000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\SysWOW64\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6ef20000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70af0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fc0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fd0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fe0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>42</ProcessIndex>
<ProcessId>3608</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778496229053</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ApplicationFrameHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\ApplicationFrameHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\ApplicationFrameHost.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Application Frame Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ff6aa270000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\ApplicationFrameHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Frame Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5240000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\ApplicationFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фрейм приложения</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\system32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\D3D10Warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>43</ProcessIndex>
<ProcessId>5952</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778883326814</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54150_1240996307 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>44</ProcessIndex>
<ProcessId>5800</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765779120650795</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\esent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>45</ProcessIndex>
<ProcessId>340</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765800389528045</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54870_1839591030 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c50000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\Ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>46</ProcessIndex>
<ProcessId>2736</ProcessId>
<ParentProcessId>3976</ParentProcessId>
<ParentProcessIndex>47</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765800903010156</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Taskmgr.exe</ProcessName>
<ImagePath>C:\Windows\System32\Taskmgr.exe</ImagePath>
<CommandLine>&quot;C:\Windows\System32\Taskmgr.exe&quot; /2 </CommandLine>
<CompanyName>Microsoft® Windows® Operating System</CompanyName>
<Version>1, 0, 0, 1</Version>
<Description>Task Manager</Description>
<modulelist>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ff7c2a70000</BaseAddress>
<Size>1286144</Size>
<Path>C:\Windows\System32\Taskmgr.exe</Path>
<Version>1, 0, 0, 1</Version>
<Company>Microsoft® Windows® Operating System</Company>
<Description>Task Manager</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdfa0000</BaseAddress>
<Size>393216</Size>
<Path>C:\Windows\System32\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\System32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>49</ProcessIndex>
<ProcessId>6724</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803507001117</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHActiveDefense.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe&quot;</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1008</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795778431738530</Timestamp>
<BaseAddress>0x10000</BaseAddress>
<Size>413696</Size>
<Path>C:\ProgramData\Package Cache\{b8e12890-118d-4721-8e54-05d978086712}\VC_redist.x64.exe</Path>
<Version>14.0.24516.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24516</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0xd0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</Path>
<Version>10,0,0,1008</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795778469924367</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Wireshark\WinPcap_4_1_3.exe</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>WinPcap 4.1.3 installer</Description>
</module>
<module>
<Timestamp>131795778203065490</Timestamp>
<BaseAddress>0x840000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files\Wireshark\vcredist_x64.exe</Path>
<Version>14.12.25810.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810</Description>
</module>
<module>
<Timestamp>131795778429155018</Timestamp>
<BaseAddress>0x34c0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\mfc140deu.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>MFC Language Specific Resources</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x3c80000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778395516599</Timestamp>
<BaseAddress>0x40e0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\System32\vccorlib140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795778389953959</Timestamp>
<BaseAddress>0xa8e0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778421734438</Timestamp>
<BaseAddress>0xe830000</BaseAddress>
<Size>6127616</Size>
<Path>C:\Windows\System32\mfc140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>MFCDLL Shared Library - Retail Version</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fb90000</BaseAddress>
<Size>2736128</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\deepscan.dll</Path>
<Version>3, 5, 1, 2130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60190000</BaseAddress>
<Size>475136</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360SafeCamera.tpi</Path>
<Version>2, 0, 0, 1031</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60210000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\jcloudscan.dll</Path>
<Version>1, 0, 0, 1012</Version>
<Company>360.cn</Company>
<Description>360安全卫士 移动云查询模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604a0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appdext.dll</Path>
<Version>1, 0, 0, 1483</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604e0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\DrvUtility.dll</Path>
<Version>1, 0, 0, 1081</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60510000</BaseAddress>
<Size>409600</Size>
<Path>C:\Program Files (x86)\360\Total Security\SafeScan.dll</Path>
<Version>1, 0, 0, 1074</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60580000</BaseAddress>
<Size>204800</Size>
<Path>C:\Program Files (x86)\360\Total Security\ScanStub.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x605c0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360gameidentify.dll</Path>
<Version>1, 0, 1, 1050</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏识别模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60640000</BaseAddress>
<Size>430080</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\Netgm.dll</Path>
<Version>9,0,0,1005</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏模式判断模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60a50000</BaseAddress>
<Size>479232</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\DsSysRepair.dll</Path>
<Version>1, 0, 0, 1062</Version>
<Company>QIHU360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security System Repair Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61000000</BaseAddress>
<Size>184320</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\qutmipc.dll</Path>
<Version>7, 3, 0, 1267</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61030000</BaseAddress>
<Size>262144</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg.dll</Path>
<Version>3, 0, 0, 1160</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x610d0000</BaseAddress>
<Size>1097728</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\SomAdvUtils.dll</Path>
<Version>3, 1, 1, 2020</Version>
<Company>360.cn</Company>
<Description>360 Safeguard PC Boost</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61480000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qex\qex.dll</Path>
<Version>4.1.13.3366</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2017 Antivirus</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x616a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SelfProtectAPI2.dll</Path>
<Version>7, 1, 1, 1033</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61700000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360procmon.dll</Path>
<Version>7, 1, 1, 1221</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61780000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\netdefender.dll</Path>
<Version>1, 0, 0, 1129</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x617e0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appd.dll</Path>
<Version>7, 3, 6, 3113</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360HipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61ab0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\fileMgr.dll</Path>
<Version>7, 3, 0, 1963</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x621a0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\yhregd.dll</Path>
<Version>7, 2, 0, 1903</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62280000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\360SoftMgrS.dll</Path>
<Version>2, 1, 6, 1490</Version>
<Company>360.cn</Company>
<Description>360软件管家 服务模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62470000</BaseAddress>
<Size>405504</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll</Path>
<Version>7, 2, 1, 1279</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x624e0000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\360box.dll</Path>
<Version>2, 0, 0, 1043</Version>
<Company>360.cn</Company>
<Description>360隔离沙箱模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\deepscan\DsRes.dll</Path>
<Version>1,0,0,1012</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security Resource</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b70000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\gamemode.tpi</Path>
<Version>9,0,0,1001</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Game Mode Control</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67130000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\devenum.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечисление устройств.</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\fltlib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6c0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6ea80000</BaseAddress>
<Size>860160</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\QVM\360QVM.dll</Path>
<Version>5.0.2.1003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security QVM Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70210000</BaseAddress>
<Size>966656</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEngine.dll</Path>
<Version>1, 0, 0, 2016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70300000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEI.dll</Path>
<Version>1, 0, 0, 2003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>50</ProcessIndex>
<ProcessId>6340</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765803510844292</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>QHSafeTray.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</ImagePath>
<CommandLine>/showtrayicon</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1024</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0xec0000</BaseAddress>
<Size>2351104</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</Path>
<Version>10,0,0,1024</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x68f0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c480000</BaseAddress>
<Size>245760</Size>
<Path>C:\Program Files (x86)\360\Total Security\PDown.dll</Path>
<Version>1, 3, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Security Center Network Module </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5fe30000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll</Path>
<Version>9,6,0,1001</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60020000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360netctrl.dll</Path>
<Version>5, 3, 15, 2232</Version>
<Company>360.cn</Company>
<Description>360 Total Security NetwokrMonCtrl</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60090000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\netmon.tpi</Path>
<Version>5, 1, 1, 3157</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360安全卫士 流量防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60350000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Program Files (x86)\360\Total Security\ToolBox.dll</Path>
<Version>1, 0, 0, 1094</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x606b0000</BaseAddress>
<Size>598016</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe.dll</Path>
<Version>1, 0, 0, 1120</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x609b0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360GuardBase.dll</Path>
<Version>3, 1, 0, 1060</Version>
<Company>360.cn</Company>
<Description>360保镖</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61070000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SomProxy.dll</Path>
<Version>1, 0, 0, 1900</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x611e0000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360connect.tpi</Path>
<Version>9,2,0,1030</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Connect</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x618c0000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files (x86)\360\Total Security\sites.dll</Path>
<Version>11, 1, 0, 1212</Version>
<Company>360.cn</Company>
<Description>360安全卫士</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360hipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\softmgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\Cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62210000</BaseAddress>
<Size>446464</Size>
<Path>C:\Program Files (x86)\360\Total Security\360TSCommon.dll</Path>
<Version>9, 0, 0, 1016</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62960000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\CleanPlusCache.tpi</Path>
<Version>1, 0, 0, 1004</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>CleanPlusCache</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795771279916892</Timestamp>
<BaseAddress>0x68850000</BaseAddress>
<Size>2764800</Size>
<Path>C:\Windows\SysWOW64\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e6e0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e770000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SysWOW64\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71170000</BaseAddress>
<Size>466944</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\CQhCltHttpW.dll</Path>
<Version>1, 4, 0, 1030</Version>
<Company>QIHU 360 SOFTWARE  CO. LIMITED</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>51</ProcessIndex>
<ProcessId>6860</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803555957830</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHWatchdog.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe&quot; /watch</CommandLine>
<CompanyName>QIHU 360 SOFTWARE CO. LIMITED</CompanyName>
<Version>8,2,0,1000</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0xdf0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</Path>
<Version>8,2,0,1000</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>52</ProcessIndex>
<ProcessId>5924</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765805232900810</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>wmiprvse.exe</ProcessName>
<ImagePath>C:\Windows\sysWOW64\wbem\wmiprvse.exe</ImagePath>
<CommandLine>C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Description>WMI Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x950000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\sysWOW64\wbem\wmiprvse.exe</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Provider Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\storagewmi_passthru.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60160000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x604d0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\delegatorprovider.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>53</ProcessIndex>
<ProcessId>6180</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765807370364309</CreateTime>
<FinishTime>131795777990682736</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>smartscreen.exe</ProcessName>
<ImagePath>C:\Windows\System32\smartscreen.exe</ImagePath>
<CommandLine>C:\Windows\System32\smartscreen.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>SmartScreen</Description>
<modulelist>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ff688690000</BaseAddress>
<Size>2416640</Size>
<Path>C:\Windows\System32\smartscreen.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreen</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaafa00000</BaseAddress>
<Size>2936832</Size>
<Path>C:\Windows\System32\certenroll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент регистрации служб сертификатов Active Directory Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffab2210000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\certca.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ЦС служб сертификации Microsoft® Active Directory</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\SYSTEM32\windows.globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac3290000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\smartscreenps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreenPS</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\System32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\CFGMGR32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382127</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>54</ProcessIndex>
<ProcessId>4408</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765812380694767</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x17826230000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1140000</BaseAddress>
<Size>1134592</Size>
<Path>C:\Windows\System32\ReAgent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>C:\Windows\System32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\system32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe000000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\system32\WinSATAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Assessment Tool API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf050000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\sdiageng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема выполнения сценариев диагностики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4ae0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sdiagschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запланированная задача сценариев проверки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4b00000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\MemoryDiagnostic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач средства проверки памяти Windows (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac5c80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\TempSignedLicenseExchangeTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TempSignedLicenseExchangeTask Task</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca200000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\ReAgentTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca210000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\RstrtMgr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер перезапуска</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacac00000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\radarrs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>программа устранения нехватки системных ресурсов Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>55</ProcessIndex>
<ProcessId>6944</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131767576301455145</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SkypeHost.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe&quot; -ServerName:SkypeHost.ServerServer</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>12.1815.210.0</Version>
<Description>Microsoft Skype</Description>
<modulelist>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ff7e8670000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaae130000</BaseAddress>
<Size>22437888</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkyWrap.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabe150000</BaseAddress>
<Size>2691072</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\skypert.dll</Path>
<Version>2018.15.01.31</Version>
<Company></Company>
<Description>SkypeRT shared library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1a80000</BaseAddress>
<Size>978944</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7c80000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>56</ProcessIndex>
<ProcessId>1048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131768729449405953</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>sedsvc.exe</ProcessName>
<ImagePath>C:\Program Files\rempl\sedsvc.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\rempl\sedsvc.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Description>sedsvc</Description>
<modulelist>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ff751430000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\rempl\sedsvc.exe</Path>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>sedsvc</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>57</ProcessIndex>
<ProcessId>7744</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081112364684</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; </CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x11330000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60900000</BaseAddress>
<Size>720896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\urlproc.dll</Path>
<Version>2, 9, 5, 1260</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x68b00000</BaseAddress>
<Size>44998656</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ce30000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6dc80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files (x86)\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6df70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\SysWOW64\shdocvw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e070000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e090000</BaseAddress>
<Size>233472</Size>
<Path>C:\Windows\SysWOW64\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e110000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e120000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multimedia Realtime Runtime</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e2a0000</BaseAddress>
<Size>4440064</Size>
<Path>C:\Windows\SysWOW64\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb60000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb70000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ec40000</BaseAddress>
<Size>442368</Size>
<Path>C:\Windows\SysWOW64\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd00000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd20000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe40000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe50000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SysWOW64\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ff90000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\SysWOW64\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ffe0000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\SysWOW64\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70190000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x701a0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\dllyupdate.dll</Path>
<Version>1.2.0.1831</Version>
<Company>Yandex LLC</Company>
<Description>Yandex updater (CU)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b30000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\WINUSB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows USB Driver User Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b60000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x711f0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>58</ProcessIndex>
<ProcessId>5696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081114193232</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe --type=crashpad-handler &quot;--user-data-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler &quot;--database=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data\Crashpad&quot; &quot;--metrics-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; --url=https://crash-reports.browser.yandex.net/submit --annotation=machine_id=c46245ef0fec9d5c44d2fa20241f2070 --annotation=main_process_pid=7744 --annotation=metrics_client_id=520f4dd3247d4cdfb744f32b1130b1bf --annotation=plat=Win32 --annotation=prod=Yandex --annotation=ver=18.6.1.770 --initial-client-data=0x1c4,0x1cc,0x1d0,0x1c0,0x1d4,0x700b800c,0x700b7ffc,0x700b7fe0,0x1c8</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>59</ProcessIndex>
<ProcessId>4664</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081123844756</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=gpu-process --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --service-request-channel-token=CC1AC8FA9C8EFF1EEBC2375FE4F704C6 --mojo-platform-channel-handle=1588 --ignored=&quot; --type=renderer &quot; /prefetch:2</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ecb0000</BaseAddress>
<Size>2228224</Size>
<Path>C:\Windows\SysWOW64\mfh264enc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation H264 Encoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f250000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\SysWOW64\ddraw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectDraw</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f340000</BaseAddress>
<Size>3784704</Size>
<Path>C:\Windows\SysWOW64\D3DCompiler_47.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D HLSL Compiler</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f6e0000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\SysWOW64\msvproc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Video Processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fbe0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\mf.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff20000</BaseAddress>
<Size>118784</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\swiftshader\libegl.dll</Path>
<Version>4.0.0.3</Version>
<Company></Company>
<Description>SwiftShader libEGL 32-bit Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dxva2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Video Acceleration 2.0 DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x705d0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\DCIMAN32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DCI Manager</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>60</ProcessIndex>
<ProcessId>8968</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081206363215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=183F52B8A6577BFD721F95F3A9641348 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=183F52B8A6577BFD721F95F3A9641348 --renderer-client-id=4 --mojo-platform-channel-handle=2640 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>61</ProcessIndex>
<ProcessId>4992</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081244357280</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=7E8A8199C364F4B0114F2A163B757250 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E8A8199C364F4B0114F2A163B757250 --renderer-client-id=10 --mojo-platform-channel-handle=3904 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>63</ProcessIndex>
<ProcessId>9504</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956266598229</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgent.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgent.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgent.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>InstallAgent</Description>
<modulelist>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ff63d380000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\InstallAgent.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffabea60000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\VEStoreEventHandlers.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDL Store Event Handlers</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4ad0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\EAMProgressHandler.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>EAMProgressHandler</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>64</ProcessIndex>
<ProcessId>8768</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956321853179</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgentUserBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgentUserBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgentUserBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>InstallAgentUserBroker</Description>
<modulelist>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x22530450000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ff74f890000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\InstallAgentUserBroker.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgentUserBroker</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>65</ProcessIndex>
<ProcessId>9636</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956424585250</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettingsBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\SystemSettingsBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\SystemSettingsBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>System Settings Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ff6015f0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\SystemSettingsBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Broker</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>66</ProcessIndex>
<ProcessId>10592</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956519902643</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettings.exe</ProcessName>
<ImagePath>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</ImagePath>
<CommandLine>&quot;C:\Windows\ImmersiveControlPanel\SystemSettings.exe&quot; -ServerName:microsoft.windows.immersivecontrolpanel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Параметры</Description>
<modulelist>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x18099ef0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\WMI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI DC and DP functionality</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ff7937a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaabce0000</BaseAddress>
<Size>2535424</Size>
<Path>C:\Windows\System32\NetworkMobileSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System settings network mobile handlers group</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac220000</BaseAddress>
<Size>4952064</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Application</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaadd90000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\NetworkDesktopSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Группа обработчиков системных параметров сетевого рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaaf920000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettingsViewModel.Desktop.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings View Model Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0970000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\credprovhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост инфраструктуры поставщика учетных данных</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0a70000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\System32\fhcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигураций истории файлов</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\SYSTEM32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\SYSTEM32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab91d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\ImmersiveControlPanel\Telemetry.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Telemetry Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcc60000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\System32\MiracastReceiver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API приемника Miracast</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2bf0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\EFSUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>EFS Utility Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\SYSTEM32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\wmiclnt.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca560000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\NcaApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Network Connectivity Assistant API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>67</ProcessIndex>
<ProcessId>10964</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794956837373387</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{BA126F01-2166-11D1-B1D0-00805FC1270E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\system32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>68</ProcessIndex>
<ProcessId>8940</ProcessId>
<ParentProcessId>2156</ParentProcessId>
<ParentProcessIndex>62</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956984780982</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Photoshop.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe&quot; &quot;C:\Users\User\Downloads\tlauncher_psd\tlauncher_psd.psd&quot;</CommandLine>
<CompanyName>Adobe Systems, Incorporated</CompanyName>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Description>Adobe Photoshop CC 2017</Description>
<modulelist>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0xb20000</BaseAddress>
<Size>9846784</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\cg.dll</Path>
<Version>3.0.00007</Version>
<Company>NVIDIA Corporation</Company>
<Description>Cg Core Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1490000</BaseAddress>
<Size>3276800</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\libmmd.dll</Path>
<Version>12.0.12.2</Version>
<Company>Intel Corporation</Company>
<Description>Math Library for Intel(r) Compilers (thread-safe)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x10000000</BaseAddress>
<Size>6070272</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\svml_dispmd.dll</Path>
<Version>12.0.12.2</Version>
<Company>Intel Corporation</Company>
<Description>SVML Library for Intel(r) Compilers (thread-safe)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x4fad0000</BaseAddress>
<Size>70561792</Size>
<Path>C:\Program Files\Common Files\Adobe\Plug-Ins\CC\File Formats\Camera Raw.8bi</Path>
<Version>9.8</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Photoshop Camera Raw Plug-in</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5b690000</BaseAddress>
<Size>4763648</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\SVGRE.dll</Path>
<Version>6, 0, 0, 37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>SVGRE 6.0</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5bcf0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AXE8SharedExpat.dll</Path>
<Version>3.8.0.34320</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>AXE Shared EXPAT (UTF-8 native)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5bd30000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\dnssd.dll</Path>
<Version>3,0,0,2</Version>
<Company>Apple Inc.</Company>
<Description>Bonjour Client Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5bd40000</BaseAddress>
<Size>974848</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AXEDOMCore.dll</Path>
<Version>3.8.0.34320</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XML Engine: DOM Core</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5be30000</BaseAddress>
<Size>1306624</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\icucnv40.dll</Path>
<Version>4, 0, 0, 1001</Version>
<Company>IBM Corporation and others</Company>
<Description>IBM ICU Common DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x6a400000</BaseAddress>
<Size>479232</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\cgGL.dll</Path>
<Version>3.0.00007</Version>
<Company>NVIDIA Corporation</Company>
<Description>Cg GL Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\File Formats\PSDX.8bi</Path>
<Version>14.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Photoshop Remix Plug-In</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2eee90000</BaseAddress>
<Size>13922304</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\icudt40.dll</Path>
<Version>4, 0, 0, 1001</Version>
<Company>IBM Corporation and others</Company>
<Description>ICU Data DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f1470000</BaseAddress>
<Size>12288</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PSArt.dll</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Resource DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f3490000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.dll</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Resource DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f3620000</BaseAddress>
<Size>2699264</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PSViews.dll</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Resource DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f93a0000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\WRServices.dll</Path>
<Version>12.0.0.1000</Version>
<Company>WinSoft S.A.</Company>
<Description>WRServices Engine</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f9540000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Linguistics\Providers\Plugins2\WRLiloPlugin.bundle\WRLiloPlugin.dll</Path>
<Version>1.3.6rc1</Version>
<Company>WinSoft SA</Company>
<Description>WR LILO Plugin</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ff6c3030000</BaseAddress>
<Size>182624256</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa0cb0000</BaseAddress>
<Size>1880064</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\aif.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa0e80000</BaseAddress>
<Size>2637824</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\LogSession.dll</Path>
<Version>7.4.1.60.45263</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>LogSession</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa1110000</BaseAddress>
<Size>70823936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\libcef.dll</Path>
<Version>3.2526.1347.gcf20046</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa54a0000</BaseAddress>
<Size>7950336</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\ScriptingSupport.8li</Path>
<Version>18.0.1</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>ScriptingSupport</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa5c40000</BaseAddress>
<Size>2113536</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\AdobeHunspellPlugin.dll</Path>
<Version>11.0.0.22122</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>AdobeHunspellPlugin</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa5e50000</BaseAddress>
<Size>4493312</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\CoolType.dll</Path>
<Version>5.15.00.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>CoolType Typography Engine</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa62a0000</BaseAddress>
<Size>5267456</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AGM.dll</Path>
<Version>4.30.60.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Graphics Manager</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa67b0000</BaseAddress>
<Size>1839104</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ACE.dll</Path>
<Version>2.20.02.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Color Engine</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6980000</BaseAddress>
<Size>1302528</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeXMP.dll</Path>
<Version>5.6-c138 ( 64 bit ), 79.159824, 2016/09/14-01:09:01</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XMP Core 5.6-c138 ( 64 bit )</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6ac0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\MultiProcessor Support.8bx</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6b70000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\MMXCore.8bx</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2093056</Size>
<Path>C:\Windows\system32\wpdshext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки для переносных устройств</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6fd0000</BaseAddress>
<Size>978944</Size>
<Path>C:\Windows\SYSTEM32\MSVCR120.dll</Path>
<Version>12.00.40660.0 built by: VSULDR</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa70c0000</BaseAddress>
<Size>679936</Size>
<Path>C:\Windows\SYSTEM32\MSVCP120.dll</Path>
<Version>12.00.40660.0 built by: VSULDR</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7170000</BaseAddress>
<Size>2826240</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\opencv_imgproc249.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7430000</BaseAddress>
<Size>2564096</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\opencv_core249.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa76b0000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AIDE.dll</Path>
<Version>1.5.0.36540</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Image Decode Encode Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7820000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\tbbmalloc.dll</Path>
<Version>4, 4, 2016, 0412</Version>
<Company>Intel Corporation</Company>
<Description>Scalable Allocator library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7870000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\SYSTEM32\DDRAW.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectDraw</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7b20000</BaseAddress>
<Size>2613248</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeOwl.dll</Path>
<Version>5.2.11</Version>
<Company>Adobe Systems, Incorporated </Company>
<Description>Adobe Owl(64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7da0000</BaseAddress>
<Size>749568</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ScCore.dll</Path>
<Version>4.5.6.4</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Scripting Components Core (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7e60000</BaseAddress>
<Size>18792448</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\mona.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9050000</BaseAddress>
<Size>802816</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ExtendScript.dll</Path>
<Version>4.5.6.4</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe ExtendScript scripting engine (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9120000</BaseAddress>
<Size>5681152</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PlugPlugOwl.dll</Path>
<Version>7.0.0.67</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>PlugPlugOwl Standard Dll (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9690000</BaseAddress>
<Size>5595136</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\MPS.dll</Path>
<Version>5.8.1.37174</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Modular Parsing System</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9bf0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ahclient.dll</Path>
<Version>2.0.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Help Client Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9c50000</BaseAddress>
<Size>569344</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\manta.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9ce0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\tbb.dll</Path>
<Version>4, 4, 2016, 0412</Version>
<Company>Intel Corporation</Company>
<Description>Intel(R) Threading Building Blocks library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9d30000</BaseAddress>
<Size>499712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\VulcanControl.dll</Path>
<Version>__</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Vulcan Application Control Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9db0000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\VulcanMessage5.dll</Path>
<Version>__</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Vulcan Message Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9e50000</BaseAddress>
<Size>1241088</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdbePM.dll</Path>
<Version>2.5.00</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe PatchMatch</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9f80000</BaseAddress>
<Size>167936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\CITThreading.dll</Path>
<Version>2.1.0.1 ( 32 bit Debug)</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>CITTHREADING_NAME, 2.1.0.1 ( 32 bit Debug)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9fb0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\adobe_caps.dll</Path>
<Version>10,0,0,6</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CAPS DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa190000</BaseAddress>
<Size>1191936</Size>
<Path>C:\Windows\SYSTEM32\OPENGL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OpenGL Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa2c0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa5f0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\IMSLib.dll</Path>
<Version>10.0.0.1</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>IMSLib DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa9c0000</BaseAddress>
<Size>9007104</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\File Formats\Dicom.8bi</Path>
<Version>18.0.1</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Dicom Plugin</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaba80000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\GLU32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека подпрограмм OpenGL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaabca0000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PLUGIN.dll</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Plugin Utilities</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaade70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\icm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Color Management Module (CMM)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab06d0000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\c_g18030.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>GB18030 DBCS-Unicode Conversion DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab0b60000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeSVGAGM.dll</Path>
<Version>1.0.0.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe SVG AGM Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab1e60000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeXMPFiles.dll</Path>
<Version>5.7-f022 ( 64 bit ), 79.159824, 2016/09/14-01:09:01</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XMP Files 5.7-f022 ( 64 bit )</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab22e0000</BaseAddress>
<Size>1544192</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Spaces.8li</Path>
<Version>18.0.1</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Spaces</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab3410000</BaseAddress>
<Size>167936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\libglog.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabb070000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobePIP.dll</Path>
<Version>7.4.1.60.45263</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Product Improvement Program</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabb250000</BaseAddress>
<Size>380928</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\BIBUtils.dll</Path>
<Version>1.1.01.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Bravo Interface Binder Utilities</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabcc00000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\SYSTEM32\STI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека устройств неподвижных изображений </Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac0b40000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\dlnashext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLNA Namespace DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1300000</BaseAddress>
<Size>598016</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\BIB.dll</Path>
<Version>1.2.03.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Bravo Interface Binder</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\SYSTEM32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeXMPScript.dll</Path>
<Version>5.2-s002 ( 64 bit ), 79.159824, 2016/09/14-01:09:01</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XMP Script 5.2-s002 ( 64 bit )</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac4c50000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\WSOCK32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6aa0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\amtlib.dll</Path>
<Version>10.0.0.3</Version>
<Company>painter</Company>
<Description>AMTEmu Licensing</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\FastCore.8bx</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac7710000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\wiatrace.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WIA Tracing</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca540000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SYSTEM32\DCIMAN32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DCI Manager</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacac80000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SYSTEM32\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>69</ProcessIndex>
<ProcessId>10000</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957424930105</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>AdobeIPCBroker.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe&quot; &quot;-launchedbyvulcan&quot;</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>5.0.0.76</Version>
<Description>Adobe IPC Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0xbe0000</BaseAddress>
<Size>798720</Size>
<Path>C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe</Path>
<Version>5.0.0.76</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe IPC Broker</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>70</ProcessIndex>
<ProcessId>10064</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957636746019</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Adobe Spaces Helper.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe&quot; --type=renderer --no-sandbox --touch-events=disabled --lang=en-US --lang=ru --locales-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\locales\\&quot; --log-file=&quot;C:\Users\User\AppData\Roaming\Adobe\Adobe Photoshop CC 2017\Logs\debug.log&quot; --resources-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\\&quot; --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;8940.0.1405287427\319210639&quot; /prefetch:673131151</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ff6c2ef0000</BaseAddress>
<Size>1196032</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaa1110000</BaseAddress>
<Size>70823936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\libcef.dll</Path>
<Version>3.2526.1347.gcf20046</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SSPICLI.DLL</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>71</ProcessIndex>
<ProcessId>8596</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957641371503</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Adobe Spaces Helper.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe&quot; --type=renderer --no-sandbox --touch-events=disabled --lang=en-US --lang=ru --locales-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\locales\\&quot; --log-file=&quot;C:\Users\User\AppData\Roaming\Adobe\Adobe Photoshop CC 2017\Logs\debug.log&quot; --resources-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\\&quot; --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;8940.1.1139889345\75461215&quot; /prefetch:673131151</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ff6c2ef0000</BaseAddress>
<Size>1196032</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaa1110000</BaseAddress>
<Size>70823936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\libcef.dll</Path>
<Version>3.2526.1347.gcf20046</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SSPICLI.DLL</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>72</ProcessIndex>
<ProcessId>11172</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957658059215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; &quot;C:\Program Files (x86)\Common Files\Adobe\CEP\extensions\com.adobe.previewHD\PSLoader\loader.html&quot; 2ec98b7b-08f4-4716-915a-e20a700b24cb 8940 PHXS 18.0.1 com.adobe.preview.loader 1 &quot;C:\Program Files (x86)\Common Files\Adobe\CEP\extensions\com.adobe.previewHD&quot; &quot;Photoshop&quot; 16 WyItLWVuYWJsZS1ub2RlanMiXQ== ru_RU 4293980400 1</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>73</ProcessIndex>
<ProcessId>11216</ProcessId>
<ParentProcessId>11172</ParentProcessId>
<ParentProcessIndex>72</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957800622174</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=ru --log-file=&quot;C:\Users\User\AppData\Local\Temp\CEPHtmlEngine7-PHXS-18.0.1-com.adobe.preview.loader.log&quot; --log-severity=error --params_ppid=PHXS --params_ppversion=18.0.1 --params_extensionid=com.adobe.preview.loader --params_loglevel=1 --params_serverid=8940 --params_extensionuuid=2ec98b7b-08f4-4716-915a-e20a700b24cb --params_windowid=70742 --params_commandline=WyItLWVuYWJsZS1ub2RlanMiXQ== --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=11172 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;11172.0.296388529\1274093304&quot; /prefetch:673131151</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x6d990000</BaseAddress>
<Size>3055616</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\ffmpegsumo.dll</Path>
<Version>41.0.2272.104</Version>
<Company>The Chromium Authors</Company>
<Description>Chromium</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>74</ProcessIndex>
<ProcessId>10844</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958201141405</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\extensions\com.adobe.experimentation.extension\index.html&quot; e44c0384-b65f-4f05-a36a-c6092cb32d00 8940 PHXS 18.0.1 com.adobe.experimentation.extension 1 &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\extensions\com.adobe.experimentation.extension&quot; &quot;Photoshop&quot; 16 WyItLWVuYWJsZS1ub2RlanMiXQ== ru_RU 4293980400 1</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>75</ProcessIndex>
<ProcessId>9092</ProcessId>
<ParentProcessId>10844</ParentProcessId>
<ParentProcessIndex>74</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958208470288</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=ru --log-file=&quot;C:\Users\User\AppData\Local\Temp\CEPHtmlEngine7-PHXS-18.0.1-com.adobe.experimentation.extension.log&quot; --log-severity=error --params_ppid=PHXS --params_ppversion=18.0.1 --params_extensionid=com.adobe.experimentation.extension --params_loglevel=1 --params_serverid=8940 --params_extensionuuid=e44c0384-b65f-4f05-a36a-c6092cb32d00 --params_windowid=198892 --params_commandline=WyItLWVuYWJsZS1ub2RlanMiXQ== --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=10844 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;10844.0.379179099\270765323&quot; /prefetch:673131151</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x6d990000</BaseAddress>
<Size>3055616</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\ffmpegsumo.dll</Path>
<Version>41.0.2272.104</Version>
<Company>The Chromium Authors</Company>
<Description>Chromium</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>76</ProcessIndex>
<ProcessId>11496</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958406617238</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SearchUI.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe&quot; -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>Search and Cortana application</Description>
<modulelist>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ff79c3c0000</BaseAddress>
<Size>10706944</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Search and Cortana application</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\SYSTEM32\chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\SYSTEM32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4c70000</BaseAddress>
<Size>4874240</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab52c0000</BaseAddress>
<Size>2445312</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5840000</BaseAddress>
<Size>3108864</Size>
<Path>C:\Windows\System32\Speech_OneCore\Common\sapi_onecore.dll</Path>
<Version>5.3.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Speech API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5db0000</BaseAddress>
<Size>9781248</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9d50000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;CortanaApi.ProxyStub.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe770000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabefa0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\Cortana.Persona.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana.Persona</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac10b0000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\PersonaX.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PersonaX</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\SYSTEM32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3bf0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionMgr.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana Action Manager</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bb0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\windows.cortana.pal.desktop.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.PAL.Desktop</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7c50000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\BingConfigurationClient.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bing Configuration Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\SYSTEM32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>77</ProcessIndex>
<ProcessId>11408</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794962679173110</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>node.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\node.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\node.exe&quot; &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Generator-builtin&quot; --launchreason menu --menu crema-dummy-menu --photoshopVersion 18.0.1 -i \\.\pipe\36b615a8-a6c5-11e8-b291-8ffa7e69373b_i -o \\.\pipe\36b615a8-a6c5-11e8-b291-8ffa7e69373b_o -f &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Generator&quot; -f &quot;C:\Program Files\Common Files\Adobe\Plug-Ins\CC\Generator&quot;</CommandLine>
<CompanyName>Node.js</CompanyName>
<Version>4.3.1</Version>
<Description>Node.js: Server-side JavaScript</Description>
<modulelist>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ff6cbb20000</BaseAddress>
<Size>14237696</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\node.exe</Path>
<Version>4.3.1</Version>
<Company>Node.js</Company>
<Description>Node.js: Server-side JavaScript</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>78</ProcessIndex>
<ProcessId>12164</ProcessId>
<ParentProcessId>11408</ParentProcessId>
<ParentProcessIndex>77</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794962697229215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>conhost.exe</ProcessName>
<ImagePath>C:\Windows\system32\conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0x4</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffabe520000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SYSTEM32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.DLL</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>79</ProcessIndex>
<ProcessId>5612</ProcessId>
<ParentProcessId>904</ParentProcessId>
<ParentProcessIndex>22</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131794965205293998</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>dashost.exe</ProcessName>
<ImagePath>C:\Windows\system32\dashost.exe</ImagePath>
<CommandLine>dashost.exe {609e1ffd-7b4d-4dbc-a36f725917d81f2d}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Device Association Framework Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ff6559c0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\dashost.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Framework Provider Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabb1a0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\DAFWSD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF WSD Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabc970000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\dafupnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF UPnP Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>80</ProcessIndex>
<ProcessId>9720</ProcessId>
<ParentProcessId>9180</ParentProcessId>
<ParentProcessIndex>81</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794969418818027</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Windows10UpgraderApp.exe</ProcessName>
<ImagePath>C:\Windows10Upgrade\Windows10UpgraderApp.exe</ImagePath>
<CommandLine>&quot;C:\Windows10Upgrade\Windows10UpgraderApp.exe&quot;  /Install /ClientID Win10Upgrade:VNL:NHV18:{} /SkipEULA /PostEosUi</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>1.4.9200.22452</Version>
<Description>Помощник по обновлению Windows 10</Description>
<modulelist>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0xb30000</BaseAddress>
<Size>1875968</Size>
<Path>C:\Windows10Upgrade\Windows10UpgraderApp.exe</Path>
<Version>1.4.9200.22452</Version>
<Company>Microsoft Corporation</Company>
<Description>Помощник по обновлению Windows 10</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d6e0000</BaseAddress>
<Size>634880</Size>
<Path>C:\Windows\SysWOW64\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d780000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\SysWOW64\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d860000</BaseAddress>
<Size>1245184</Size>
<Path>C:\Windows\SysWOW64\MFC42u.dll</Path>
<Version>6.06.8063.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека MFCDLL - розничная версия</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6ded0000</BaseAddress>
<Size>630784</Size>
<Path>C:\Windows\SysWOW64\ODBC32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ODBC Driver Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfc0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfd0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SysWOW64\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e010000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows10Upgrade\Downloader.dll</Path>
<Version>1.4.9200.22452 (win8_ldr.180426-0600)</Version>
<Company>Microsoft Corporation</Company>
<Description>Downloader</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e050000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.DLL</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>82</ProcessIndex>
<ProcessId>8944</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795005508439638</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>fontdrvhost.exe</ProcessName>
<ImagePath>C:\Windows\system32\fontdrvhost.exe</ImagePath>
<CommandLine>&quot;fontdrvhost.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Usermode Font Driver Host</Description>
<modulelist>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ff654db0000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\system32\fontdrvhost.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Usermode Font Driver Host</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>83</ProcessIndex>
<ProcessId>6684</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795006053748558</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Microsoft.Photos.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe&quot; -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ff705e40000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bb10000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bc70000</BaseAddress>
<Size>3158016</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bf80000</BaseAddress>
<Size>2994176</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9c260000</BaseAddress>
<Size>20144128</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9d5a0000</BaseAddress>
<Size>29011968</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9fb20000</BaseAddress>
<Size>7950336</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.3_1.3.24201.0_x64__8wekyb3d8bbwe\SharedLibrary.dll</Path>
<Version></Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Shared Framework</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa03f0000</BaseAddress>
<Size>4546560</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\FaceSdkStoreWrapper.dll</Path>
<Version>16.425.0.0</Version>
<Company>Microsoft Corporation</Company>
<Description>FaceSdkStoreWrapper</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa0850000</BaseAddress>
<Size>2371584</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\MediaEngine.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab270000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\System32\Windows.AccountsControl.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Accounts Control</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\Windows.System.Diagnostics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Diagnostics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f60000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\CryptoWinRT.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto WinRT Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9270000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9b40000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x64__8wekyb3d8bbwe\mrt100_app.dll</Path>
<Version>1.4.24201.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabea30000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\Windows.Energy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Energy Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0fa0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1c70000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCOMP140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C/C++ OpenMP Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2c00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\clrcompression.dll</Path>
<Version>1.0.23123.00 built by: PROJECTKREL</Version>
<Company>Microsoft Corporation</Company>
<Description>ClrCompression</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SYSTEM32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\mrt100.dll</Path>
<Version>1.0.24120.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OleAut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>84</ProcessIndex>
<ProcessId>6208</ProcessId>
<ParentProcessId>12140</ParentProcessId>
<ParentProcessIndex>85</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795181740423780</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>OneDrive.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</ImagePath>
<CommandLine> /updateInstalled /background</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>18.131.0701.0007</Version>
<Description>Microsoft OneDrive</Description>
<modulelist>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x11f0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x55a0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSync.Resources.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\MSHTML.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6bab0000</BaseAddress>
<Size>4472832</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Widgets.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d210000</BaseAddress>
<Size>4993024</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Gui.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\Wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ce0000</BaseAddress>
<Size>1519616</Size>
<Path>C:\Windows\SysWOW64\wpc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека параметров родительского контроля</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70f00000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71200000</BaseAddress>
<Size>708608</Size>
<Path>C:\Windows\SysWOW64\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x712b0000</BaseAddress>
<Size>602112</Size>
<Path>C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71350000</BaseAddress>
<Size>2867200</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Quick.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71630000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x716b0000</BaseAddress>
<Size>1294336</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LIBEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x717f0000</BaseAddress>
<Size>2637824</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Qml.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71a80000</BaseAddress>
<Size>4796416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Core.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71f20000</BaseAddress>
<Size>6033408</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SyncEngine.DLL</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Sync Engine</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72530000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72550000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72810000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72820000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SysWOW64\MicrosoftAccountTokenProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Token Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72850000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\SysWOW64\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728b0000</BaseAddress>
<Size>135168</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncFAL.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDriveFile Sync FAL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\SysWOW64\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72bb0000</BaseAddress>
<Size>1105920</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\platforms\qwindows.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e90000</BaseAddress>
<Size>299008</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SSLEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ee0000</BaseAddress>
<Size>950272</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Network.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72fd0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\loadperf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Загрузка и выгрузка счетчиков производительности</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ff0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\pdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль поддержки данных производительности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73040000</BaseAddress>
<Size>253952</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5WinExtras.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73080000</BaseAddress>
<Size>880640</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ADAL.dll</Path>
<Version>1.0.2110.0526</Version>
<Company>Microsoft</Company>
<Description>ADAL.Native</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73160000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WSOCK32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73170000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SysWOW64\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x731d0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\WnsClientApi.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive WNS Client Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73240000</BaseAddress>
<Size>520192</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LogUploader.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive Sync LogUploader Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x732c0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncViews.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Qt Components</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73400000</BaseAddress>
<Size>159744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\UpdateRingSettings.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Ring Settings</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73430000</BaseAddress>
<Size>1748992</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncSessions.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>P2P Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x735e0000</BaseAddress>
<Size>671744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\RemoteAccess.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73690000</BaseAddress>
<Size>188416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Telemetry.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Telemetry Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ETWLog.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>ETW Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736d0000</BaseAddress>
<Size>3600384</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncClient.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Client</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73af0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LoggingPlatform.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Logging Platform</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73dc0000</BaseAddress>
<Size>1171456</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ucrtbase.dll</Path>
<Version>10.0.17134.12 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73fb0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\MSWSOCK.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74090000</BaseAddress>
<Size>462848</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\MSVCP140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\VCRUNTIME140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74220000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>86</ProcessIndex>
<ProcessId>6140</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795747339404666</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=764E64A4EA650A23B18EB059FF0B4B51 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=764E64A4EA650A23B18EB059FF0B4B51 --renderer-client-id=106 --mojo-platform-channel-handle=6612 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>87</ProcessIndex>
<ProcessId>11432</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755605761168</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=9DD318D38190D474A9A0F5AFD262A449 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=9DD318D38190D474A9A0F5AFD262A449 --renderer-client-id=109 --mojo-platform-channel-handle=4152 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>88</ProcessIndex>
<ProcessId>10384</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755746873891</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=7E669976FFDCEE94D9B90B02CADE1179 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E669976FFDCEE94D9B90B02CADE1179 --renderer-client-id=112 --mojo-platform-channel-handle=5412 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>90</ProcessIndex>
<ProcessId>6936</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795756360200321</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --renderer-client-id=116 --mojo-platform-channel-handle=4024 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>98</ProcessIndex>
<ProcessId>6080</ProcessId>
<ParentProcessId>84</ParentProcessId>
<ParentProcessIndex>97</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795771125310655</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MCLauncher.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe&quot; </CommandLine>
<CompanyName></CompanyName>
<Version>1.0</Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795771127806606</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>2830336</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Version>1.0</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771129292604</Timestamp>
<BaseAddress>0x750000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771335510731</Timestamp>
<BaseAddress>0x11000000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771334241016</Timestamp>
<BaseAddress>0x12000000</BaseAddress>
<Size>360448</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771129285523</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795771129286235</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795771129295328</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795771135408057</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795771129575672</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129398434</Timestamp>
<BaseAddress>0x66680000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771136825814</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795771129423112</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771129349562</Timestamp>
<BaseAddress>0x6b830000</BaseAddress>
<Size>2584576</Size>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795771329638947</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795771329610149</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795771329592759</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795771136045859</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795771131298623</Timestamp>
<BaseAddress>0x6d180000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795771136082794</Timestamp>
<BaseAddress>0x6dca0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Script Runtime</Description>
</module>
<module>
<Timestamp>131795771133718253</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795771129406131</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795771329618480</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795771329601483</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795771336447829</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771135435621</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795771135446667</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771136073867</Timestamp>
<BaseAddress>0x70e90000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Script Host Runtime Library</Description>
</module>
<module>
<Timestamp>131795771135423397</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795771135552456</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795771136181434</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771328759427</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771135541570</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795771347140137</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795771347110306</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795771135314174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771347090516</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795771347075776</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795771328179609</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795771130913562</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795771135359123</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795771129415027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795771130899582</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795771133098293</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795771132990161</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795771131765102</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795771129389543</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795771129317462</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795771129360685</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795771129360034</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771129496759</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795771129358136</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129357408</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795771129365891</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795771129359203</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795771129353720</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771135412052</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795771129350362</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795771129366695</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795771136054082</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795771131750596</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795771129363162</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795771328737550</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795771135228888</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795771129301509</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771129362062</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795771135227735</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795771129363985</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795771129356607</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795771129364960</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795771129354665</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795771129370252</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795771129352041</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795771129367584</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795771129351257</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771129361361</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795771129369244</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129368545</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795771131168008</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795771129352931</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771133704572</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795771129355632</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795771347076821</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795771127807387</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795771127807116</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>104</ProcessIndex>
<ProcessId>12696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777567759490</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=E83DB721798C8A70C76CD26F6F4EE1BC --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=E83DB721798C8A70C76CD26F6F4EE1BC --renderer-client-id=119 --mojo-platform-channel-handle=7052 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777567991690</Timestamp>
<BaseAddress>0xc00000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777567961139</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777569452751</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777567980184</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777567981270</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777567994943</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777570994535</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777570968696</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777570908362</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777570920904</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777570943637</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777570874151</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777570891841</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777568100773</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777570569484</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777570619251</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777570607590</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777570676211</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777570557202</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777570691164</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777570539079</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777569494420</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777570658737</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777569526517</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777569154123</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777570594964</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777570630821</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777570523174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777570582120</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777570646486</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777570953652</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777569213807</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777568156054</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777569481011</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777568142933</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777568179155</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777568043561</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777568042430</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777569239058</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777568075566</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777568073430</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777568086784</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777568041126</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777568081914</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777568046844</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777568038347</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777568088134</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777569468247</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777569466798</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777568077279</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777569469408</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777568024100</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777568039823</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777569470854</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777568036731</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777568054568</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777568078714</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777568050811</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777568084892</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777568089486</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777568083413</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777568044758</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777569464930</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777569463567</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777568116745</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777568080182</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777569457550</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777568052363</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777570632192</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777567961904</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777567961630</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>106</ProcessIndex>
<ProcessId>5556</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777595302537</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=3ADFA2396247AD5E547F61590603D06D --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=3ADFA2396247AD5E547F61590603D06D --renderer-client-id=121 --mojo-platform-channel-handle=6636 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777595490187</Timestamp>
<BaseAddress>0x1020000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595475498</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595491301</Timestamp>
<BaseAddress>0x5550000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777596381097</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595481485</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777595482474</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777595494304</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777597543015</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777597521210</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777597472595</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777597484525</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777597497517</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777597428793</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777597448444</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777595565558</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777597103476</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777597165296</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777597153510</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777597221087</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777597072535</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777597233493</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777597059294</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777596424202</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777597205195</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777596436120</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777596128973</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777597128037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777597177209</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777597044137</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777597116160</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777597192860</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777597506812</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777596148547</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777595627397</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777596410831</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777595610560</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777595638942</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777595529014</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777595527983</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777596182171</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777595541526</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777595540326</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777595551866</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777595526606</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777595547732</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777595531563</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777595524005</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777595553384</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777596396507</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777596394953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777595543299</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777596397607</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777595508927</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595525398</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777596398892</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777595522182</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777595538927</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777595544568</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777595535397</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777595550455</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777595554628</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777595549128</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777595530150</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777596393437</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777596392132</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777595583766</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777595545878</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777596385979</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777595536930</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777597178434</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777595476066</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777595475814</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>107</ProcessIndex>
<ProcessId>12560</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777638339022</CreateTime>
<FinishTime>131795778158128556</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=utility --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --lang=ru --service-sandbox-type=utility --utility-allowed-dir=&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data\file_rating&quot; --utility-enable-file-rating --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --service-request-channel-token=641C5D89318E923EF94DCE862505059D --process-name=&quot;Антивирусная проверка загруженных файлов&quot; --mojo-platform-channel-handle=6132 --ignored=&quot; --type=renderer &quot; /prefetch:8</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777638514999</Timestamp>
<BaseAddress>0x9a0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777638499252</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777640777675</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777638505336</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777638506616</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777638520771</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777643013198</Timestamp>
<BaseAddress>0x68970000</BaseAddress>
<Size>1605632</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\7z.dll</Path>
<Version>16.04</Version>
<Company>Igor Pavlov</Company>
<Description>7z Plugin</Description>
</module>
<module>
<Timestamp>131795777644063584</Timestamp>
<BaseAddress>0x6cea0000</BaseAddress>
<Size>741376</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\unpacki.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795777644499194</Timestamp>
<BaseAddress>0x6d050000</BaseAddress>
<Size>188416</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\ph.dll</Path>
<Version>1.0.0.3</Version>
<Company>Yandex LLC</Company>
<Description>PH</Description>
</module>
<module>
<Timestamp>131795777638678022</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777641007171</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777641094369</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777641078940</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777641162760</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777640993878</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777641193425</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777640980953</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777640934358</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777641144289</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777640949510</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777638805651</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777641060291</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777641111375</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777640964374</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777641045959</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777641129849</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777638824119</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777638777842</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777640905386</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777638757989</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777638790654</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777638640639</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777638639616</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777638865082</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777638653602</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777638652361</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777638664931</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777638638334</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777638660518</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777638643504</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777638635699</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777638666147</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777640885499</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777640884150</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777638655024</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777640887705</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777638622442</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777638636998</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777640890927</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777638634183</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777638650757</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777638657739</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777638647299</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777638663396</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777638667522</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777638661911</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777638641764</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777640882612</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777640878814</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777638718043</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777638659168</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777640867696</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777638648757</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777641112838</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777638499795</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777638499542</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>108</ProcessIndex>
<ProcessId>2436</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795777644009218</CreateTime>
<FinishTime>131795779784342380</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchProtocolHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchProtocolHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchProtocolHost.exe&quot; Global\UsGthrFltPipeMssGthrPipe286_ Global\UsGthrCtrlFltPipeMssGthrPipe286 1 -2147483646 &quot;Software\Microsoft\Windows Search&quot; &quot;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)&quot; &quot;C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc&quot; &quot;DownLevelDaemon&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Protocol Host</Description>
<modulelist>
<module>
<Timestamp>131795777645159014</Timestamp>
<BaseAddress>0x7ff71ad80000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\SearchProtocolHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Protocol Host</Description>
</module>
<module>
<Timestamp>131795777646253333</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\System32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795777674143166</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795777653911361</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795777653958760</Timestamp>
<BaseAddress>0x7ffac7cd0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\mssph.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик протоколов поиска Microsoft</Description>
</module>
<module>
<Timestamp>131795777646404209</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795777672706217</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777662406241</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795777654238495</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\authz.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795777646239073</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777646227946</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777646240001</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777646230573</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777646209419</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777646219266</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777646236729</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777646225633</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777646226951</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777646182523</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777646208766</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777672880184</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777672879070</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777646208012</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777646218296</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777646204698</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777648403085</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777646181578</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777646229758</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777646359182</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777646231420</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777646217468</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777646223693</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777651470786</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777646228871</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777646224544</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777645159316</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>109</ProcessIndex>
<ProcessId>12008</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795777651421021</CreateTime>
<FinishTime>131795779784529714</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchFilterHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchFilterHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchFilterHost.exe&quot; 0 708 712 720 8192 716 </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Filter Host</Description>
<modulelist>
<module>
<Timestamp>131795777651457218</Timestamp>
<BaseAddress>0x7ff68a750000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\SearchFilterHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Filter Host</Description>
</module>
<module>
<Timestamp>131795777652430059</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\System32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795777653510417</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795777652527425</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777652473355</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777652337295</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777652352101</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777652470728</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777653516465</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777652314737</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777652336608</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777652335832</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777652348843</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777652333560</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777653216837</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777652313695</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777652472487</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777652465968</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777652468742</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777652346577</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777652353955</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777652357088</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777651457501</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>110</ProcessIndex>
<ProcessId>8656</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777889654010</CreateTime>
<FinishTime>131795777905540714</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>explorer.exe</ProcessName>
<ImagePath>C:\Windows\SysWOW64\explorer.exe</ImagePath>
<CommandLine>explorer.exe /select, &quot;C:\Users\User\Downloads\Wireshark-win64-2.6.2.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795777892769117</Timestamp>
<BaseAddress>0x1000000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777892770264</Timestamp>
<BaseAddress>0x1110000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777889699586</Timestamp>
<BaseAddress>0x13c0000</BaseAddress>
<Size>4296704</Size>
<Path>C:\Windows\SysWOW64\explorer.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795777892761055</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777892761986</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777892773065</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777893847270</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795777894119896</Timestamp>
<BaseAddress>0x61030000</BaseAddress>
<Size>262144</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg.dll</Path>
<Version>3, 0, 0, 1160</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795777905323145</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795777892910294</Timestamp>
<BaseAddress>0x6b750000</BaseAddress>
<Size>880640</Size>
<Path>C:\Windows\SysWOW64\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795777892901054</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795777892863391</Timestamp>
<BaseAddress>0x6d780000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\SysWOW64\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795777894943365</Timestamp>
<BaseAddress>0x6e2a0000</BaseAddress>
<Size>4440064</Size>
<Path>C:\Windows\SysWOW64\ExplorerFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795777892892000</Timestamp>
<BaseAddress>0x6ec40000</BaseAddress>
<Size>442368</Size>
<Path>C:\Windows\SysWOW64\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795777893892516</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777893903892</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795777893877718</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777892854636</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777892881973</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777892873122</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795777892973773</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777893330943</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777894135029</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795777893876643</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777892960580</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777892800882</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777892800131</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777893366650</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777892798092</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777892819284</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777892799164</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777892807465</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777893853501</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777892792387</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777892808537</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777894292333</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777893864954</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777892817162</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777892822584</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777892783261</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777892802636</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777892821664</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777892818154</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777892816184</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777892809562</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777892813119</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777892805257</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777892820198</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777892804198</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777892801730</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777892795864</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777892794715</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777893851248</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777892806379</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777892814413</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777889700112</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777889699874</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>111</ProcessIndex>
<ProcessId>9032</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777895284069</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>explorer.exe</ProcessName>
<ImagePath>C:\Windows\explorer.exe</ImagePath>
<CommandLine>C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795777911330291</Timestamp>
<BaseAddress>0x4d80000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795777920515787</Timestamp>
<BaseAddress>0x6530000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\Microsoft Office\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795777903881315</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795777903867506</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795777895813346</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\explorer.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795777906005639</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\duser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795777922060868</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795777918507242</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795777907532495</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\System32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795777910997447</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795777915260331</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795777910978745</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\System32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795778008622616</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795778007235790</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\devrtl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795777909146457</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795777902950088</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\System32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795778007048279</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795777902932644</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795777909802797</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777909791020</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777917395017</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\linkinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795777918158137</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795777966565943</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795777908125051</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795777905900322</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\dui70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795777908270107</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795777922014669</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\System32\networkexplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795778007216762</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795777919764442</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795777915281766</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795777909775471</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795777910387599</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795777905243222</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795777919412503</Timestamp>
<BaseAddress>0x7ffac1710000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\amd64\FileSyncShell64.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795777904716802</Timestamp>
<BaseAddress>0x7ffac18b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg64.dll</Path>
<Version>1, 0, 0, 1140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795777944562485</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795777903915791</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777922001525</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795777903903305</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777909321798</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777909330655</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777906462233</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795777910949757</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795777920555307</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795777906356495</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795777905097743</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\System32\ExplorerFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795777908567233</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795777911007559</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795777914831974</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795777905390625</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777902894862</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795777906986296</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795777906995835</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795777903975733</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795777906257948</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795777919424461</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795777902880674</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777908138610</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795777902921260</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778008641775</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795777907005063</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795777918659102</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777918649579</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777909306748</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795777902905939</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795777906474194</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902941219</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795778008632518</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795777918171528</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795777907014508</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777903933947</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777902985171</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777903008375</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777902974089</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777905657867</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795777902999880</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777902852334</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777902849489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777902853126</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777902855116</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777902843222</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777902836309</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902838974</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777902841617</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777902844144</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777902848566</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777902824318</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777902854301</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777902835470</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902847555</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777902846521</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777902834719</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777916996283</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795777902838016</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777902833378</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777904879129</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777902823359</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777905449820</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795777920556415</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795777902842396</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777903888252</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777903413262</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777902840664</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777902837229</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777903887407</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795777902850328</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777903886124</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777902845086</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777902851375</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777895813598</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>112</ProcessIndex>
<ProcessId>9260</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777929610183</CreateTime>
<FinishTime>131795777984927725</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795777932875078</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795777933633940</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795777933654996</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777933511822</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795777933236004</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777933379835</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777933204420</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777933208459</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777933378161</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777933634843</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777933195335</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777933656824</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777933655979</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777933207456</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777933236938</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777933242803</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777933194415</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777933378995</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777933422499</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777933377233</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777933206622</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777933352390</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777932875316</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>113</ProcessIndex>
<ProcessId>8764</ProcessId>
<ParentProcessId>9032</ParentProcessId>
<ParentProcessIndex>111</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777945289446</CreateTime>
<FinishTime>131795777966465865</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Wireshark-win64-2.6.2.exe</ProcessName>
<ImagePath>C:\Users\User\Downloads\Wireshark-win64-2.6.2.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\Downloads\Wireshark-win64-2.6.2.exe&quot; </CommandLine>
<CompanyName>Wireshark development team</CompanyName>
<Version>2.6.2.0</Version>
<Description>Wireshark installer for 64-bit Windows</Description>
<modulelist>
<module>
<Timestamp>131795777966462721</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>503808</Size>
<Path>C:\Users\User\Downloads\Wireshark-win64-2.6.2.exe</Path>
<Version>2.6.2.0</Version>
<Company>Wireshark development team</Company>
<Description>Wireshark installer for 64-bit Windows</Description>
</module>
<module>
<Timestamp>131795777966463314</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777966463036</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>114</ProcessIndex>
<ProcessId>12552</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795777968941574</CreateTime>
<FinishTime>131795777998950648</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>consent.exe</ProcessName>
<ImagePath>C:\Windows\system32\consent.exe</ImagePath>
<CommandLine>consent.exe 348 420 000001C3866F4780</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Согласованный пользовательский интерфейс для административных приложений</Description>
<modulelist>
<module>
<Timestamp>131795777968980318</Timestamp>
<BaseAddress>0x7ff7ac660000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\consent.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Согласованный пользовательский интерфейс для административных приложений</Description>
</module>
<module>
<Timestamp>131795777980498441</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\duser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795777980145413</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\AudioSes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795777980857301</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777981479003</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795777980587991</Timestamp>
<BaseAddress>0x7ffab9010000</BaseAddress>
<Size>1409024</Size>
<Path>C:\Windows\System32\Windows.UI.Cred.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Prompt User Experience</Description>
</module>
<module>
<Timestamp>131795777974838275</Timestamp>
<BaseAddress>0x7ffabb9f0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\System32\msutb.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) сервера MSUTB</Description>
</module>
<module>
<Timestamp>131795777974804260</Timestamp>
<BaseAddress>0x7ffabba70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\MsCtfMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MsCtfMonitor DLL</Description>
</module>
<module>
<Timestamp>131795777974793522</Timestamp>
<BaseAddress>0x7ffabc5b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\amsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Anti-Malware Scan Interface</Description>
</module>
<module>
<Timestamp>131795777980110033</Timestamp>
<BaseAddress>0x7ffabd3c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\InputSwitch.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переключатель ввода Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795777985995216</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795777980126729</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\dui70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795777986419231</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\System32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795777978273384</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795777987476131</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795777980595097</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795777986654116</Timestamp>
<BaseAddress>0x7ffac1640000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\Windows.Internal.UI.Logon.ProxyStub.dll</Path>
<Version>10.0.14393.594 (rs1_release_inmarket.161213-1754)</Version>
<Company>Microsoft Corporation</Company>
<Description>Logon User Experience Proxy Stub</Description>
</module>
<module>
<Timestamp>131795777980442082</Timestamp>
<BaseAddress>0x7ffac1680000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\Windows.UI.CredDialogController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Контроллер диалоговых окон для ввода учетных данных пользователя</Description>
</module>
<module>
<Timestamp>131795777980426428</Timestamp>
<BaseAddress>0x7ffac16d0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\wincredui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Внутренний интерфейс диспетчера учетных данных</Description>
</module>
<module>
<Timestamp>131795777992554432</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795777979019901</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777986176635</Timestamp>
<BaseAddress>0x7ffac37b0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\FontGlyphAnimator.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Font Glyph Animator</Description>
</module>
<module>
<Timestamp>131795777979026126</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777980485018</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\Windows.UI.XamlHost.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>XAML Host</Description>
</module>
<module>
<Timestamp>131795777981822655</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795777996397360</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\System32\UIAutomationCore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795777980669842</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795777980658809</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795777974798730</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777983369008</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795777980648519</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795777982047525</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\System32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795777982029674</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795777982066941</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\avrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795777980156063</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795777980157388</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795777974788100</Timestamp>
<BaseAddress>0x7ffac97f0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wmsgapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinLogon IPC Client</Description>
</module>
<module>
<Timestamp>131795777982013616</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795777980466258</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795777980168550</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777974829262</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795777980115948</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795777979285013</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777981488304</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795777982499245</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795777980416590</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795777974818257</Timestamp>
<BaseAddress>0x7ffacac80000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\msimg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795777975513676</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795777982426324</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795777982054504</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795777980163186</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\devobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795777978121065</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795777982035520</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777975832479</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795777974781428</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777975824564</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777975848401</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777974774870</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777974823679</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795777975838253</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777975483352</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777975480402</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777974782340</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777974759394</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777974755227</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777974757590</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777974748323</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777975534791</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777975484109</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777975479485</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777974737313</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777974758607</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777974806532</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777975478407</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777975477227</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777974805823</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777974755958</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777974753684</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777979008730</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777974736415</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777974804981</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795777974745763</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777974812320</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777974747602</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777974754501</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777976198066</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795777975481532</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777979405959</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777975482469</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777974760131</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777968980573</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>115</ProcessIndex>
<ProcessId>13252</ProcessId>
<ParentProcessId>360</ParentProcessId>
<ParentProcessIndex>26</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131795777983764572</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>AUDIODG.EXE</ProcessName>
<ImagePath>C:\Windows\system32\AUDIODG.EXE</ImagePath>
<CommandLine>C:\Windows\system32\AUDIODG.EXE 0x3f4</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Изоляция графов аудиоустройств Windows </Description>
<modulelist>
<module>
<Timestamp>131795777983831921</Timestamp>
<BaseAddress>0x7ff644450000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\System32\audiodg.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Изоляция графов аудиоустройств Windows </Description>
</module>
<module>
<Timestamp>131795777987657478</Timestamp>
<BaseAddress>0x7ffab0410000</BaseAddress>
<Size>1802240</Size>
<Path>C:\Windows\System32\WMALFXGFXDSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SysFx DSP</Description>
</module>
<module>
<Timestamp>131795777987006767</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\AudioSes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795777987325185</Timestamp>
<BaseAddress>0x7ffac13e0000</BaseAddress>
<Size>552960</Size>
<Path>C:\Windows\System32\AudioEng.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Audio Engine</Description>
</module>
<module>
<Timestamp>131795777988064426</Timestamp>
<BaseAddress>0x7ffac15d0000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\System32\AUDIOKSE.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Audio Ks Endpoint</Description>
</module>
<module>
<Timestamp>131795777987334885</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\avrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795777987120263</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795777985530541</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795777985553442</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777985542529</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\devobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795777985878753</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777987008327</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777985919594</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777985543302</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777985558083</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777985917139</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777985559169</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777985509811</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777985555822</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777985544141</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777985554295</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777985531383</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777985518799</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777986012477</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777985508789</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777985918125</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777985916103</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777985556758</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777985532267</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777983832182</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>116</ProcessIndex>
<ProcessId>9824</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795777997156680</CreateTime>
<FinishTime>131795778048250727</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795777997172483</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795777998106067</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795777998057630</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795777998132709</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777998117532</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777997734588</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777998133585</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777997749740</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777997707384</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777997710268</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777997748214</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777997698554</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777997709343</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777997735391</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777997740844</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777997697673</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777997748967</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777997763823</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777997747380</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777997708545</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777998029154</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777997172713</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>117</ProcessIndex>
<ProcessId>10972</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795777999627989</CreateTime>
<FinishTime>131795778050153645</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795777999648788</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795777999983613</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795778000008235</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777999993479</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777999688221</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778000009044</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777999702312</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777999664533</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777999667201</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777999700799</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777999656659</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777999666347</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777999688933</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777999693967</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777999655839</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777999701542</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777999699849</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777999665630</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777999909223</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777999649020</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>118</ProcessIndex>
<ProcessId>11456</ProcessId>
<ParentProcessId>9032</ParentProcessId>
<ParentProcessIndex>111</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795778005314623</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Wireshark-win64-2.6.2.exe</ProcessName>
<ImagePath>C:\Users\User\Downloads\Wireshark-win64-2.6.2.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\Downloads\Wireshark-win64-2.6.2.exe&quot; </CommandLine>
<CompanyName>Wireshark development team</CompanyName>
<Version>2.6.2.0</Version>
<Description>Wireshark installer for 64-bit Windows</Description>
<modulelist>
<module>
<Timestamp>131795778009231982</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>503808</Size>
<Path>C:\Users\User\Downloads\Wireshark-win64-2.6.2.exe</Path>
<Version>2.6.2.0</Version>
<Company>Wireshark development team</Company>
<Description>Wireshark installer for 64-bit Windows</Description>
</module>
<module>
<Timestamp>131795778009245222</Timestamp>
<BaseAddress>0x480000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778015682938</Timestamp>
<BaseAddress>0x2030000</BaseAddress>
<Size>36864</Size>
<Path>C:\Users\User\AppData\Local\Temp\nswB814.tmp\InstallOptions.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795778014254891</Timestamp>
<BaseAddress>0x10000000</BaseAddress>
<Size>24576</Size>
<Path>C:\Users\User\AppData\Local\Temp\nswB814.tmp\System.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795778009238221</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795778009238911</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795778009248228</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795778011325628</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795778089634780</Timestamp>
<BaseAddress>0x6b7b0000</BaseAddress>
<Size>503808</Size>
<Path>C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795778014814877</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\riched20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795778010985816</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795778014835906</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795778011360794</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795778011372913</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795778014843868</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795778011346828</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795778011030934</Timestamp>
<BaseAddress>0x72510000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\shfolder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Folder Service</Description>
</module>
<module>
<Timestamp>131795778010950569</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778010974639</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778010712877</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795778011384519</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778009666389</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795778011008939</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795778010727286</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795778009272418</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795778009635084</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795778009634444</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795778009721108</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795778009632885</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778009632164</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778009640473</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778009633660</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778009627476</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778011330122</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795778009629360</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778009641448</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778010997934</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778011330953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778009637786</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778014972924</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795778009254650</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778009636664</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778009638589</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778009631391</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778009639548</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778009628515</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778010731370</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795778009625102</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778009642327</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778009624246</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778009635799</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778010952511</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778010951613</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778009648281</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795778009626440</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778015684351</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795778009630333</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778009232688</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795778009232417</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>119</ProcessIndex>
<ProcessId>2524</ProcessId>
<ParentProcessId>11456</ParentProcessId>
<ParentProcessIndex>118</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795778205265711</CreateTime>
<FinishTime>131795778449907874</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>vcredist_x64.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\vcredist_x64.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\vcredist_x64.exe&quot; /install /quiet /norestart</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>14.12.25810.0</Version>
<Description>Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810</Description>
<modulelist>
<module>
<Timestamp>131795778210427775</Timestamp>
<BaseAddress>0x840000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files\Wireshark\vcredist_x64.exe</Path>
<Version>14.12.25810.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810</Description>
</module>
<module>
<Timestamp>131795778210442423</Timestamp>
<BaseAddress>0x1100000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778210435297</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795778210436286</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795778210444947</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795778218643939</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795778221366721</Timestamp>
<BaseAddress>0x68850000</BaseAddress>
<Size>1150976</Size>
<Path>C:\Windows\SysWOW64\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795778213387731</Timestamp>
<BaseAddress>0x68970000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\SysWOW64\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795778211892360</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795778225123562</Timestamp>
<BaseAddress>0x6ce30000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795778282515800</Timestamp>
<BaseAddress>0x6ceb0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\RstrtMgr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер перезапуска</Description>
</module>
<module>
<Timestamp>131795778224990309</Timestamp>
<BaseAddress>0x6cee0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\usoapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Session Orchestrator API</Description>
</module>
<module>
<Timestamp>131795778222668117</Timestamp>
<BaseAddress>0x6cf00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\vsstrace.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795778219986472</Timestamp>
<BaseAddress>0x6cf20000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SysWOW64\spp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих точек защиты Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795778219594249</Timestamp>
<BaseAddress>0x6d000000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\srclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Windows System Restore Client Library</Description>
</module>
<module>
<Timestamp>131795778211638576</Timestamp>
<BaseAddress>0x6d050000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795778223770988</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795778218676426</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795778218687666</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795778282852553</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795778282546520</Timestamp>
<BaseAddress>0x71120000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\SysWOW64\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795778218664385</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795778230626743</Timestamp>
<BaseAddress>0x71160000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\sxproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека прокси защиты системы Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795778285675131</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778210585481</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795778249278981</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795778218605838</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795778212112533</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778249262768</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795778211975568</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795778250977817</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795778211987440</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795778210472101</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795778210537015</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795778210536267</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795778212420819</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795778210544928</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778210551034</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778210535428</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778210541828</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778218651308</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795778210533826</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778210551838</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778212772265</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778210558338</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778218652101</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778210549234</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778218630163</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795778210557390</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795778210454863</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778210534702</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778210556545</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778210532926</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778210548380</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778210550092</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778210546009</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778210540152</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778210552724</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778210539401</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778210538137</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778210543407</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778210542750</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778210553572</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795778210541005</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778210547203</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778210428509</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795778210428218</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>120</ProcessIndex>
<ProcessId>11036</ProcessId>
<ParentProcessId>2524</ParentProcessId>
<ParentProcessIndex>119</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795778214395625</CreateTime>
<FinishTime>131795778452248646</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>vcredist_x64.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\vcredist_x64.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\vcredist_x64.exe&quot; /install /quiet /norestart -burn.unelevated BurnPipe.{697252BA-65F0-4FD5-BF12-B766A9953B8A} {50175F90-C657-4E57-8E6E-540E3BD2D5E7} 2524</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>14.12.25810.0</Version>
<Description>Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810</Description>
<modulelist>
<module>
<Timestamp>131795778214451050</Timestamp>
<BaseAddress>0x840000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files\Wireshark\vcredist_x64.exe</Path>
<Version>14.12.25810.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810</Description>
</module>
<module>
<Timestamp>131795778214465354</Timestamp>
<BaseAddress>0x1300000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778214465795</Timestamp>
<BaseAddress>0x13d0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778214458935</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795778214459633</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795778214468416</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795778218835611</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795778216121811</Timestamp>
<BaseAddress>0x68970000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\SysWOW64\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795778222012167</Timestamp>
<BaseAddress>0x6b7b0000</BaseAddress>
<Size>503808</Size>
<Path>C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795778214619583</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795778219458456</Timestamp>
<BaseAddress>0x6d020000</BaseAddress>
<Size>143360</Size>
<Path>C:\Users\User\AppData\Local\Temp\{e2ee15e2-a480-4bc5-bfb7-e9803d1d9823}\.ba1\wixstdba.dll</Path>
<Version>3.7.3517.0</Version>
<Company>Microsoft Corporation</Company>
<Description>WiX Standard Bootstrapper Application</Description>
</module>
<module>
<Timestamp>131795778214607445</Timestamp>
<BaseAddress>0x6d050000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795778221823716</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\riched20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795778221778955</Timestamp>
<BaseAddress>0x6e2a0000</BaseAddress>
<Size>4440064</Size>
<Path>C:\Windows\SysWOW64\ExplorerFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795778219977174</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795778221834790</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795778218869440</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795778218882415</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795778221845989</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795778218856726</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795778216508862</Timestamp>
<BaseAddress>0x72500000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\feclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT File Encryption Client Interfaces</Description>
</module>
<module>
<Timestamp>131795778221803849</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778214583688</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795778218620300</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795778214665990</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778214634234</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795778219482612</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795778214645516</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795778214502009</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795778214556556</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795778214555835</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795778215119921</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795778214563862</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778214569777</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778214554622</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778214560817</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778218843499</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795778214553045</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778214570550</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778215512524</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778214575066</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778218844544</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778214567854</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778218823402</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795778214574088</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795778214474422</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778214553904</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778214573295</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778214552209</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778214567023</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778214568693</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778214565133</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778214559041</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778214571434</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778214558315</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778214557257</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778214562365</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778214561712</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778214572267</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795778214560019</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778219465897</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795778214566092</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778214451593</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795778214451330</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>121</ProcessIndex>
<ProcessId>9864</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795778225540656</CreateTime>
<FinishTime>131795778290826195</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795778225950821</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795778231606806</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795778229770036</Timestamp>
<BaseAddress>0x7ffac0fc0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\spp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих точек защиты Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795778236117068</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795778229793325</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\vsstrace.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795778229781683</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\System32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795778231340578</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dsrole.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795778230151193</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\sxproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека прокси защиты системы Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795778229437945</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795778229733727</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795778231662179</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778229494714</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778229650868</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778229464135</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778229467133</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778229649239</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778229419740</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778231219679</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778231218532</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778229466174</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778229495509</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778229500491</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778229418717</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778229650079</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778229782683</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778229664206</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795778229648087</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778229465385</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778229771169</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778229600832</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778225951048</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>122</ProcessIndex>
<ProcessId>9112</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778233163324</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>vssvc.exe</ProcessName>
<ImagePath>C:\Windows\system32\vssvc.exe</ImagePath>
<CommandLine>C:\Windows\system32\vssvc.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Microsoft® Volume Shadow Copy Service</Description>
<modulelist>
<module>
<Timestamp>131795778233223054</Timestamp>
<BaseAddress>0x7ff69d210000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\VSSVC.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service</Description>
</module>
<module>
<Timestamp>131795778236960155</Timestamp>
<BaseAddress>0x7ffac1690000</BaseAddress>
<Size>516096</Size>
<Path>C:\Windows\System32\catsrvut.dll</Path>
<Version>2001.12.10941.16384 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog Server Utilities</Description>
</module>
<module>
<Timestamp>131795778235339682</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795778235353194</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fltLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795778236101503</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795778235330886</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\virtdisk.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Disk API DLL</Description>
</module>
<module>
<Timestamp>131795778236181536</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795778235312630</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\vsstrace.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795778235292965</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\System32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795778236970418</Timestamp>
<BaseAddress>0x7ffac7e80000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\mfcsubs.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795778235749019</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795778236589454</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778236331302</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\samlib.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795778235302884</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\devobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795778235322056</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\authz.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795778236321713</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795778235650165</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778235659934</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778235271662</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778235274566</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778235658261</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778236590535</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778235260874</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778235271000</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778235303684</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778235270235</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778235273593</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778235268950</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778235730902</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778235259923</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778235659139</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778235293960</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778235657454</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778235272840</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778235277370</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778235275560</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778233223370</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>123</ProcessIndex>
<ProcessId>284</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778236890994</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k swprv</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795778236948261</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795778237990704</Timestamp>
<BaseAddress>0x7ffabd220000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\System32\swprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик программного обеспечения Microsoft® Volume Shadow Copy Service</Description>
</module>
<module>
<Timestamp>131795778238024341</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fltLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795778238689559</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795778238016772</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\virtdisk.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Disk API DLL</Description>
</module>
<module>
<Timestamp>131795778238009807</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\vsstrace.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795778238797239</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\System32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795778238379317</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795778238002742</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\devobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795778238084884</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795778238106525</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778238119208</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778237848893</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778238069532</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778238117518</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778238087879</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778237826515</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778238085768</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778238691232</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778238003645</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778238690445</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778237846089</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778237991665</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778238360028</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778237825108</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778238118419</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778238798278</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778238116693</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778238067953</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778237992699</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778237844499</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778236948497</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>124</ProcessIndex>
<ProcessId>8572</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778253406568</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>msiexec.exe</ProcessName>
<ImagePath>C:\Windows\system32\msiexec.exe</ImagePath>
<CommandLine>C:\Windows\system32\msiexec.exe /V</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Установщик Windows®</Description>
<modulelist>
<module>
<Timestamp>131795778259596194</Timestamp>
<BaseAddress>0x238870a0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\System32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778253563850</Timestamp>
<BaseAddress>0x7ff766ba0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\msiexec.exe</Path>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Установщик Windows®</Description>
</module>
<module>
<Timestamp>131795778259570059</Timestamp>
<BaseAddress>0x7ffaad900000</BaseAddress>
<Size>4726784</Size>
<Path>C:\Windows\AppPatch\apppatch64\AcLayers.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795778267501772</Timestamp>
<BaseAddress>0x7ffab1260000</BaseAddress>
<Size>10350592</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll</Path>
<Version>4.7.2117.0 built by: NET47REL1LAST</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Common Language Runtime - WorkStation</Description>
</module>
<module>
<Timestamp>131795778276928618</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\devrtl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795778275324308</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795778275333446</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795778259610277</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795778259661596</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778265457583</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795778267747643</Timestamp>
<BaseAddress>0x7ffabfa00000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\msvcr120_clr0400.dll</Path>
<Version>12.00.52519.0 built by: VSWINSERVICING</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778260359664</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795778399983100</Timestamp>
<BaseAddress>0x7ffac1010000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\System32\mscoree.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795778400005719</Timestamp>
<BaseAddress>0x7ffac1240000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll</Path>
<Version>4.7.2623.0 built by: NET471REL1LAST_C</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795778262571338</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795778267189195</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795778417041748</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795778400053783</Timestamp>
<BaseAddress>0x7ffac5b30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Assembly manager</Description>
</module>
<module>
<Timestamp>131795778259951873</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795778264680084</Timestamp>
<BaseAddress>0x7ffac7cc0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\msisip.dll</Path>
<Version>5.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSI Signature SIP Provider</Description>
</module>
<module>
<Timestamp>131795778265630538</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795778262583238</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795778323770185</Timestamp>
<BaseAddress>0x7ffac97f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\perfproc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов производительности системных процессов Windows</Description>
</module>
<module>
<Timestamp>131795778272914974</Timestamp>
<BaseAddress>0x7ffaca210000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\RstrtMgr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер перезапуска</Description>
</module>
<module>
<Timestamp>131795778281798291</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778259533909</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795778265279256</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795778264074461</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795778264625720</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795778265470245</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795778262605488</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795778261744074</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795778264613136</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795778264639501</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795778273070150</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795778272956330</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795778261891434</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795778259633594</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778260278752</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778260602827</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778260604728</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778264076719</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795778259576609</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778259578595</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778259572597</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778264077537</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778260603797</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778260601744</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778259515815</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778264075791</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778272946115</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778260600162</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778260598868</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778272945223</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778262622754</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795778259577351</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778265716961</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795778259571021</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778260302861</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778259514798</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778276914178</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795778259573318</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778259571855</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778259575900</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778259912248</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778259914551</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795778259575080</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778259913185</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778253564149</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>125</ProcessIndex>
<ProcessId>8656</ProcessId>
<ParentProcessId>2524</ParentProcessId>
<ParentProcessIndex>119</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795778434403526</CreateTime>
<FinishTime>131795778449509279</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>VC_redist.x64.exe</ProcessName>
<ImagePath>C:\ProgramData\Package Cache\{b8e12890-118d-4721-8e54-05d978086712}\VC_redist.x64.exe</ImagePath>
<CommandLine>&quot;C:\ProgramData\Package Cache\{b8e12890-118d-4721-8e54-05d978086712}\VC_redist.x64.exe&quot; -uninstall -quiet -burn.related.upgrade -burn.ancestors={e2ee15e2-a480-4bc5-bfb7-e9803d1d9823} -burn.embedded BurnPipe.{BE717A63-3124-43B0-8DF0-9BCCFE1C6C46} {7F991BFE-7F20-4BF3-80B9-32F4DBA651F1} 2524</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>14.0.24516.0</Version>
<Description>Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24516</Description>
<modulelist>
<module>
<Timestamp>131795778434634350</Timestamp>
<BaseAddress>0x10000</BaseAddress>
<Size>413696</Size>
<Path>C:\ProgramData\Package Cache\{b8e12890-118d-4721-8e54-05d978086712}\VC_redist.x64.exe</Path>
<Version>14.0.24516.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24516</Description>
</module>
<module>
<Timestamp>131795778434648128</Timestamp>
<BaseAddress>0x1360000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778434648583</Timestamp>
<BaseAddress>0x1480000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778434641410</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795778434642130</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795778434651378</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795778441076729</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795778441270302</Timestamp>
<BaseAddress>0x68850000</BaseAddress>
<Size>1150976</Size>
<Path>C:\Windows\SysWOW64\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795778436130151</Timestamp>
<BaseAddress>0x68970000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\SysWOW64\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795778434806108</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795778443637167</Timestamp>
<BaseAddress>0x6ce30000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795778443628036</Timestamp>
<BaseAddress>0x6cee0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\usoapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Session Orchestrator API</Description>
</module>
<module>
<Timestamp>131795778441281584</Timestamp>
<BaseAddress>0x6cf00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\vsstrace.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795778441259129</Timestamp>
<BaseAddress>0x6cf20000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SysWOW64\spp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих точек защиты Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795778441248268</Timestamp>
<BaseAddress>0x6d000000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\srclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Windows System Restore Client Library</Description>
</module>
<module>
<Timestamp>131795778434794184</Timestamp>
<BaseAddress>0x6d050000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795778441301056</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795778441109685</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795778441122291</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795778441096915</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795778445929094</Timestamp>
<BaseAddress>0x71160000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\sxproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека прокси защиты системы Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795778434770598</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795778440930826</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795778434848736</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778434820454</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795778434836911</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795778434685096</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795778434742405</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795778434741657</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795778435298794</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795778434750487</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778434756266</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778434740842</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778434747032</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778441083445</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795778434739183</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778434757031</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778436023989</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778434761608</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778441084251</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778434754465</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778441062552</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795778434760832</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795778434657620</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778434740050</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778434760017</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778434738141</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778434753620</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778434755332</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778434751570</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778434745317</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778434757914</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778434744552</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778434743114</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778434748913</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778434747946</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778434758962</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795778434746209</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778434752540</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778434634926</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795778434634658</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>126</ProcessIndex>
<ProcessId>6220</ProcessId>
<ParentProcessId>8656</ParentProcessId>
<ParentProcessIndex>125</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795778436498602</CreateTime>
<FinishTime>131795778449487186</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>VC_redist.x64.exe</ProcessName>
<ImagePath>C:\ProgramData\Package Cache\{b8e12890-118d-4721-8e54-05d978086712}\VC_redist.x64.exe</ImagePath>
<CommandLine>&quot;C:\ProgramData\Package Cache\{b8e12890-118d-4721-8e54-05d978086712}\VC_redist.x64.exe&quot; -uninstall -quiet -burn.related.upgrade -burn.ancestors={e2ee15e2-a480-4bc5-bfb7-e9803d1d9823} -burn.embedded BurnPipe.{BE717A63-3124-43B0-8DF0-9BCCFE1C6C46} {7F991BFE-7F20-4BF3-80B9-32F4DBA651F1} 2524 -burn.unelevated BurnPipe.{48270A10-6862-4006-8B01-6C4F9472A44D} {5996361E-1B16-4470-AEAB-C73797FE6398} 8656</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>14.0.24516.0</Version>
<Description>Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24516</Description>
<modulelist>
<module>
<Timestamp>131795778436566065</Timestamp>
<BaseAddress>0x10000</BaseAddress>
<Size>413696</Size>
<Path>C:\ProgramData\Package Cache\{b8e12890-118d-4721-8e54-05d978086712}\VC_redist.x64.exe</Path>
<Version>14.0.24516.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24516</Description>
</module>
<module>
<Timestamp>131795778436579766</Timestamp>
<BaseAddress>0x700000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778436572900</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795778436573839</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795778436582534</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795778441327246</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795778438075641</Timestamp>
<BaseAddress>0x68970000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\SysWOW64\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795778442687826</Timestamp>
<BaseAddress>0x6b7b0000</BaseAddress>
<Size>503808</Size>
<Path>C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795778436733415</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795778442256204</Timestamp>
<BaseAddress>0x6cd70000</BaseAddress>
<Size>143360</Size>
<Path>C:\Users\User\AppData\Local\Temp\{b8e12890-118d-4721-8e54-05d978086712}\.ba1\wixstdba.dll</Path>
<Version>3.7.3517.0</Version>
<Company>Microsoft Corporation</Company>
<Description>WiX Standard Bootstrapper Application</Description>
</module>
<module>
<Timestamp>131795778436721283</Timestamp>
<BaseAddress>0x6d050000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795778442576841</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\riched20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795778442529522</Timestamp>
<BaseAddress>0x6e2a0000</BaseAddress>
<Size>4440064</Size>
<Path>C:\Windows\SysWOW64\ExplorerFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795778442502351</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795778442588868</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795778441361803</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795778441378263</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795778442600490</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795778441349089</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795778438212692</Timestamp>
<BaseAddress>0x72500000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\feclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT File Encryption Client Interfaces</Description>
</module>
<module>
<Timestamp>131795778442555873</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778436695628</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795778440978535</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795778436773248</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778436748111</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795778442277432</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795778436761290</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795778436606302</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795778436665517</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795778436664767</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795778437154760</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795778436673103</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778436679196</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778436663741</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778436669975</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778441334349</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795778436662107</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778436679960</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778437936235</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778436686695</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778441335211</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778436677145</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778441315064</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795778436683797</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795778436589014</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778436662999</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778436682756</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778436661242</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778436676309</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778436678015</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778436674386</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778436668188</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778436680850</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778436667363</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778436666274</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778436671588</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778436670931</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778436681714</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795778436669155</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778442264244</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795778436675383</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778436566644</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795778436566376</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>127</ProcessIndex>
<ProcessId>776</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795778444410924</CreateTime>
<FinishTime>131795778496489041</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795778444445952</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795778446219853</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795778445863520</Timestamp>
<BaseAddress>0x7ffac0fc0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\spp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих точек защиты Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795778446358944</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795778445911171</Timestamp>
<BaseAddress>0x7ffac37b0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\sxproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека прокси защиты системы Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795778445886505</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\vsstrace.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795778445874946</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\System32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795778446189657</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dsrole.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795778445528349</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795778445822117</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795778446229567</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778445607136</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778445733287</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778445554437</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778445557842</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778445731331</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778445510504</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778446164492</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778446163608</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778445556886</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778445607992</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778445613339</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778445509620</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778445732492</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778445875933</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778445746497</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795778445730425</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778445555609</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778445864695</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778445702180</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778444446182</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>128</ProcessIndex>
<ProcessId>12664</ProcessId>
<ParentProcessId>11456</ParentProcessId>
<ParentProcessIndex>118</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795778472532085</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>WinPcap_4_1_3.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\WinPcap_4_1_3.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\WinPcap_4_1_3.exe&quot;</CommandLine>
<CompanyName>Riverbed Technology, Inc.</CompanyName>
<Version>4.1.0.2980</Version>
<Description>WinPcap 4.1.3 installer</Description>
<modulelist>
<module>
<Timestamp>131795778474370909</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Wireshark\WinPcap_4_1_3.exe</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>WinPcap 4.1.3 installer</Description>
</module>
<module>
<Timestamp>131795778474385662</Timestamp>
<BaseAddress>0x450000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778481441454</Timestamp>
<BaseAddress>0x10000000</BaseAddress>
<Size>36864</Size>
<Path>C:\Users\User\AppData\Local\Temp\nsy6E15.tmp\InstallOptions.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795778474378741</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795778474379428</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795778474388380</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795778478947902</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795778475429642</Timestamp>
<BaseAddress>0x66680000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778475455924</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778476129447</Timestamp>
<BaseAddress>0x68890000</BaseAddress>
<Size>2506752</Size>
<Path>C:\Windows\AppPatch\AcGenral.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795778474677141</Timestamp>
<BaseAddress>0x6b830000</BaseAddress>
<Size>2584576</Size>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795778480464294</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\riched20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795778477256204</Timestamp>
<BaseAddress>0x6e070000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\msacm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795778475437968</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795778476670529</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795778480530862</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795778478980362</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795778478991569</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795778480522492</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795778478967471</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795778479094944</Timestamp>
<BaseAddress>0x72510000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\shfolder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Folder Service</Description>
</module>
<module>
<Timestamp>131795778477334993</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795778479412597</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778477303386</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778477311770</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795778476643968</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795778475447551</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778477321345</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795778476661893</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795778478915573</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795778477286525</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795778477294825</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795778475176915</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795778474424278</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795778475146383</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795778475145740</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795778478799256</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795778475144147</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778475143114</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778475151896</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778475144928</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778475139437</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778478951681</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795778475135689</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778475152658</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778479395683</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778478952460</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778475149237</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778480549998</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795778474394583</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778475147716</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778475150048</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778475142341</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778475150968</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778475140388</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778475156318</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795778475137512</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778475153528</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778475136714</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778475147048</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778475155357</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778475154692</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778476634451</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795778475138620</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778481442448</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795778475141404</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778474371565</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795778474371291</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>129</ProcessIndex>
<ProcessId>4536</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778749072780</CreateTime>
<FinishTime>131795779059347952</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>360TsLiveUpd.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\360TsLiveUpd.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\360TsLiveUpd.exe&quot; /delay:30</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>9,6,0,1006</Version>
<Description>360 Update Module</Description>
<modulelist>
<module>
<Timestamp>131795778754806493</Timestamp>
<BaseAddress>0x960000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778749089644</Timestamp>
<BaseAddress>0xaf0000</BaseAddress>
<Size>1773568</Size>
<Path>C:\Program Files (x86)\360\Total Security\360TsLiveUpd.exe</Path>
<Version>9,6,0,1006</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Update Module</Description>
</module>
<module>
<Timestamp>131795778754806923</Timestamp>
<BaseAddress>0xcb0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778754799495</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795778754800515</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795778754814885</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795778757370572</Timestamp>
<BaseAddress>0x5c480000</BaseAddress>
<Size>245760</Size>
<Path>C:\Program Files (x86)\360\Total Security\PDown.dll</Path>
<Version>1, 3, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Security Center Network Module </Description>
</module>
<module>
<Timestamp>131795778756606776</Timestamp>
<BaseAddress>0x62210000</BaseAddress>
<Size>446464</Size>
<Path>C:\Program Files (x86)\360\Total Security\360TSCommon.dll</Path>
<Version>9, 0, 0, 1016</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795778756675674</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795778771269230</Timestamp>
<BaseAddress>0x62530000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\devrtl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795778756191261</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795778758783666</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795778760284069</Timestamp>
<BaseAddress>0x686c0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Program Files (x86)\360\Total Security\360P2SP.dll</Path>
<Version>1, 3, 0, 1490</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Security Center Network Module </Description>
</module>
<module>
<Timestamp>131795778759580194</Timestamp>
<BaseAddress>0x687e0000</BaseAddress>
<Size>671744</Size>
<Path>C:\Windows\SysWOW64\rasapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795778756645104</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795778759221046</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>450560</Size>
<Path>C:\Program Files (x86)\360\Total Security\LiveUpd360.dll</Path>
<Version>1, 3, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Security Center Network Module </Description>
</module>
<module>
<Timestamp>131795778771241478</Timestamp>
<BaseAddress>0x6ceb0000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795778759558966</Timestamp>
<BaseAddress>0x6cee0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files (x86)\360\Total Security\360net.dll</Path>
<Version>1, 2, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Security Center Network Module</Description>
</module>
<module>
<Timestamp>131795778759591359</Timestamp>
<BaseAddress>0x6d000000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795778757259323</Timestamp>
<BaseAddress>0x6d020000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files (x86)\360\Total Security\Safelive.dll</Path>
<Version>3, 0, 0, 3090</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Security Center Network Module</Description>
</module>
<module>
<Timestamp>131795778754915374</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795778757076225</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.dll</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795778757053689</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795778760819219</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795778760808345</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795778760831928</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795778760719360</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\NapiNSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795778757042532</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795778754954034</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795778759176302</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795778760037733</Timestamp>
<BaseAddress>0x72500000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795778754965083</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795778760703814</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778754885272</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795778760157762</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795778760844304</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795778759033319</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795778759195405</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795778758811901</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795778754896160</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795778756496605</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795778758800201</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795778758995875</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795778755444210</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795778757065417</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778754936829</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795778754926035</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795778754906982</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795778754839724</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795778754839061</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795778754984308</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795778754844921</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778754844209</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778754848553</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778754838261</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778754834307</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778754836789</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778754849287</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778754858137</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778757264416</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778754845880</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778757525679</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795778754858868</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795778754821950</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778754837590</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778754859660</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778754836061</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778754843447</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778754847622</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778754841594</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778757263313</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795778754832290</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778754850160</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778754830966</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778754840388</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778754852723</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778754852075</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778754851111</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795778754833517</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778754842516</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778758801140</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795778749090198</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795778749089932</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>130</ProcessIndex>
<ProcessId>576</ProcessId>
<ParentProcessId>904</ParentProcessId>
<ParentProcessIndex>22</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778801446311</CreateTime>
<FinishTime>131795778914376890</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>compattelrunner.exe</ProcessName>
<ImagePath>C:\Windows\system32\compattelrunner.exe</ImagePath>
<CommandLine>C:\Windows\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Description>Microsoft Compatibility Telemetry</Description>
<modulelist>
<module>
<Timestamp>131795778801697096</Timestamp>
<BaseAddress>0x7ff70d700000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\CompatTelRunner.exe</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Compatibility Telemetry</Description>
</module>
<module>
<Timestamp>131795778818066285</Timestamp>
<BaseAddress>0x7ffaafa00000</BaseAddress>
<Size>2240512</Size>
<Path>C:\Windows\System32\OpcServices.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Native Code OPC Services Library</Description>
</module>
<module>
<Timestamp>131795778817591965</Timestamp>
<BaseAddress>0x7ffababa0000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\System32\AppxPackaging.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пакетов машинного кода Appx</Description>
</module>
<module>
<Timestamp>131795778804489710</Timestamp>
<BaseAddress>0x7ffabc160000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\System32\aeinv.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Inventory Component</Description>
</module>
<module>
<Timestamp>131795778805836272</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795778814205456</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795778822547539</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795778804504849</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795778817977946</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795778804546449</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795778804520752</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795778832909471</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795778906843983</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795778832655807</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795778804404344</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795778815078784</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778828219669</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795778814441201</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795778804580321</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795778907262709</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795778907252028</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795778907278739</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795778804414262</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778804494514</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778804493744</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778804495988</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778827105014</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795778804382980</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778804377788</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778804379461</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778804384595</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778804495204</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778804492916</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778801923662</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778827104008</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778804386163</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778804491943</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778804490783</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778804385435</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778906861800</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795778804378536</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778804375031</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778805812639</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778801922778</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778804382152</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778804383814</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778804377045</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778804387986</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778804376248</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795778804387078</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778804380589</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778801697420</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>131</ProcessIndex>
<ProcessId>5796</ProcessId>
<ParentProcessId>576</ParentProcessId>
<ParentProcessIndex>130</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778802922396</CreateTime>
<FinishTime>131795778914424489</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>Conhost.exe</ProcessName>
<ImagePath>C:\Windows\System32\Conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795778802973283</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795778803854304</Timestamp>
<BaseAddress>0x7ffabe520000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795778803885132</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778804265910</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778804263214</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778804266691</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778803866949</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778803863023</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778803864758</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778803868855</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778803886850</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778804262100</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778803830045</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778803871230</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778804260987</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778804259635</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778803870515</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778803863810</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778803838246</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778803829142</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778803866104</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778803869659</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795778803868080</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778803862004</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778804264068</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778804265029</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778803886000</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778802973543</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>132</ProcessIndex>
<ProcessId>5748</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778806993759</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k wsappx</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795778807042136</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795778809771371</Timestamp>
<BaseAddress>0x7ffaafc30000</BaseAddress>
<Size>2297856</Size>
<Path>C:\Windows\System32\AppXDeploymentServer.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера развертывания AppX</Description>
</module>
<module>
<Timestamp>131795778810217417</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795778809793544</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fltLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795778809909001</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795778810725123</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795778810201985</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795778809816672</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795778809822524</Timestamp>
<BaseAddress>0x7ffacb720000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\mintdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795778809799027</Timestamp>
<BaseAddress>0x7ffacb820000</BaseAddress>
<Size>712704</Size>
<Path>C:\Windows\System32\tdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795778810317823</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795778809809854</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795778810208064</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778809594468</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778809776574</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778809778372</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795778809607454</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778809572087</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778809580973</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778809605642</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778810318817</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778809772360</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778809561432</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778809777533</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778809774521</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778809773756</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778809570735</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778809595255</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778810493271</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778809560537</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778809606459</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778809600563</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778809580022</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778809775513</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778809569904</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778807042435</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>1</ProcessIndex>
<ProcessId>11372</ProcessId>
<ParentProcessId>10560</ParentProcessId>
<ParentProcessIndex>2</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770632346846</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon64.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Temp\Procmon64.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Temp\Procmon64.exe&quot;  /originalpath &quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot;</CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>2</ProcessIndex>
<ProcessId>10560</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770594566098</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon.exe</ProcessName>
<ImagePath>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot; </CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x1000000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x62530000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\RICHED20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cd0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72520000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\Riched32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wrapper Dll for Richedit 1.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>3</ProcessIndex>
<ProcessId>4048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765778109600457</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchIndexer.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchIndexer.exe</ImagePath>
<CommandLine>C:\Windows\system32\SearchIndexer.exe /Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Индексатор службы Microsoft Windows Search</Description>
<modulelist>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ff63db40000</BaseAddress>
<Size>929792</Size>
<Path>C:\Windows\system32\SearchIndexer.exe</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индексатор службы Microsoft Windows Search</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\MSSRCH.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabd990000</BaseAddress>
<Size>720896</Size>
<Path>C:\Windows\system32\ElsLad.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ELS Language Detection</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\Msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>4</ProcessIndex>
<ProcessId>580</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776275984299</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>services.exe</ProcessName>
<ImagePath>C:\Windows\system32\services.exe</ImagePath>
<CommandLine>C:\Windows\system32\services.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Приложение служб и контроллеров</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>6</ProcessIndex>
<ProcessId>664</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776282506625</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k DcomLaunch</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc6a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\SebBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; SEB Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc7e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\SmartCardBackgroundPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartCardBackgroundPolicy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8c0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\CbtBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; CBT Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8d0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\ACPBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; ACP Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc900000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BackgroundMediaPolicy.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Background Media Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\RmClient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca740000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\DAB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL брокера активности компьютера</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacabd0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\OnDemandBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OnDemandBrokerClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacae70000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\systemeventsbrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер системных событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacafc0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy RM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb010000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SYSTEM32\psmserviceexthost.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager PSM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb390000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\psmsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process State Manager (PSM) Service</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb4f0000</BaseAddress>
<Size>794624</Size>
<Path>c:\windows\system32\bisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба инфраструктуры фоновых задач</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb720000</BaseAddress>
<Size>344064</Size>
<Path>c:\windows\system32\mintdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>c:\windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb820000</BaseAddress>
<Size>712704</Size>
<Path>C:\Windows\SYSTEM32\tdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8d0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\umpoext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения службы пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8f0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\umpo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb940000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\umpnpmgr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский режим службы самонастройки (Plug-and-Play)</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>7</ProcessIndex>
<ProcessId>884</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776292813936</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9230000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\bluetoothapis.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Usermode Api host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9580000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\BthRadioMedia.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab95a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WlanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wlan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaba920000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\rmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Radio Manager API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabae80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\NfcRadioMedia.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NFC Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabb8a0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\XboxGipRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Xbox GIP Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc0e0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\WwanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wwan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac78c0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\shacct.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Classes</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7f80000</BaseAddress>
<Size>208896</Size>
<Path>c:\windows\system32\wscsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8490000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\dhcpcore6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8c90000</BaseAddress>
<Size>385024</Size>
<Path>c:\windows\system32\dhcpcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>c:\windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac9c30000</BaseAddress>
<Size>1732608</Size>
<Path>c:\windows\system32\wevtsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба протоколирования событий</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca2a0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\timebrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер событий времени</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca330000</BaseAddress>
<Size>36864</Size>
<Path>c:\windows\system32\nrpsrv.DLL</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Name Resolution Proxy (NRP) RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4d0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lmhsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб транспорта TCPIP NetBios</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>8</ProcessIndex>
<ProcessId>0</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:00000000</AuthenticationId>
<CreateTime>131765775874898587</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>4294967295</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity></Integrity>
<Owner></Owner>
<ProcessName>Idle</ProcessName>
<ImagePath>Idle</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>9</ProcessIndex>
<ProcessId>4</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775907178738</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>System</ProcessName>
<ImagePath>System</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b6e00000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\System32\win32kfull.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Win32k Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7190000</BaseAddress>
<Size>1576960</Size>
<Path>C:\Windows\System32\win32kbase.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Базовый драйвер ядра Win32k</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7320000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\TSDDD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Framebuffer Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7330000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\cdd.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Canonical Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b74a0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\win32k.sys</Path>
<Version>10.0.14393.594 (rs1_release_inmarket.161213-1754)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Multi-User Win32 Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80278934000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\kd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Kernel Debugger</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80279678000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92e00000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\ksecdd.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ee0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\cmimcext.sys</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Configuration Manager Initial Configuration Extension Host Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ef0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\ntosext.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTOS extension host driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92fa0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\drivers\cng.sys</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Cryptography, Next Generation</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93040000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\system32\drivers\Wdf01000.sys</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения платформы драйвера режима ядра</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93120000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\drivers\WDFLDR.SYS</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Mode Driver Framework Loader</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93140000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\Drivers\acpiex.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPIEx Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93170000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\Drivers\WppRecorder.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WPP Trace Recorder</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93180000</BaseAddress>
<Size>733184</Size>
<Path>C:\Windows\System32\drivers\ACPI.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPI драйвер для NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93240000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\WMILIB.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMILIB WMI support library Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93260000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\intelpep.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Power Engine Plugin</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93280000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\drivers\WindowsTrustedRT.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932a0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Service Proxy Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\pcw.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Performance Counters for Windows Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932d0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\msisadrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ISA Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932e0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\isapnp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер шины PNP ISA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932f0000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\drivers\pci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Plug and Play PCI-перечислитель</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93350000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\vdrvroot.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Drive Root Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93370000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\drivers\pdc.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Power Dependency Coordinator Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933a0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\CEA.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation Kernel Mode Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\partmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Partition driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\nvraid.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) RAID Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93420000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\CLASSPNP.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI Class System Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93490000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\vmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Дочерний драйвер шины виртуальной машины Microsoft Hyper-V</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d934c0000</BaseAddress>
<Size>1212416</Size>
<Path>C:\Windows\System32\drivers\NDIS.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS (Network Driver Interface Specification)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d935f0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\drivers\NETIO.SYS</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network I/O Subsystem</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93670000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\hvsocket.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Hyper-V Socket Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\vmbkmcl.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V VMBus KMCL</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\winhv.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Hypervisor Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\pciide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Generic PCI IDE Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936e0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\PCIIDEX.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PCI IDE Bus Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93700000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\drivers\spaceport.sys</Path>
<Version>10.0.14393.1914 (rs1_release_inmarket.171117-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Spaces Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937a0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\intelide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel PCI IDE Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937b0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\volmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937d0000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\drivers\volmgrx.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер расширения диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93830000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\drivers\mountmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер точек подключения</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93850000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\nvstor.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) Sata Performance Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\drivers\storport.sys</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Storage Port Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93910000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\atapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI IDE Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93920000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\System32\drivers\ataport.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93960000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\storahci.sys</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS AHCI Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93990000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\stornvme.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft NVM Express Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\drivers\EhStorClass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enhanced Storage Class driver for IEEE 1667 devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\fileinfo.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FileInfo Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939f0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\Drivers\Wof.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр оверлея Windows</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93a80000</BaseAddress>
<Size>2297856</Size>
<Path>C:\Windows\System32\Drivers\NTFS.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер файловой системы NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\storvsc.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage VSC Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cd0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\Drivers\Fs_Rec.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>File System Recognizer Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93d10000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\System32\drivers\USBPORT.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта USB 1.1 и 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93db0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\mcupdate_GenuineIntel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Microcode Update Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93e50000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\System32\drivers\CLFS.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Common Log File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ec0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\tm.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Transaction Manager Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ef0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\PSHED.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер аппаратных ошибок, специфичных для платформы</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f10000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\BOOTVID.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>VGA Boot Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f20000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\FLTMGR.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер фильтров файловых систем Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\drivers\msrpc.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Remote Procedure Call Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94000000</BaseAddress>
<Size>430080</Size>
<Path>C:\Windows\System32\drivers\fwpkclnt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FWP/IPsec Kernel-Mode API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94070000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\wfplwfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WFP NDIS 6.30 Lightweight Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d940b0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DRIVERS\fvevol.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BitLocker Drive Encryption Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94160000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\volume.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94170000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\System32\drivers\volsnap.sys</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume Shadow Copy driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d941e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\scmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Class Memory Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\drivers\rdyboost.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ReadyBoost Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94250000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\Drivers\mup.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер поставщика множественных UNC</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94280000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\drivers\iorate.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>I/O rate control Filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942a0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\disk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PnP Disk Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942e0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\crashdmp.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crash Dump Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d943c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\drivers\cdrom.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI CD-ROM Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94400000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\drivers\filecrypt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows sandboxing and encryption filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94420000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\tbs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Export driver for kernel mode TPM API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94430000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Null.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NULL Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94440000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Beep.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BEEP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94450000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\BasicDisplay.sys</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94470000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\watchdog.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Watchdog Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94490000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\System32\drivers\dxgkrnl.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Kernel</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\BasicRender.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Render Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\Npfs.SYS</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPFS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94700000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\DRIVERS\tdx.sys</Path>
<Version>10.0.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDI Translation Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94740000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\DRIVERS\netbt.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>MBT Transport driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94790000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\drivers\afd.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер дополнительных функций для Winsock</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94830000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\vwififlt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual WiFi Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94850000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\pacer.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Планировщик пакетов QoS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\drivers\netbios.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetBIOS interface driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d948a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\rdbss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер подсистемы буферизации перенаправленного диска</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94920000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\drivers\csc.sys</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Client Side Caching Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\nsiproxy.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\npsvctrig.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Named pipe service triggers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\gpuenergydrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GPU Energy Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a00000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Drivers\dfsc.sys</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DFS Namespace Client Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a50000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\DRIVERS\ahcache.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Compatibility Cache</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a90000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-Transport Composite Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\kdnic.sys</Path>
<Version>6.01.00.0000 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Kernel Debugger Network Miniport</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ac0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\drivers\umbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User-Mode Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ae0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\i8042prt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта i8042</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b10000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\drivers\kbdclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса клавиатуры</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b30000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\mouclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса мыши</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b80000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\HDAudBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ba0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\drivers\portcls.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Port Class (Class Driver for Port/Miniport Devices)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c10000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\drmk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trusted Audio Drivers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c40000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\drivers\ks.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel CSA Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cb0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\usbohci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OHCI USB Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\CmBatt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Control Method Battery Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cd0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\BATTC.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Class Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ce0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\intelppm.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Processor Device Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d10000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\NdisVirtualBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечислитель виртуальных сетевых адаптеров (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d20000</BaseAddress>
<Size>2588672</Size>
<Path>C:\Windows\System32\drivers\tcpip.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fa0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\swenum.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Plug and Play Software Device Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fb0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\rdpbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft RDP Bus Device driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95200000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\DRIVERS\udfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UDF File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95280000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\Drivers\dump_diskdump.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d952c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\Drivers\dump_storahci.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95310000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\Drivers\dump_dumpfve.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95330000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\system32\drivers\HTTP.sys</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Стек протокола HTTP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95450000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\drivers\WudfPf.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - User-mode Driver Framework Platform Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95470000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\DRIVERS\bowser.sys</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Lan Manager Datagram Receiver Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d954a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT SMB Minirdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95520000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\mpsdrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Protection Service Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95540000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb20.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB 2.0 Redirector</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95580000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\DRIVERS\srvnet.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Network driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d955d0000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\System32\DRIVERS\srv2.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер сервера SMB 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95690000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb10.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB Downlevel SubRdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d956e0000</BaseAddress>
<Size>573440</Size>
<Path>C:\Windows\System32\DRIVERS\srv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95770000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\tcpipreg.sys</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>TCP/IP Registry Compatibility Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95860000</BaseAddress>
<Size>684032</Size>
<Path>C:\Windows\System32\drivers\dxgmms2.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics MMS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95910000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\luafv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра виртуализации файлов LUA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95960000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\storqosflt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр качества обслуживания хранилища</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95980000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\registry.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Registry Containment Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959a0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\drivers\lltdio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Mapper I/O Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959c0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\drivers\mslldp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер протокола Microsoft LLDP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\rspndr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Responder Driver for NDIS 6</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95ae0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\USBD.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Universal Serial Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95af0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\DRIVERS\HdAudio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Function Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95b60000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\ksthunk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Streaming WOW Thunk Service</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95bc0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\HIDPARSE.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hid Parsing Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97020000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\Drivers\360AntiHacker64.sys</Path>
<Version>1.0.0.1149</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络防黑模块</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97060000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\DRIVERS\360AvFlt.sys</Path>
<Version>1.1.0.1056</Version>
<Company>360.cn</Company>
<Description>360杀毒 文件监控驱动</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97080000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\DRIVERS\BAPIDRV64.sys</Path>
<Version>2.0.0.1221</Version>
<Company>360.cn</Company>
<Description>BAPIDRV</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d970c0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\drivers\360netmon.sys</Path>
<Version>2.1.11.5195</Version>
<Company>360.cn</Company>
<Description>360netmon</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97120000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\system32\DRIVERS\360Box64.sys</Path>
<Version>2.1.0.1253</Version>
<Company>360.cn</Company>
<Description>360Box64</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97180000</BaseAddress>
<Size>811008</Size>
<Path>C:\Windows\system32\DRIVERS\360FsFlt.sys</Path>
<Version>6.9.1.1751</Version>
<Company>360.cn</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97330000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\hidusb.sys</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>USB Miniport Driver for Input Devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97350000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\HIDCLASS.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека классов HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97380000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\mouhid.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра мыши HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97390000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\rassstp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS SSTP Miniport Call Manager</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973b0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\DRIVERS\NDProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\drivers\AgileVpn.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер вызовов минипорта RAS Agile VPN</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97420000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\drivers\rasl2tp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS L2TP mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97460000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\raspptp.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Peer-to-Peer Tunneling Protocol</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974a0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\raspppoe.sys</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS PPPoE mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\DRIVERS\ndistapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS 3.0 connection wrapper driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974d0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\drivers\ndiswan.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS PPP Framing Driver (Strong Encryption)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97510000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\DRIVERS\wanarp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS Remote Access and Routing ARP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97550000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\E1G6032E.sys</Path>
<Version>8.4.13.0 built by: WinDDK</Version>
<Company>Intel Corporation</Company>
<Description>Intel(R) PRO/1000 Adapter NDIS 6 deserialized driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97580000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\tunnel.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер интерфейса туннеля (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97600000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\Drivers\PROCMON24.SYS</Path>
<Version>3.10</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor Driver</Description>
</module>
<module>
<Timestamp>131795780236159256</Timestamp>
<BaseAddress>0xfffff80d97620000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\npf.sys</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>npf.sys (NT5/6 AMD64) Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97a60000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\system32\drivers\peauth.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Protected Environment Authentication and Authorization Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b30000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\Ndu.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Network Data Usage Monitoring Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b60000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\drivers\mmcss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMCSS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97bb0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\condrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Driver</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>10</ProcessIndex>
<ProcessId>320</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775908989732</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>smss.exe</ProcessName>
<ImagePath>C:\Windows\System32\smss.exe</ImagePath>
<CommandLine>\SystemRoot\System32\smss.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер сеанса  Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>11</ProcessIndex>
<ProcessId>3108</ProcessId>
<ParentProcessId>3092</ParentProcessId>
<ParentProcessIndex>12</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777624392598</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Explorer.EXE</ProcessName>
<ImagePath>C:\Windows\Explorer.EXE</ImagePath>
<CommandLine>C:\Windows\Explorer.EXE</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x31b0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5db0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Program Files\Uninstall Tool\utshellext.dll</Path>
<Version>1.1.0.15</Version>
<Company>CrystalIDEA Software</Company>
<Description>Uninstall Tool Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x81a0000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\MICROS~1\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x8cb0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5bf70000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_08e394a1a83e212f\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\Notepad++\NppShell_06.dll</Path>
<Version>0.1</Version>
<Company></Company>
<Description>ShellHandler for Notepad++ (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\Explorer.EXE</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2093056</Size>
<Path>C:\Windows\system32\wpdshext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки для переносных устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab350000</BaseAddress>
<Size>1683456</Size>
<Path>C:\Windows\System32\comsvcs.dll</Path>
<Version>2001.12.10941.16384 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Services</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab4f0000</BaseAddress>
<Size>1400832</Size>
<Path>C:\Windows\system32\connect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Мастера подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab650000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\system32\rasgcw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Страницы мастера RAS</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\System32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\system32\ieframe.DLL</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0df0000</BaseAddress>
<Size>1626112</Size>
<Path>C:\Windows\SYSTEM32\d3d9.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 9 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0f80000</BaseAddress>
<Size>1777664</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoViewer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Просмотр фотографий Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab27c0000</BaseAddress>
<Size>516096</Size>
<Path>C:\Windows\System32\imapi2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>IMAPI версии 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2840000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\bthprops.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложение панели управления Bluetooth</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2880000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\cscobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Внутрипроцессный COM-объект используемый клиентами CSC API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab29a0000</BaseAddress>
<Size>1912832</Size>
<Path>C:\Windows\System32\pnidui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Значок сетевой системы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2b80000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\system32\SettingMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Change Monitor</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2bc0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\PortableDeviceTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device (Parameter) Types Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab34f0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\System32\Actioncenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5120000</BaseAddress>
<Size>1691648</Size>
<Path>C:\Windows\system32\BatMeter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Meter Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\MsftEdit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7e40000</BaseAddress>
<Size>3420160</Size>
<Path>C:\Windows\System32\SyncCenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр синхронизации Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\system32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\system32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab99b0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\dxp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки компонента Device Stage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9ba0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\SYSTEM32\searchfolder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SearchFolder</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabac60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\EhStorAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Enhanced Storage API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae20000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msiltcfg.dll</Path>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer Configuration API Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaea0000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\system32\SHDOCVW.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\SYSTEM32\settingsynccore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SYSTEM32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SYSTEM32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd3c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\InputSwitch.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переключатель ввода Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd670000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\framedynos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI SDK Provider Framework</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd6c0000</BaseAddress>
<Size>1306624</Size>
<Path>C:\Windows\System32\werconcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PRS CPL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd800000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\NPSMDesktopProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Библиотека DLL локального поставщика рабочего стола NPSM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabda60000</BaseAddress>
<Size>1241088</Size>
<Path>C:\Windows\System32\wscui.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdeb0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\wpdshserviceobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device Shell Service Object</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabded0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\stobject.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Объект службы оболочки Systray</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe470000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\wscinterop.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Health Center WSC Interop</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe580000</BaseAddress>
<Size>831488</Size>
<Path>C:\Program Files (x86)\360\Total Security\MenuEx64.dll</Path>
<Version>9, 6, 0, 1001</Version>
<Company></Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe650000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\system32\zipfldr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сжатые ZIP-папки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9a0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\Syncreg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Synchronization Framework Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\system32\NetworkExplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0b0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\playtomenu.dll</Path>
<Version>12.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека меню функции &quot;Передать на устройство&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\System32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf590000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\syncui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Портфель Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfba0000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\WSCAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\MICROS~1\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b40000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\dlnashext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLNA Namespace DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\srchadmin.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры индексирования</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0f60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SYSTEM32\CHARTV.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Chart View</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1cc0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.Sockets.PushEnabledApplication DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac27a0000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.111.0603.0006\amd64\FileSyncShell64.dll</Path>
<Version>18.111.0603.0006</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac32e0000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\twext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Свойства: Предыдущие версии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3350000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\OLEACCHOOKS.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Event Hooks Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\dsreg.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5140000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\AboveLockAppHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AboveLockAppHost</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5190000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\NotificationController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5570000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\system32\twinui.pcshell.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Twinui.PCShell</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac55d0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\windows.immersiveshell.serviceprovider.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.ImmersiveShell.ServiceProvider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\system32\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5c70000</BaseAddress>
<Size>65536</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoBase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Base Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6650000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\npsm.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPSM</Description>
</module>
<module>
<Timestamp>131795780903771340</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac78f0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\hgcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Панель управления домашней группы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d40000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\SYNCENG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Briefcase Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d90000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\SYSTEM32\SndVolSSO.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Громкость SCA </Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7f50000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\acppage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека расширений для вкладки &quot;Совместимость&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\SYSTEM32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795778062352400</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\ploptin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Prelaunch OptIn</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ea0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\hcproviders.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщики компонента &quot;Центр безопасности и обслуживания&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca190000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\WorkFoldersShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки рабочих папок (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795780604813666</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac80000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SYSTEM32\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>13</ProcessIndex>
<ProcessId>404</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776186257169</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>15</ProcessIndex>
<ProcessId>468</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776223665667</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>17</ProcessIndex>
<ProcessId>484</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226419105</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>wininit.exe</ProcessName>
<ImagePath>C:\Windows\system32\wininit.exe</ImagePath>
<CommandLine>wininit.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Автозагрузка приложений Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>18</ProcessIndex>
<ProcessId>520</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226825613</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>winlogon.exe</ProcessName>
<ImagePath>C:\Windows\system32\winlogon.exe</ImagePath>
<CommandLine>winlogon.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Программа входа в систему Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ff7b5570000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\winlogon.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа входа в систему Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaee0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\dwminit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMInit</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacafa0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\UXINIT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows User Experience Session Initialization Dll</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>19</ProcessIndex>
<ProcessId>588</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776277547408</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>lsass.exe</ProcessName>
<ImagePath>C:\Windows\system32\lsass.exe</ImagePath>
<CommandLine>C:\Windows\system32\lsass.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Description>Local Security Authority Process</Description>
<modulelist>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x222e3610000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\msprivs.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переводы привилегий Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ff6b2d20000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\lsass.exe</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Security Authority Process</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffab9170000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\vaultsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба диспетчера учетных данных</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf170000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\hmkd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows HMAC Key Derivation API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf190000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\ngcpopkeysrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Passport Proof-of-possession Key Service</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\keyiso.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба изоляции ключей CNG</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SYSTEM32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf270000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SecureTimeAggregator.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Secure Time Aggregator</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb9b0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\scecli.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент редактора конфигураций безопасности</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\SspiSrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA SSPI RPC interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\dpapisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DPAPI Server</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbad0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\efslsaext.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA extension for EFS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbb70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wdigest.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Digest Access</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc00000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\MicrosoftAccountCloudAP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MicrosoftAccount Cloud AP Plugin</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc50000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\cloudAP.DLL</Path>
<Version>10.0.14393.1358 (rs1_release.170602-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cloud AP Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbcb0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\system32\pku2u.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pku2u Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd00000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\tspkg.DLL</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Web Service Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe30000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\gmsaclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;gmsaclient.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe60000</BaseAddress>
<Size>843776</Size>
<Path>C:\Windows\system32\netlogon.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека службы Net Logon</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc030000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\KerbClientShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kerberos Client Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc180000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\negoexts.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NegoExtender Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\JOINUTIL.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\netprovfw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Provisioning Service Framework DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc260000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\SYSTEM32\samsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сервера диспетчера учетных записей</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc380000</BaseAddress>
<Size>1527808</Size>
<Path>C:\Windows\system32\lsasrv.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера LSA</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>20</ProcessIndex>
<ProcessId>704</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776284978539</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k RPCSS</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8250000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\wshhyperv.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V Winsock2 Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6a0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\RpcRtRemote.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote RPC Extension</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\rpcepmap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сопоставитель конечных точек RPC
</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>21</ProcessIndex>
<ProcessId>808</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0000c8d4</AuthenticationId>
<CreateTime>131765776288401882</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>Window Manager\DWM-1</Owner>
<ProcessName>dwm.exe</ProcessName>
<ImagePath>C:\Windows\system32\dwm.exe</ImagePath>
<CommandLine>&quot;dwm.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер окон рабочего стола</Description>
<modulelist>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ff683990000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\dwm.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\system32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7b70000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\System32\Windows.Gaming.Input.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Gaming Input API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\avrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9a30000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SYSTEM32\ism32k.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca110000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\dwmghost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMGhost</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca8d0000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\system32\dwmcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека ядра Microsoft DWM</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacac90000</BaseAddress>
<Size>856064</Size>
<Path>C:\Windows\SYSTEM32\udwm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\dwmredir.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компонент перенаправления диспетчера окон рабочего стола Microsoft</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>22</ProcessIndex>
<ProcessId>904</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776293087855</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x259b0640000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\SFC.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab830000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\netman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>c:\windows\system32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>c:\windows\system32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab1260000</BaseAddress>
<Size>10350592</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll</Path>
<Version>4.7.2117.0 built by: NET47REL1LAST</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Common Language Runtime - WorkStation</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>c:\windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795778252487651</Timestamp>
<BaseAddress>0x7ffabc160000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\System32\aeinv.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Inventory Component</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778007496118</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabfa00000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\SYSTEM32\MSVCR120_CLR0400.dll</Path>
<Version>12.00.52519.0 built by: VSWINSERVICING</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\MSI.DLL</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0fc0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\spp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих точек защиты Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1010000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\system32\MSCOREE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac10f0000</BaseAddress>
<Size>421888</Size>
<Path>c:\windows\system32\storsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы хранения</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1240000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll</Path>
<Version>4.7.2623.0 built by: NET471REL1LAST_C</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2420000</BaseAddress>
<Size>466944</Size>
<Path>c:\windows\system32\das.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сопоставления устройств</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795778007645121</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac41c0000</BaseAddress>
<Size>139264</Size>
<Path>c:\windows\system32\trkwks.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент отслеживания изменившихся связей</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4650000</BaseAddress>
<Size>516096</Size>
<Path>c:\windows\system32\pcasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба помощника по совместимости программ</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Assembly manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b50000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\dssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы NT для службы совместного доступа к данным</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6120000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\sysmain.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост службы Superfetch</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b10000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\SYSTEM32\WUDFPlatform.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - библиотека платформ пользовательского режима</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b50000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\wudfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation (WDF) - служба среды выполнения платформы драйвера режима пользователя</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9800000</BaseAddress>
<Size>376832</Size>
<Path>c:\windows\system32\audioendpointbuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство построения конечных точек Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9de0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\portabledeviceconnectapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Portable Device Connection API Components</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SYSTEM32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca2d0000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\ncbservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Посредник подключений к сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>c:\windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca710000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\pcadm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Diagnostic Module</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\system32\SXS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>c:\windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>23</ProcessIndex>
<ProcessId>96</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776304995849</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2510000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\energyprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2580000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\ncuprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Connectivity Statistics Provider for System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2b90000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\nduprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик сетевой статистики для службы отслеживания использования ресурсов системы</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bb0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\appsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bd0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\eeprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy Estimator SRUM provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2c20000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\wfapigp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall GPO Helper dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2d70000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\wpnsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SRUM provider for WPN</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3310000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\srumsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3730000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\pnpts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PlugPlay Troubleshooter</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3bd0000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\ncdautosetup.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы автоматической настройки сетевых устройств</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac41f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\adhapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD harvest sites and subnets API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4500000</BaseAddress>
<Size>200704</Size>
<Path>c:\windows\system32\dps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба политики диагностики WDI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4cd0000</BaseAddress>
<Size>933888</Size>
<Path>c:\windows\system32\mpssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба защиты (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6740000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\dtsh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API состояния общего доступа и обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac74b0000</BaseAddress>
<Size>827392</Size>
<Path>c:\windows\system32\bfe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба базовой фильтрации</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\coremessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\system32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\CFGMGR32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>24</ProcessIndex>
<ProcessId>348</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776305446235</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k netsvcs</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaa0aa0000</BaseAddress>
<Size>2138112</Size>
<Path>c:\windows\system32\wlidsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба учетных записей Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0750000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\system32\rascustom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль настраиваемых протоколов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab07b0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\vpnike.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>VPNIKE Protocol Engine - Test dll</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab09b0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\system32\rasppp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access PPP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0a00000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\rastapi.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access TAPI Compliance Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab3440000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\rasmans.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер подключений удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4c50000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\eappprxy.dll</Path>
<Version>10.0.14393.187 (rs1_release_inmarket.160906-1818)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft EAPHost Peer Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab9a90000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\dmEnrollEngine.DLL</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enroll Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabc210000</BaseAddress>
<Size>2355200</Size>
<Path>c:\windows\system32\wuaueng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Агент Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabdf60000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\raschap.dll</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>Удаленные доступ через PPP CHAP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4a0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\appinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о приложении</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabed80000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\system32\wbem\wbemess.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee10000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee30000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\system32\wbem\wmiprvsd.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf090000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>c:\windows\system32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfda0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\wbem\ncprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Non-COM WMI Event Provision APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0000000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wbem\repdrvfs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Repository Driver</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\shacctprofile.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Profile Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1530000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SYSTEM32\dpx.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft(R) Delta Package Expander</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1900000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\appxapplicabilityblob.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Appx Applicability Blob DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1970000</BaseAddress>
<Size>1073152</Size>
<Path>c:\windows\system32\qmgr.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фоновая интеллектуальная служба передачи</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1c30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\DMProcessXMLFiltered.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmprocessxmlfiltered</Description>
</module>
<module>
<Timestamp>131795779661934902</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1cf0000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\SYSTEM32\wuuhext.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update Agent plugin for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1df0000</BaseAddress>
<Size>61440</Size>
<Path>c:\windows\system32\NCI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CoInstaller: NET</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e20000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f10000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\DMCmnUtils.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmcmnutils</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f50000</BaseAddress>
<Size>471040</Size>
<Path>C:\Windows\system32\wbem\esscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20f0000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\CLUSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API кластера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2210000</BaseAddress>
<Size>1351680</Size>
<Path>C:\Windows\system32\wbem\wbemcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инструментарий управления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2370000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\adhsvc.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD Harvest Sites and Subnets Service</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2390000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\httpprxm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager</Description>
</module>
<module>
<Timestamp>131795775850813653</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac24a0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\system32\RESUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служебной программы ресурсов кластера (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795780837071260</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2640000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\wmidcom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2670000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\miutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура управления</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac26f0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\sscoreext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Core DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2720000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SYSTEM32\WPTaskScheduler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WP Task Scheduler DLL</Description>
</module>
<module>
<Timestamp>131795780838238287</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2770000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\SSCORE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основная DLL-библиотека службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2940000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CSystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Classic System Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>c:\windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a40000</BaseAddress>
<Size>974848</Size>
<Path>c:\windows\system32\iphlpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Эта служба предоставляет автоматическое подключение IPv6 в сети IPv4.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c60000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\WDSCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Panther Engine Module</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\system32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3740000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3b40000</BaseAddress>
<Size>245760</Size>
<Path>c:\windows\system32\wbem\wmisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3fa0000</BaseAddress>
<Size>331776</Size>
<Path>c:\windows\system32\srvsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) ресурсов для службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4160000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\wpnservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба системы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4480000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\taskcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оснастка обратной совместимости диспетчера задач</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4540000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\ProximityServicePAL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service PAL</Description>
</module>
<module>
<Timestamp>131795775380234927</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4cc0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ProximityCommonPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Common PAL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4dc0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\ProximityCommon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Универсальная реализация близкого взаимодействия</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4ee0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\ProximityService.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service Implementation</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5ef0000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\System32\MbaeApiPublic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Mobile Broadband Account API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7700000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\CredentialMigrationHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Migration Handler</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\sqmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SQM Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d60000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\UpdatePolicy.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Policy Reader</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e90000</BaseAddress>
<Size>749568</Size>
<Path>c:\windows\system32\FVEAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows BitLocker Drive Encryption API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac82d0000</BaseAddress>
<Size>643072</Size>
<Path>c:\windows\system32\shsvcs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8590000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\LocationWinPalMisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Location Platform Abstraction Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac85c0000</BaseAddress>
<Size>1810432</Size>
<Path>c:\windows\system32\LocationFramework.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа географического положения Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8780000</BaseAddress>
<Size>274432</Size>
<Path>c:\windows\system32\UBPM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL единого диспетчера фоновых процессов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8b60000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\schedsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac91c0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\profsvcext.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvcExt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92a0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\sens.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба уведомления о системных событиях (SENS)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\themeservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы темы оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9420000</BaseAddress>
<Size>380928</Size>
<Path>c:\windows\system32\profsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvc</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9a70000</BaseAddress>
<Size>1257472</Size>
<Path>c:\windows\system32\gpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca700000</BaseAddress>
<Size>32768</Size>
<Path>c:\windows\system32\DABAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Desktop Activity Broker API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca720000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\bitsigd.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service IGD Support</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacab70000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба географического положения</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac40000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\seclogon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL службы вторичного входа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac50000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\bitsperf.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Perfmon Counter Access</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\MSWSOCK.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>25</ProcessIndex>
<ProcessId>372</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776305463443</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>c:\windows\system32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab91f0000</BaseAddress>
<Size>233472</Size>
<Path>c:\windows\system32\sstpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обеспечивает возможность использования SSTP для подключения к удаленным компьютерам с помощью VPN.</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795780812578370</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabc610000</BaseAddress>
<Size>540672</Size>
<Path>c:\windows\system32\w32time.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба времени Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabef00000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\cdpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба CDP Майкрософт (R)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05e0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\sbservicetrigger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Socket Broker Service Trigger</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795780812550384</Timestamp>
<BaseAddress>0x7ffac3290000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\fthsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль диагностики отказоустойчивой кучи Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4130000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\fdphost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба размещения поставщиков функций обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4200000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\perftrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Performance PerfTrack</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5b80000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\AuthBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API WinRT для веб-проверки подлинности</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66e0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\fdssdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery SSDP Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6960000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\fdwsd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery WS Discovery Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac76d0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\vmictimeprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Machine Integration Component Time Sync Provider Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7a10000</BaseAddress>
<Size>544768</Size>
<Path>c:\windows\system32\netprofmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер списка сетей</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7f70000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\licensemanagersvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManagerSvc</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90a0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\nsisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RPC-сервер интерфейса сохранения сети</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac91f0000</BaseAddress>
<Size>172032</Size>
<Path>c:\windows\system32\FontProvider.dll</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Font Provider Library</Description>
</module>
<module>
<Timestamp>131795780812573070</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9860000</BaseAddress>
<Size>1896448</Size>
<Path>c:\windows\system32\fntcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэша шрифтов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>c:\windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795780812567382</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>26</ProcessIndex>
<ProcessId>360</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311216195</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffabaad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\deviceaccess.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Broker And Policy COM Server</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac7e70000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\coreaudiopolicymanagerext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;coreaudiopolicymanagerext.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac87d0000</BaseAddress>
<Size>237568</Size>
<Path>c:\windows\system32\AUDIOSRVPOLICYMANAGER.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Audio Service Policy Manager</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac90d0000</BaseAddress>
<Size>978944</Size>
<Path>c:\windows\system32\audiosrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\POWRPROF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>27</ProcessIndex>
<ProcessId>1040</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311708649</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8820000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SYSTEM32\cmintegrator.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>cmintegrator.dll</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8c50000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wcmcsp.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Service Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8fe0000</BaseAddress>
<Size>737280</Size>
<Path>c:\windows\system32\wcmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы диспетчера подключений Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>28</ProcessIndex>
<ProcessId>1068</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776312395030</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\CRYPTNET.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\cryptcatsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Catalog Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65f0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\crypttpmeksvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic TPM Endorsement Key Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6680000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\cryptsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6f00000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\wkssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы рабочей станции</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79e0000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\netjoin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL присоединения к домену</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\WlanApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7c00000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\ssdpapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8260000</BaseAddress>
<Size>425984</Size>
<Path>c:\windows\system32\ncsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индикатор работоспособности сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8370000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\nlasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о подключенных сетях 2</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8410000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dnsext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DNS extension DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SYSTEM32\Fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8830000</BaseAddress>
<Size>290816</Size>
<Path>c:\windows\system32\dnsrslvr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэширующего сопоставителя DNS</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\JoinUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>29</ProcessIndex>
<ProcessId>1248</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776322176070</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>spoolsv.exe</ProcessName>
<ImagePath>C:\Windows\System32\spoolsv.exe</ImagePath>
<CommandLine>C:\Windows\System32\spoolsv.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер очереди печати</Description>
<modulelist>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ff639680000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\spoolsv.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер очереди печати</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffab8a60000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaba980000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\jscript.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabb7d0000</BaseAddress>
<Size>851968</Size>
<Path>C:\Windows\System32\win32spl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик печати с исполнением на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\prntvpt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Ticket Services Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd70000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_53d78f68bc1697cc\Amd64\PrintConfig.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc0c0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPFILEQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPFILEQ</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc590000</BaseAddress>
<Size>118784</Size>
<Path>C:\Program Files\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc5b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\amsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Anti-Malware Scan Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd040000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdPnp.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pnp Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd060000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\WSDMon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер порта принтера WSD</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd100000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\usbmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Standard Dynamic Printing Port Monitor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd160000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\wsnmp32.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft WinSNMP v2.0 Manager API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd2a0000</BaseAddress>
<Size>1159168</Size>
<Path>C:\Windows\System32\localspl.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека локального диспетчера очереди</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabde60000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\System32\tcpmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека монитора портов TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe3f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\spool\PRTPROCS\x64\winprint.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Print Processor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe6c0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\PrintIsolationProxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Sandbox COM Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe8a0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\snmpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SNMP Utility Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe980000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\SPOOLSS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Spooler SubSystem DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f00000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\FXSMON.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft  Fax Print Monitor</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac4e90000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\wshirda.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Sockets Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac7e00000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\inetpp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Internet Print Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>30</ProcessIndex>
<ProcessId>1512</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776336551242</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffabe9f0000</BaseAddress>
<Size>258048</Size>
<Path>c:\windows\system32\ssdpsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы SSDP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69b0000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\fdrespub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба публикации ресурсов обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>c:\windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>31</ProcessIndex>
<ProcessId>1556</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776339471770</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k utcsvc</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x272f9bf0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf140000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\CourtesyEngine.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Feedback Courtesy Engine DLL Server</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfde0000</BaseAddress>
<Size>143360</Size>
<Path>c:\windows\system32\CRYPTXML.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API-интерфейс XML DigSig</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\Netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\DSREG.DLL</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac5fd0000</BaseAddress>
<Size>1056768</Size>
<Path>c:\windows\system32\WindowsPerformanceRecorderControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Performance Recorder Control Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>c:\windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6210000</BaseAddress>
<Size>2007040</Size>
<Path>c:\windows\system32\diagtrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диагностическое отслеживание Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795775838362137</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795775839498740</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>32</ProcessIndex>
<ProcessId>1636</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776343009549</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k appmodel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>c:\windows\system32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3c10000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\tileobjserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер моделей данных плиток</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>c:\windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>c:\windows\system32\windows.staterepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795780599947775</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795780600943570</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>33</ProcessIndex>
<ProcessId>1744</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776348255325</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>MemCompression</ProcessName>
<ImagePath>MemCompression</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>34</ProcessIndex>
<ProcessId>2100</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776438403561</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffabff90000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\ipsecsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows IPsec SPD Server DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac1e00000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\FwRemoteSvr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall Remote APIs Server</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>35</ProcessIndex>
<ProcessId>2648</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777555980720</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>sihost.exe</ProcessName>
<ImagePath>C:\Windows\system32\sihost.exe</ImagePath>
<CommandLine>sihost.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Shell Infrastructure Host</Description>
<modulelist>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ff7bbae0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\sihost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Infrastructure Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb910000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\container.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Containers</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb970000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\daxexec.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>daxexec</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc450000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\system32\ShareHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShareHost</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc800000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\windowmanagement.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Window Management</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc850000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\AppointmentActivation.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL for AppointmentActivation</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc8b0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\NotificationPlatformComponent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationPlatformComponent</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc9a0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\activationmanager.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Activation Manager</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabca10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\ClipboardServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Modern Clipboard</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcde0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Windows\System32\modernexecserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Modern Execution</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcf10000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\desktopshellext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DesktopHost Extensions</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\system32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>36</ProcessIndex>
<ProcessId>840</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777563791648</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k UnistackSvcGroup</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf6a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\PhoneUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Phone utilities</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf700000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\System32\PIMSTORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>POOM</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab05d0000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\AccountAccessor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync data model to access accounts</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab0630000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\SyncController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SyncController for managing sync of mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb20000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\CEMAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CEMAPI</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcd80000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\cdpusersvc.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP User Components</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabd630000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\MCCSEngineShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Utilies shared among OneSync engines</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabdde0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\SYNCUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabed20000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\aphostservice.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>c:\windows\system32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4100000</BaseAddress>
<Size>151552</Size>
<Path>c:\windows\system32\NetworkHelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac97b0000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\InprocLogger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>In-proc Private Event Trace Logger</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca1d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\UserDataTypeHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Type Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca270000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\UserDataLanguageUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Language-related helper functions for user data</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca520000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\APHostClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service RPC Client </Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacabf0000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\MCCSPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform abstraction layer dll for MCCS</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacac20000</BaseAddress>
<Size>86016</Size>
<Path>c:\windows\system32\UserDataPlatformHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>37</ProcessIndex>
<ProcessId>528</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777565618284</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\system32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb440000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\system32\MTFServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;MTFServer.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb510000</BaseAddress>
<Size>2854912</Size>
<Path>C:\Windows\system32\InputService.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Text InputService Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8c0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\InputLocaleManager.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;InputLocaleManager.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8f0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\EditBufferTestHook.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;EditBufferTestHook.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb9f0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\system32\MSUTB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) сервера MSUTB</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabba70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\MsCtfMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MsCtfMonitor DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabbc20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\PlaySndSrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба PlaySound</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\system32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac7d10000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\KBDUS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>United States Keyboard Layout</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab10000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\WordBreakers.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;WordBreakers.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>38</ProcessIndex>
<ProcessId>3632</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777941176116</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>RuntimeBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\RuntimeBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\RuntimeBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Runtime Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7a45f0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\RuntimeBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Runtime Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\System32\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795780843802542</Timestamp>
<BaseAddress>0x7ffaad3f0000</BaseAddress>
<Size>1826816</Size>
<Path>C:\Windows\System32\Wpc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека параметров родительского контроля</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\mssrch.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795780489291214</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795780917042363</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795780917592192</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795780613006289</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795780733496994</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795780611542837</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795780918057976</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe880000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\FeClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT File Encryption Client Interfaces</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe8c0000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\system32\windows.cortana.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.Desktop</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780443980999</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf9c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\system32\windows.cortana.onecore.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.OneCore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795780634363506</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795779561161209</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780447369522</Timestamp>
<BaseAddress>0x7ffac37b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795771234179313</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795780489961900</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795780846908833</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5ca0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\AppExtension.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API AppExtension</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795780451650645</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795780641878393</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7d00000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SYSTEM32\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795780849625720</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780918548230</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\samlib.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795780611842861</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>39</ProcessIndex>
<ProcessId>3164</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778119045372</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ShellExperienceHost.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe&quot; -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Windows Shell Experience Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ff697570000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Experience Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f760000</BaseAddress>
<Size>3796992</Size>
<Path>C:\Windows\System32\MFMediaEngine.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Media Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaabad0000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\mfsrcsnk.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Source and Sink DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaafe70000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\System32\mfcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Core DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab0be0000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\ShellExperiences\NetworkUX.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab9eb0000</BaseAddress>
<Size>2899968</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.ActionCenter.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActionCenter Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaba180000</BaseAddress>
<Size>7880704</Size>
<Path>C:\Windows\ShellExperiences\StartUI.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Start UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SYSTEM32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd420000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\RTMediaFrame.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime MediaFrame DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe410000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\SYSTEM32\globcollationhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GlobCollationHost</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795780594734370</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0080000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\System32\resampledmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Resampler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0110000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\QuickActionsDataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>QuickActionsDataModel</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0160000</BaseAddress>
<Size>491520</Size>
<Path>C:\Windows\ShellExperiences\QuickActions.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac40f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4eb0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5b20000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\CompPkgSup.DLL</Path>
<Version>10.0.14393.969 (rs1_release_inmarket.170315-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Component Package Support DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5e90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\Windows.Media.MediaControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера MediaControl среды выполнения Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>40</ProcessIndex>
<ProcessId>4856</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778391112136</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MSASCuiL.exe</ProcessName>
<ImagePath>C:\Program Files\Windows Defender\MSASCuiL.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Windows Defender\MSASCuiL.exe&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Description>Windows Defender notification icon</Description>
<modulelist>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x23622c70000</BaseAddress>
<Size>733184</Size>
<Path>C:\Program Files\Windows Defender\EppManifest.dll</Path>
<Version>4.10.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль ресурсов настройки пользовательского интерфейса</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ff63bef0000</BaseAddress>
<Size>651264</Size>
<Path>C:\Program Files\Windows Defender\MSASCuiL.exe</Path>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Defender notification icon</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4560000</BaseAddress>
<Size>950272</Size>
<Path>C:\Program Files\Windows Defender\mpclient.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Client Interface</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>41</ProcessIndex>
<ProcessId>4928</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778406250112</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>uTorrent.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe&quot;  /MINIMIZED</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>3.5.4.44498</Version>
<Description>µTorrent</Description>
<modulelist>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>5406720</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</Path>
<Version>3.5.4.44498</Version>
<Company>BitTorrent Inc.</Company>
<Description>µTorrent</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e140000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SysWOW64\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1c0000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\SysWOW64\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6ef20000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70af0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fc0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fd0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fe0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>42</ProcessIndex>
<ProcessId>3608</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778496229053</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ApplicationFrameHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\ApplicationFrameHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\ApplicationFrameHost.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Application Frame Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ff6aa270000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\ApplicationFrameHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Frame Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5240000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\ApplicationFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фрейм приложения</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\system32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\D3D10Warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>43</ProcessIndex>
<ProcessId>5952</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778883326814</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54150_1240996307 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>44</ProcessIndex>
<ProcessId>5800</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765779120650795</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\esent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>45</ProcessIndex>
<ProcessId>340</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765800389528045</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54870_1839591030 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c50000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\Ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>46</ProcessIndex>
<ProcessId>2736</ProcessId>
<ParentProcessId>3976</ParentProcessId>
<ParentProcessIndex>47</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765800903010156</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Taskmgr.exe</ProcessName>
<ImagePath>C:\Windows\System32\Taskmgr.exe</ImagePath>
<CommandLine>&quot;C:\Windows\System32\Taskmgr.exe&quot; /2 </CommandLine>
<CompanyName>Microsoft® Windows® Operating System</CompanyName>
<Version>1, 0, 0, 1</Version>
<Description>Task Manager</Description>
<modulelist>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ff7c2a70000</BaseAddress>
<Size>1286144</Size>
<Path>C:\Windows\System32\Taskmgr.exe</Path>
<Version>1, 0, 0, 1</Version>
<Company>Microsoft® Windows® Operating System</Company>
<Description>Task Manager</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdfa0000</BaseAddress>
<Size>393216</Size>
<Path>C:\Windows\System32\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\System32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>49</ProcessIndex>
<ProcessId>6724</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803507001117</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHActiveDefense.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe&quot;</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1008</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795778431738530</Timestamp>
<BaseAddress>0x10000</BaseAddress>
<Size>413696</Size>
<Path>C:\ProgramData\Package Cache\{b8e12890-118d-4721-8e54-05d978086712}\VC_redist.x64.exe</Path>
<Version>14.0.24516.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24516</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0xd0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</Path>
<Version>10,0,0,1008</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795778469924367</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Wireshark\WinPcap_4_1_3.exe</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>WinPcap 4.1.3 installer</Description>
</module>
<module>
<Timestamp>131795778203065490</Timestamp>
<BaseAddress>0x840000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files\Wireshark\vcredist_x64.exe</Path>
<Version>14.12.25810.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810</Description>
</module>
<module>
<Timestamp>131795780232774368</Timestamp>
<BaseAddress>0x34c0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x3c80000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795780944214585</Timestamp>
<BaseAddress>0x40a0000</BaseAddress>
<Size>438272</Size>
<Path>C:\Program Files\Wireshark\dumpcap.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community</Company>
<Description>Dumpcap</Description>
</module>
<module>
<Timestamp>131795780231568066</Timestamp>
<BaseAddress>0x4630000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SysWOW64\net1.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Command</Description>
</module>
<module>
<Timestamp>131795778389953959</Timestamp>
<BaseAddress>0xa8e0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778421734438</Timestamp>
<BaseAddress>0xe830000</BaseAddress>
<Size>6127616</Size>
<Path>C:\Windows\System32\mfc140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>MFCDLL Shared Library - Retail Version</Description>
</module>
<module>
<Timestamp>131795780691287613</Timestamp>
<BaseAddress>0xf730000</BaseAddress>
<Size>8298496</Size>
<Path>C:\Program Files\Wireshark\Wireshark.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark</Description>
</module>
<module>
<Timestamp>131795780222197886</Timestamp>
<BaseAddress>0x10000000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fb90000</BaseAddress>
<Size>2736128</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\deepscan.dll</Path>
<Version>3, 5, 1, 2130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60190000</BaseAddress>
<Size>475136</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360SafeCamera.tpi</Path>
<Version>2, 0, 0, 1031</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60210000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\jcloudscan.dll</Path>
<Version>1, 0, 0, 1012</Version>
<Company>360.cn</Company>
<Description>360安全卫士 移动云查询模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604a0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appdext.dll</Path>
<Version>1, 0, 0, 1483</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604e0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\DrvUtility.dll</Path>
<Version>1, 0, 0, 1081</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60510000</BaseAddress>
<Size>409600</Size>
<Path>C:\Program Files (x86)\360\Total Security\SafeScan.dll</Path>
<Version>1, 0, 0, 1074</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60580000</BaseAddress>
<Size>204800</Size>
<Path>C:\Program Files (x86)\360\Total Security\ScanStub.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x605c0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360gameidentify.dll</Path>
<Version>1, 0, 1, 1050</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏识别模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60640000</BaseAddress>
<Size>430080</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\Netgm.dll</Path>
<Version>9,0,0,1005</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏模式判断模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60a50000</BaseAddress>
<Size>479232</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\DsSysRepair.dll</Path>
<Version>1, 0, 0, 1062</Version>
<Company>QIHU360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security System Repair Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61000000</BaseAddress>
<Size>184320</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\qutmipc.dll</Path>
<Version>7, 3, 0, 1267</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61030000</BaseAddress>
<Size>262144</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg.dll</Path>
<Version>3, 0, 0, 1160</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x610d0000</BaseAddress>
<Size>1097728</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\SomAdvUtils.dll</Path>
<Version>3, 1, 1, 2020</Version>
<Company>360.cn</Company>
<Description>360 Safeguard PC Boost</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61480000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qex\qex.dll</Path>
<Version>4.1.13.3366</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2017 Antivirus</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x616a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SelfProtectAPI2.dll</Path>
<Version>7, 1, 1, 1033</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61700000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360procmon.dll</Path>
<Version>7, 1, 1, 1221</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61780000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\netdefender.dll</Path>
<Version>1, 0, 0, 1129</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x617e0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appd.dll</Path>
<Version>7, 3, 6, 3113</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360HipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61ab0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\fileMgr.dll</Path>
<Version>7, 3, 0, 1963</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x621a0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\yhregd.dll</Path>
<Version>7, 2, 0, 1903</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62280000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\360SoftMgrS.dll</Path>
<Version>2, 1, 6, 1490</Version>
<Company>360.cn</Company>
<Description>360软件管家 服务模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62470000</BaseAddress>
<Size>405504</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll</Path>
<Version>7, 2, 1, 1279</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x624e0000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\360box.dll</Path>
<Version>2, 0, 0, 1043</Version>
<Company>360.cn</Company>
<Description>360隔离沙箱模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\deepscan\DsRes.dll</Path>
<Version>1,0,0,1012</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security Resource</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b70000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\gamemode.tpi</Path>
<Version>9,0,0,1001</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Game Mode Control</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67130000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\devenum.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечисление устройств.</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\fltlib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6c0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6ea80000</BaseAddress>
<Size>860160</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\QVM\360QVM.dll</Path>
<Version>5.0.2.1003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security QVM Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70210000</BaseAddress>
<Size>966656</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEngine.dll</Path>
<Version>1, 0, 0, 2016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70300000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEI.dll</Path>
<Version>1, 0, 0, 2003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>50</ProcessIndex>
<ProcessId>6340</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765803510844292</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>QHSafeTray.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</ImagePath>
<CommandLine>/showtrayicon</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1024</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0xec0000</BaseAddress>
<Size>2351104</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</Path>
<Version>10,0,0,1024</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x68f0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c480000</BaseAddress>
<Size>245760</Size>
<Path>C:\Program Files (x86)\360\Total Security\PDown.dll</Path>
<Version>1, 3, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Security Center Network Module </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5fe30000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll</Path>
<Version>9,6,0,1001</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60020000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360netctrl.dll</Path>
<Version>5, 3, 15, 2232</Version>
<Company>360.cn</Company>
<Description>360 Total Security NetwokrMonCtrl</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60090000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\netmon.tpi</Path>
<Version>5, 1, 1, 3157</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360安全卫士 流量防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60350000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Program Files (x86)\360\Total Security\ToolBox.dll</Path>
<Version>1, 0, 0, 1094</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x606b0000</BaseAddress>
<Size>598016</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe.dll</Path>
<Version>1, 0, 0, 1120</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x609b0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360GuardBase.dll</Path>
<Version>3, 1, 0, 1060</Version>
<Company>360.cn</Company>
<Description>360保镖</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61070000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SomProxy.dll</Path>
<Version>1, 0, 0, 1900</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x611e0000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360connect.tpi</Path>
<Version>9,2,0,1030</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Connect</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x618c0000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files (x86)\360\Total Security\sites.dll</Path>
<Version>11, 1, 0, 1212</Version>
<Company>360.cn</Company>
<Description>360安全卫士</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360hipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\softmgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\Cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62210000</BaseAddress>
<Size>446464</Size>
<Path>C:\Program Files (x86)\360\Total Security\360TSCommon.dll</Path>
<Version>9, 0, 0, 1016</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62960000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\CleanPlusCache.tpi</Path>
<Version>1, 0, 0, 1004</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>CleanPlusCache</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795771279916892</Timestamp>
<BaseAddress>0x68850000</BaseAddress>
<Size>2764800</Size>
<Path>C:\Windows\SysWOW64\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e6e0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e770000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SysWOW64\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71170000</BaseAddress>
<Size>466944</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\CQhCltHttpW.dll</Path>
<Version>1, 4, 0, 1030</Version>
<Company>QIHU 360 SOFTWARE  CO. LIMITED</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>51</ProcessIndex>
<ProcessId>6860</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803555957830</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHWatchdog.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe&quot; /watch</CommandLine>
<CompanyName>QIHU 360 SOFTWARE CO. LIMITED</CompanyName>
<Version>8,2,0,1000</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0xdf0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</Path>
<Version>8,2,0,1000</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>52</ProcessIndex>
<ProcessId>5924</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765805232900810</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>wmiprvse.exe</ProcessName>
<ImagePath>C:\Windows\sysWOW64\wbem\wmiprvse.exe</ImagePath>
<CommandLine>C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Description>WMI Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x950000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\sysWOW64\wbem\wmiprvse.exe</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Provider Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\storagewmi_passthru.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60160000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x604d0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\delegatorprovider.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>54</ProcessIndex>
<ProcessId>4408</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765812380694767</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x17826230000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1140000</BaseAddress>
<Size>1134592</Size>
<Path>C:\Windows\System32\ReAgent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>C:\Windows\System32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\system32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe000000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\system32\WinSATAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Assessment Tool API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf050000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\sdiageng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема выполнения сценариев диагностики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4ae0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sdiagschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запланированная задача сценариев проверки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4b00000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\MemoryDiagnostic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач средства проверки памяти Windows (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac5c80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\TempSignedLicenseExchangeTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TempSignedLicenseExchangeTask Task</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca200000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\ReAgentTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca210000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\RstrtMgr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер перезапуска</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacac00000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\radarrs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>программа устранения нехватки системных ресурсов Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>55</ProcessIndex>
<ProcessId>6944</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131767576301455145</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SkypeHost.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe&quot; -ServerName:SkypeHost.ServerServer</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>12.1815.210.0</Version>
<Description>Microsoft Skype</Description>
<modulelist>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ff7e8670000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaae130000</BaseAddress>
<Size>22437888</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkyWrap.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabe150000</BaseAddress>
<Size>2691072</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\skypert.dll</Path>
<Version>2018.15.01.31</Version>
<Company></Company>
<Description>SkypeRT shared library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1a80000</BaseAddress>
<Size>978944</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7c80000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>56</ProcessIndex>
<ProcessId>1048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131768729449405953</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>sedsvc.exe</ProcessName>
<ImagePath>C:\Program Files\rempl\sedsvc.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\rempl\sedsvc.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Description>sedsvc</Description>
<modulelist>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ff751430000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\rempl\sedsvc.exe</Path>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>sedsvc</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>57</ProcessIndex>
<ProcessId>7744</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081112364684</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; </CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x11330000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60900000</BaseAddress>
<Size>720896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\urlproc.dll</Path>
<Version>2, 9, 5, 1260</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x68b00000</BaseAddress>
<Size>44998656</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ce30000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6dc80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files (x86)\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6df70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\SysWOW64\shdocvw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e070000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e090000</BaseAddress>
<Size>233472</Size>
<Path>C:\Windows\SysWOW64\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e110000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e120000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multimedia Realtime Runtime</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e2a0000</BaseAddress>
<Size>4440064</Size>
<Path>C:\Windows\SysWOW64\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb60000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb70000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ec40000</BaseAddress>
<Size>442368</Size>
<Path>C:\Windows\SysWOW64\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd00000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd20000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe40000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe50000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SysWOW64\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ff90000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\SysWOW64\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ffe0000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\SysWOW64\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70190000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x701a0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\dllyupdate.dll</Path>
<Version>1.2.0.1831</Version>
<Company>Yandex LLC</Company>
<Description>Yandex updater (CU)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b30000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\WINUSB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows USB Driver User Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b60000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x711f0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>58</ProcessIndex>
<ProcessId>5696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081114193232</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe --type=crashpad-handler &quot;--user-data-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler &quot;--database=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data\Crashpad&quot; &quot;--metrics-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; --url=https://crash-reports.browser.yandex.net/submit --annotation=machine_id=c46245ef0fec9d5c44d2fa20241f2070 --annotation=main_process_pid=7744 --annotation=metrics_client_id=520f4dd3247d4cdfb744f32b1130b1bf --annotation=plat=Win32 --annotation=prod=Yandex --annotation=ver=18.6.1.770 --initial-client-data=0x1c4,0x1cc,0x1d0,0x1c0,0x1d4,0x700b800c,0x700b7ffc,0x700b7fe0,0x1c8</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>59</ProcessIndex>
<ProcessId>4664</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081123844756</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=gpu-process --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --service-request-channel-token=CC1AC8FA9C8EFF1EEBC2375FE4F704C6 --mojo-platform-channel-handle=1588 --ignored=&quot; --type=renderer &quot; /prefetch:2</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ecb0000</BaseAddress>
<Size>2228224</Size>
<Path>C:\Windows\SysWOW64\mfh264enc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation H264 Encoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f250000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\SysWOW64\ddraw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectDraw</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f340000</BaseAddress>
<Size>3784704</Size>
<Path>C:\Windows\SysWOW64\D3DCompiler_47.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D HLSL Compiler</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f6e0000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\SysWOW64\msvproc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Video Processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fbe0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\mf.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff20000</BaseAddress>
<Size>118784</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\swiftshader\libegl.dll</Path>
<Version>4.0.0.3</Version>
<Company></Company>
<Description>SwiftShader libEGL 32-bit Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dxva2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Video Acceleration 2.0 DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x705d0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\DCIMAN32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DCI Manager</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>60</ProcessIndex>
<ProcessId>8968</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081206363215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=183F52B8A6577BFD721F95F3A9641348 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=183F52B8A6577BFD721F95F3A9641348 --renderer-client-id=4 --mojo-platform-channel-handle=2640 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>61</ProcessIndex>
<ProcessId>4992</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081244357280</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=7E8A8199C364F4B0114F2A163B757250 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E8A8199C364F4B0114F2A163B757250 --renderer-client-id=10 --mojo-platform-channel-handle=3904 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>63</ProcessIndex>
<ProcessId>9504</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956266598229</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgent.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgent.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgent.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>InstallAgent</Description>
<modulelist>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ff63d380000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\InstallAgent.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffabea60000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\VEStoreEventHandlers.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDL Store Event Handlers</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4ad0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\EAMProgressHandler.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>EAMProgressHandler</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>64</ProcessIndex>
<ProcessId>8768</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956321853179</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgentUserBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgentUserBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgentUserBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>InstallAgentUserBroker</Description>
<modulelist>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x22530450000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ff74f890000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\InstallAgentUserBroker.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgentUserBroker</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>65</ProcessIndex>
<ProcessId>9636</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956424585250</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettingsBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\SystemSettingsBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\SystemSettingsBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>System Settings Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ff6015f0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\SystemSettingsBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Broker</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>66</ProcessIndex>
<ProcessId>10592</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956519902643</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettings.exe</ProcessName>
<ImagePath>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</ImagePath>
<CommandLine>&quot;C:\Windows\ImmersiveControlPanel\SystemSettings.exe&quot; -ServerName:microsoft.windows.immersivecontrolpanel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Параметры</Description>
<modulelist>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x18099ef0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\WMI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI DC and DP functionality</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ff7937a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaabce0000</BaseAddress>
<Size>2535424</Size>
<Path>C:\Windows\System32\NetworkMobileSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System settings network mobile handlers group</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac220000</BaseAddress>
<Size>4952064</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Application</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaadd90000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\NetworkDesktopSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Группа обработчиков системных параметров сетевого рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaaf920000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettingsViewModel.Desktop.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings View Model Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0970000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\credprovhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост инфраструктуры поставщика учетных данных</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0a70000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\System32\fhcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигураций истории файлов</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\SYSTEM32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\SYSTEM32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab91d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\ImmersiveControlPanel\Telemetry.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Telemetry Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcc60000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\System32\MiracastReceiver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API приемника Miracast</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2bf0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\EFSUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>EFS Utility Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\SYSTEM32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\wmiclnt.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca560000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\NcaApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Network Connectivity Assistant API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>67</ProcessIndex>
<ProcessId>10964</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794956837373387</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{BA126F01-2166-11D1-B1D0-00805FC1270E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\system32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>68</ProcessIndex>
<ProcessId>8940</ProcessId>
<ParentProcessId>2156</ParentProcessId>
<ParentProcessIndex>62</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956984780982</CreateTime>
<FinishTime>131795780667428563</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Photoshop.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe&quot; &quot;C:\Users\User\Downloads\tlauncher_psd\tlauncher_psd.psd&quot;</CommandLine>
<CompanyName>Adobe Systems, Incorporated</CompanyName>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Description>Adobe Photoshop CC 2017</Description>
<modulelist>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0xb20000</BaseAddress>
<Size>9846784</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\cg.dll</Path>
<Version>3.0.00007</Version>
<Company>NVIDIA Corporation</Company>
<Description>Cg Core Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1490000</BaseAddress>
<Size>3276800</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\libmmd.dll</Path>
<Version>12.0.12.2</Version>
<Company>Intel Corporation</Company>
<Description>Math Library for Intel(r) Compilers (thread-safe)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x10000000</BaseAddress>
<Size>6070272</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\svml_dispmd.dll</Path>
<Version>12.0.12.2</Version>
<Company>Intel Corporation</Company>
<Description>SVML Library for Intel(r) Compilers (thread-safe)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x4fad0000</BaseAddress>
<Size>70561792</Size>
<Path>C:\Program Files\Common Files\Adobe\Plug-Ins\CC\File Formats\Camera Raw.8bi</Path>
<Version>9.8</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Photoshop Camera Raw Plug-in</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5b690000</BaseAddress>
<Size>4763648</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\SVGRE.dll</Path>
<Version>6, 0, 0, 37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>SVGRE 6.0</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5bcf0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AXE8SharedExpat.dll</Path>
<Version>3.8.0.34320</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>AXE Shared EXPAT (UTF-8 native)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5bd30000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\dnssd.dll</Path>
<Version>3,0,0,2</Version>
<Company>Apple Inc.</Company>
<Description>Bonjour Client Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5bd40000</BaseAddress>
<Size>974848</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AXEDOMCore.dll</Path>
<Version>3.8.0.34320</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XML Engine: DOM Core</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x5be30000</BaseAddress>
<Size>1306624</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\icucnv40.dll</Path>
<Version>4, 0, 0, 1001</Version>
<Company>IBM Corporation and others</Company>
<Description>IBM ICU Common DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x6a400000</BaseAddress>
<Size>479232</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\cgGL.dll</Path>
<Version>3.0.00007</Version>
<Company>NVIDIA Corporation</Company>
<Description>Cg GL Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\File Formats\PSDX.8bi</Path>
<Version>14.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Photoshop Remix Plug-In</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2eee90000</BaseAddress>
<Size>13922304</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\icudt40.dll</Path>
<Version>4, 0, 0, 1001</Version>
<Company>IBM Corporation and others</Company>
<Description>ICU Data DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f1470000</BaseAddress>
<Size>12288</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PSArt.dll</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Resource DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f3490000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.dll</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Resource DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f3620000</BaseAddress>
<Size>2699264</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PSViews.dll</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Resource DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f93a0000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\WRServices.dll</Path>
<Version>12.0.0.1000</Version>
<Company>WinSoft S.A.</Company>
<Description>WRServices Engine</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x1c2f9540000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Linguistics\Providers\Plugins2\WRLiloPlugin.bundle\WRLiloPlugin.dll</Path>
<Version>1.3.6rc1</Version>
<Company>WinSoft SA</Company>
<Description>WR LILO Plugin</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ff6c3030000</BaseAddress>
<Size>182624256</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe</Path>
<Version>18.0.1 (2017.0.1 20161130.r.29 2016/11/30:23:00:00 CL 1099099)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa0cb0000</BaseAddress>
<Size>1880064</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\aif.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa0e80000</BaseAddress>
<Size>2637824</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\LogSession.dll</Path>
<Version>7.4.1.60.45263</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>LogSession</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa1110000</BaseAddress>
<Size>70823936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\libcef.dll</Path>
<Version>3.2526.1347.gcf20046</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa54a0000</BaseAddress>
<Size>7950336</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\ScriptingSupport.8li</Path>
<Version>18.0.1</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>ScriptingSupport</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa5c40000</BaseAddress>
<Size>2113536</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\AdobeHunspellPlugin.dll</Path>
<Version>11.0.0.22122</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>AdobeHunspellPlugin</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa5e50000</BaseAddress>
<Size>4493312</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\CoolType.dll</Path>
<Version>5.15.00.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>CoolType Typography Engine</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa62a0000</BaseAddress>
<Size>5267456</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AGM.dll</Path>
<Version>4.30.60.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Graphics Manager</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa67b0000</BaseAddress>
<Size>1839104</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ACE.dll</Path>
<Version>2.20.02.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Color Engine</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6980000</BaseAddress>
<Size>1302528</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeXMP.dll</Path>
<Version>5.6-c138 ( 64 bit ), 79.159824, 2016/09/14-01:09:01</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XMP Core 5.6-c138 ( 64 bit )</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6ac0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\MultiProcessor Support.8bx</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6b70000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\MMXCore.8bx</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2093056</Size>
<Path>C:\Windows\system32\wpdshext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки для переносных устройств</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa6fd0000</BaseAddress>
<Size>978944</Size>
<Path>C:\Windows\SYSTEM32\MSVCR120.dll</Path>
<Version>12.00.40660.0 built by: VSULDR</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa70c0000</BaseAddress>
<Size>679936</Size>
<Path>C:\Windows\SYSTEM32\MSVCP120.dll</Path>
<Version>12.00.40660.0 built by: VSULDR</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7170000</BaseAddress>
<Size>2826240</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\opencv_imgproc249.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7430000</BaseAddress>
<Size>2564096</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\opencv_core249.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa76b0000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AIDE.dll</Path>
<Version>1.5.0.36540</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Image Decode Encode Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7820000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\tbbmalloc.dll</Path>
<Version>4, 4, 2016, 0412</Version>
<Company>Intel Corporation</Company>
<Description>Scalable Allocator library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7870000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\SYSTEM32\DDRAW.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectDraw</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7b20000</BaseAddress>
<Size>2613248</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeOwl.dll</Path>
<Version>5.2.11</Version>
<Company>Adobe Systems, Incorporated </Company>
<Description>Adobe Owl(64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7da0000</BaseAddress>
<Size>749568</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ScCore.dll</Path>
<Version>4.5.6.4</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Scripting Components Core (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa7e60000</BaseAddress>
<Size>18792448</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\mona.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9050000</BaseAddress>
<Size>802816</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ExtendScript.dll</Path>
<Version>4.5.6.4</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe ExtendScript scripting engine (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9120000</BaseAddress>
<Size>5681152</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PlugPlugOwl.dll</Path>
<Version>7.0.0.67</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>PlugPlugOwl Standard Dll (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9690000</BaseAddress>
<Size>5595136</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\MPS.dll</Path>
<Version>5.8.1.37174</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Modular Parsing System</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9bf0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\ahclient.dll</Path>
<Version>2.0.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe Help Client Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9c50000</BaseAddress>
<Size>569344</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\manta.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9ce0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\tbb.dll</Path>
<Version>4, 4, 2016, 0412</Version>
<Company>Intel Corporation</Company>
<Description>Intel(R) Threading Building Blocks library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9d30000</BaseAddress>
<Size>499712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\VulcanControl.dll</Path>
<Version>__</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Vulcan Application Control Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9db0000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\VulcanMessage5.dll</Path>
<Version>__</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Vulcan Message Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9e50000</BaseAddress>
<Size>1241088</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdbePM.dll</Path>
<Version>2.5.00</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe PatchMatch</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9f80000</BaseAddress>
<Size>167936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\CITThreading.dll</Path>
<Version>2.1.0.1 ( 32 bit Debug)</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>CITTHREADING_NAME, 2.1.0.1 ( 32 bit Debug)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaa9fb0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\adobe_caps.dll</Path>
<Version>10,0,0,6</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CAPS DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa190000</BaseAddress>
<Size>1191936</Size>
<Path>C:\Windows\SYSTEM32\OPENGL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OpenGL Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa2c0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa5f0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\IMSLib.dll</Path>
<Version>10.0.0.1</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>IMSLib DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaa9c0000</BaseAddress>
<Size>9007104</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\File Formats\Dicom.8bi</Path>
<Version>18.0.1</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Dicom Plugin</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaaba80000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\GLU32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека подпрограмм OpenGL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaabca0000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\PLUGIN.dll</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Photoshop Plugin Utilities</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaade70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\icm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Color Management Module (CMM)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab06d0000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\c_g18030.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>GB18030 DBCS-Unicode Conversion DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab0b60000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeSVGAGM.dll</Path>
<Version>1.0.0.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe SVG AGM Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab1e60000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeXMPFiles.dll</Path>
<Version>5.7-f022 ( 64 bit ), 79.159824, 2016/09/14-01:09:01</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XMP Files 5.7-f022 ( 64 bit )</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab22e0000</BaseAddress>
<Size>1544192</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Spaces.8li</Path>
<Version>18.0.1</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Spaces</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab3410000</BaseAddress>
<Size>167936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\libglog.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabb070000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobePIP.dll</Path>
<Version>7.4.1.60.45263</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Product Improvement Program</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabb250000</BaseAddress>
<Size>380928</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\BIBUtils.dll</Path>
<Version>1.1.01.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Bravo Interface Binder Utilities</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabcc00000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\SYSTEM32\STI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека устройств неподвижных изображений </Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac0b40000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\dlnashext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLNA Namespace DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1300000</BaseAddress>
<Size>598016</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\BIB.dll</Path>
<Version>1.2.03.37447</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Bravo Interface Binder</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\SYSTEM32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\AdobeXMPScript.dll</Path>
<Version>5.2-s002 ( 64 bit ), 79.159824, 2016/09/14-01:09:01</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe XMP Script 5.2-s002 ( 64 bit )</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac4c50000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\WSOCK32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6aa0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\amtlib.dll</Path>
<Version>10.0.0.3</Version>
<Company>painter</Company>
<Description>AMTEmu Licensing</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Extensions\FastCore.8bx</Path>
<Version>18.0.1 (2017.0.1 x001 x003)</Version>
<Company>Adobe Systems, Incorporated</Company>
<Description>Adobe Photoshop CC 2017</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac7710000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\wiatrace.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WIA Tracing</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca540000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SYSTEM32\DCIMAN32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DCI Manager</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacac80000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SYSTEM32\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383911</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>69</ProcessIndex>
<ProcessId>10000</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957424930105</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>AdobeIPCBroker.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe&quot; &quot;-launchedbyvulcan&quot;</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>5.0.0.76</Version>
<Description>Adobe IPC Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0xbe0000</BaseAddress>
<Size>798720</Size>
<Path>C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe</Path>
<Version>5.0.0.76</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe IPC Broker</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>70</ProcessIndex>
<ProcessId>10064</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957636746019</CreateTime>
<FinishTime>131795780871972781</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Adobe Spaces Helper.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe&quot; --type=renderer --no-sandbox --touch-events=disabled --lang=en-US --lang=ru --locales-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\locales\\&quot; --log-file=&quot;C:\Users\User\AppData\Roaming\Adobe\Adobe Photoshop CC 2017\Logs\debug.log&quot; --resources-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\\&quot; --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;8940.0.1405287427\319210639&quot; /prefetch:673131151</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ff6c2ef0000</BaseAddress>
<Size>1196032</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaa1110000</BaseAddress>
<Size>70823936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\libcef.dll</Path>
<Version>3.2526.1347.gcf20046</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SSPICLI.DLL</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384116</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>71</ProcessIndex>
<ProcessId>8596</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957641371503</CreateTime>
<FinishTime>131795780871854772</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Adobe Spaces Helper.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe&quot; --type=renderer --no-sandbox --touch-events=disabled --lang=en-US --lang=ru --locales-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\locales\\&quot; --log-file=&quot;C:\Users\User\AppData\Roaming\Adobe\Adobe Photoshop CC 2017\Logs\debug.log&quot; --resources-dir-path=&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Resources\\&quot; --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;8940.1.1139889345\75461215&quot; /prefetch:673131151</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ff6c2ef0000</BaseAddress>
<Size>1196032</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\Adobe Spaces Helper.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaa1110000</BaseAddress>
<Size>70823936</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Spaces\libcef.dll</Path>
<Version>3.2526.1347.gcf20046</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SSPICLI.DLL</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384222</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>72</ProcessIndex>
<ProcessId>11172</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957658059215</CreateTime>
<FinishTime>131795780685488658</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; &quot;C:\Program Files (x86)\Common Files\Adobe\CEP\extensions\com.adobe.previewHD\PSLoader\loader.html&quot; 2ec98b7b-08f4-4716-915a-e20a700b24cb 8940 PHXS 18.0.1 com.adobe.preview.loader 1 &quot;C:\Program Files (x86)\Common Files\Adobe\CEP\extensions\com.adobe.previewHD&quot; &quot;Photoshop&quot; 16 WyItLWVuYWJsZS1ub2RlanMiXQ== ru_RU 4293980400 1</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384338</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>73</ProcessIndex>
<ProcessId>11216</ProcessId>
<ParentProcessId>11172</ParentProcessId>
<ParentProcessIndex>72</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957800622174</CreateTime>
<FinishTime>131795780687170604</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=ru --log-file=&quot;C:\Users\User\AppData\Local\Temp\CEPHtmlEngine7-PHXS-18.0.1-com.adobe.preview.loader.log&quot; --log-severity=error --params_ppid=PHXS --params_ppversion=18.0.1 --params_extensionid=com.adobe.preview.loader --params_loglevel=1 --params_serverid=8940 --params_extensionuuid=2ec98b7b-08f4-4716-915a-e20a700b24cb --params_windowid=70742 --params_commandline=WyItLWVuYWJsZS1ub2RlanMiXQ== --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=11172 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;11172.0.296388529\1274093304&quot; /prefetch:673131151</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x6d990000</BaseAddress>
<Size>3055616</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\ffmpegsumo.dll</Path>
<Version>41.0.2272.104</Version>
<Company>The Chromium Authors</Company>
<Description>Chromium</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384488</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>74</ProcessIndex>
<ProcessId>10844</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958201141405</CreateTime>
<FinishTime>131795780685576568</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\extensions\com.adobe.experimentation.extension\index.html&quot; e44c0384-b65f-4f05-a36a-c6092cb32d00 8940 PHXS 18.0.1 com.adobe.experimentation.extension 1 &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\extensions\com.adobe.experimentation.extension&quot; &quot;Photoshop&quot; 16 WyItLWVuYWJsZS1ub2RlanMiXQ== ru_RU 4293980400 1</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384610</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>75</ProcessIndex>
<ProcessId>9092</ProcessId>
<ParentProcessId>10844</ParentProcessId>
<ParentProcessIndex>74</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958208470288</CreateTime>
<FinishTime>131795780687158805</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>CEPHtmlEngine.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe&quot; --type=renderer --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=ru --log-file=&quot;C:\Users\User\AppData\Local\Temp\CEPHtmlEngine7-PHXS-18.0.1-com.adobe.experimentation.extension.log&quot; --log-severity=error --params_ppid=PHXS --params_ppversion=18.0.1 --params_extensionid=com.adobe.experimentation.extension --params_loglevel=1 --params_serverid=8940 --params_extensionuuid=e44c0384-b65f-4f05-a36a-c6092cb32d00 --params_windowid=198892 --params_commandline=WyItLWVuYWJsZS1ub2RlanMiXQ== --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=10844 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel=&quot;10844.0.379179099\270765323&quot; /prefetch:673131151</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>7.0.0</Version>
<Description>Adobe CEP HTML Engine</Description>
<modulelist>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x240000</BaseAddress>
<Size>4014080</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe</Path>
<Version>7.0.0</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe CEP HTML Engine</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x5d110000</BaseAddress>
<Size>44531712</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\libcef.dll</Path>
<Version>3.2272.67.g479a5bd</Version>
<Company></Company>
<Description>Chromium Embedded Framework (CEF) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x6d990000</BaseAddress>
<Size>3055616</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\CEP\CEPHtmlEngine\ffmpegsumo.dll</Path>
<Version>41.0.2272.104</Version>
<Company>The Chromium Authors</Company>
<Description>Chromium</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x6e210000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x6e230000</BaseAddress>
<Size>446464</Size>
<Path>C:\Windows\SysWOW64\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384720</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>76</ProcessIndex>
<ProcessId>11496</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958406617238</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SearchUI.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe&quot; -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>Search and Cortana application</Description>
<modulelist>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ff79c3c0000</BaseAddress>
<Size>10706944</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Search and Cortana application</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\SYSTEM32\chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\SYSTEM32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4c70000</BaseAddress>
<Size>4874240</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab52c0000</BaseAddress>
<Size>2445312</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5840000</BaseAddress>
<Size>3108864</Size>
<Path>C:\Windows\System32\Speech_OneCore\Common\sapi_onecore.dll</Path>
<Version>5.3.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Speech API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5db0000</BaseAddress>
<Size>9781248</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9d50000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;CortanaApi.ProxyStub.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe770000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabefa0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\Cortana.Persona.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana.Persona</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac10b0000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\PersonaX.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PersonaX</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\SYSTEM32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3bf0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionMgr.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana Action Manager</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bb0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\windows.cortana.pal.desktop.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.PAL.Desktop</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7c50000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\BingConfigurationClient.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bing Configuration Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\SYSTEM32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780654647361</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>77</ProcessIndex>
<ProcessId>11408</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794962679173110</CreateTime>
<FinishTime>131795780748861608</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>node.exe</ProcessName>
<ImagePath>C:\Program Files\Adobe\Adobe Photoshop CC 2017\node.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\node.exe&quot; &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Generator-builtin&quot; --launchreason menu --menu crema-dummy-menu --photoshopVersion 18.0.1 -i \\.\pipe\36b615a8-a6c5-11e8-b291-8ffa7e69373b_i -o \\.\pipe\36b615a8-a6c5-11e8-b291-8ffa7e69373b_o -f &quot;C:\Program Files\Adobe\Adobe Photoshop CC 2017\Required\Plug-Ins\Generator&quot; -f &quot;C:\Program Files\Common Files\Adobe\Plug-Ins\CC\Generator&quot;</CommandLine>
<CompanyName>Node.js</CompanyName>
<Version>4.3.1</Version>
<Description>Node.js: Server-side JavaScript</Description>
<modulelist>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ff6cbb20000</BaseAddress>
<Size>14237696</Size>
<Path>C:\Program Files\Adobe\Adobe Photoshop CC 2017\node.exe</Path>
<Version>4.3.1</Version>
<Company>Node.js</Company>
<Description>Node.js: Server-side JavaScript</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385734</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>78</ProcessIndex>
<ProcessId>12164</ProcessId>
<ParentProcessId>11408</ParentProcessId>
<ParentProcessIndex>77</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794962697229215</CreateTime>
<FinishTime>131795780751857016</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>conhost.exe</ProcessName>
<ImagePath>C:\Windows\system32\conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0x4</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffabe520000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SYSTEM32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.DLL</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385831</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>79</ProcessIndex>
<ProcessId>5612</ProcessId>
<ParentProcessId>904</ParentProcessId>
<ParentProcessIndex>22</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131794965205293998</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>dashost.exe</ProcessName>
<ImagePath>C:\Windows\system32\dashost.exe</ImagePath>
<CommandLine>dashost.exe {609e1ffd-7b4d-4dbc-a36f725917d81f2d}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Device Association Framework Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ff6559c0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\dashost.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Framework Provider Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabb1a0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\DAFWSD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF WSD Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabc970000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\dafupnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF UPnP Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>80</ProcessIndex>
<ProcessId>9720</ProcessId>
<ParentProcessId>9180</ParentProcessId>
<ParentProcessIndex>81</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794969418818027</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Windows10UpgraderApp.exe</ProcessName>
<ImagePath>C:\Windows10Upgrade\Windows10UpgraderApp.exe</ImagePath>
<CommandLine>&quot;C:\Windows10Upgrade\Windows10UpgraderApp.exe&quot;  /Install /ClientID Win10Upgrade:VNL:NHV18:{} /SkipEULA /PostEosUi</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>1.4.9200.22452</Version>
<Description>Помощник по обновлению Windows 10</Description>
<modulelist>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0xb30000</BaseAddress>
<Size>1875968</Size>
<Path>C:\Windows10Upgrade\Windows10UpgraderApp.exe</Path>
<Version>1.4.9200.22452</Version>
<Company>Microsoft Corporation</Company>
<Description>Помощник по обновлению Windows 10</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d6e0000</BaseAddress>
<Size>634880</Size>
<Path>C:\Windows\SysWOW64\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d780000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\SysWOW64\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d860000</BaseAddress>
<Size>1245184</Size>
<Path>C:\Windows\SysWOW64\MFC42u.dll</Path>
<Version>6.06.8063.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека MFCDLL - розничная версия</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6ded0000</BaseAddress>
<Size>630784</Size>
<Path>C:\Windows\SysWOW64\ODBC32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ODBC Driver Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfc0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfd0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SysWOW64\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e010000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows10Upgrade\Downloader.dll</Path>
<Version>1.4.9200.22452 (win8_ldr.180426-0600)</Version>
<Company>Microsoft Corporation</Company>
<Description>Downloader</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e050000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.DLL</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>82</ProcessIndex>
<ProcessId>8944</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795005508439638</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>fontdrvhost.exe</ProcessName>
<ImagePath>C:\Windows\system32\fontdrvhost.exe</ImagePath>
<CommandLine>&quot;fontdrvhost.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Usermode Font Driver Host</Description>
<modulelist>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ff654db0000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\system32\fontdrvhost.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Usermode Font Driver Host</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>83</ProcessIndex>
<ProcessId>6684</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795006053748558</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Microsoft.Photos.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe&quot; -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ff705e40000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bb10000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bc70000</BaseAddress>
<Size>3158016</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bf80000</BaseAddress>
<Size>2994176</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9c260000</BaseAddress>
<Size>20144128</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9d5a0000</BaseAddress>
<Size>29011968</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9fb20000</BaseAddress>
<Size>7950336</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.3_1.3.24201.0_x64__8wekyb3d8bbwe\SharedLibrary.dll</Path>
<Version></Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Shared Framework</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa03f0000</BaseAddress>
<Size>4546560</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\FaceSdkStoreWrapper.dll</Path>
<Version>16.425.0.0</Version>
<Company>Microsoft Corporation</Company>
<Description>FaceSdkStoreWrapper</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa0850000</BaseAddress>
<Size>2371584</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\MediaEngine.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab270000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\System32\Windows.AccountsControl.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Accounts Control</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\Windows.System.Diagnostics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Diagnostics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f60000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\CryptoWinRT.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto WinRT Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9270000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9b40000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x64__8wekyb3d8bbwe\mrt100_app.dll</Path>
<Version>1.4.24201.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabea30000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\Windows.Energy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Energy Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0fa0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1c70000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCOMP140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C/C++ OpenMP Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2c00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\clrcompression.dll</Path>
<Version>1.0.23123.00 built by: PROJECTKREL</Version>
<Company>Microsoft Corporation</Company>
<Description>ClrCompression</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SYSTEM32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\mrt100.dll</Path>
<Version>1.0.24120.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OleAut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>84</ProcessIndex>
<ProcessId>6208</ProcessId>
<ParentProcessId>12140</ParentProcessId>
<ParentProcessIndex>85</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795181740423780</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>OneDrive.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</ImagePath>
<CommandLine> /updateInstalled /background</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>18.131.0701.0007</Version>
<Description>Microsoft OneDrive</Description>
<modulelist>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x11f0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x55a0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSync.Resources.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\MSHTML.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6bab0000</BaseAddress>
<Size>4472832</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Widgets.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d210000</BaseAddress>
<Size>4993024</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Gui.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\Wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ce0000</BaseAddress>
<Size>1519616</Size>
<Path>C:\Windows\SysWOW64\wpc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека параметров родительского контроля</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70f00000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71200000</BaseAddress>
<Size>708608</Size>
<Path>C:\Windows\SysWOW64\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x712b0000</BaseAddress>
<Size>602112</Size>
<Path>C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71350000</BaseAddress>
<Size>2867200</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Quick.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71630000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x716b0000</BaseAddress>
<Size>1294336</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LIBEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x717f0000</BaseAddress>
<Size>2637824</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Qml.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71a80000</BaseAddress>
<Size>4796416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Core.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71f20000</BaseAddress>
<Size>6033408</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SyncEngine.DLL</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Sync Engine</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72530000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72550000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72810000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72820000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SysWOW64\MicrosoftAccountTokenProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Token Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72850000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\SysWOW64\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728b0000</BaseAddress>
<Size>135168</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncFAL.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDriveFile Sync FAL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\SysWOW64\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72bb0000</BaseAddress>
<Size>1105920</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\platforms\qwindows.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e90000</BaseAddress>
<Size>299008</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SSLEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ee0000</BaseAddress>
<Size>950272</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Network.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72fd0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\loadperf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Загрузка и выгрузка счетчиков производительности</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ff0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\pdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль поддержки данных производительности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73040000</BaseAddress>
<Size>253952</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5WinExtras.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73080000</BaseAddress>
<Size>880640</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ADAL.dll</Path>
<Version>1.0.2110.0526</Version>
<Company>Microsoft</Company>
<Description>ADAL.Native</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73160000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WSOCK32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73170000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SysWOW64\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x731d0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\WnsClientApi.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive WNS Client Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73240000</BaseAddress>
<Size>520192</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LogUploader.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive Sync LogUploader Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x732c0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncViews.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Qt Components</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73400000</BaseAddress>
<Size>159744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\UpdateRingSettings.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Ring Settings</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73430000</BaseAddress>
<Size>1748992</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncSessions.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>P2P Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x735e0000</BaseAddress>
<Size>671744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\RemoteAccess.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73690000</BaseAddress>
<Size>188416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Telemetry.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Telemetry Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ETWLog.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>ETW Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736d0000</BaseAddress>
<Size>3600384</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncClient.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Client</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73af0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LoggingPlatform.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Logging Platform</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73dc0000</BaseAddress>
<Size>1171456</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ucrtbase.dll</Path>
<Version>10.0.17134.12 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73fb0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\MSWSOCK.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74090000</BaseAddress>
<Size>462848</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\MSVCP140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\VCRUNTIME140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74220000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>86</ProcessIndex>
<ProcessId>6140</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795747339404666</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=764E64A4EA650A23B18EB059FF0B4B51 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=764E64A4EA650A23B18EB059FF0B4B51 --renderer-client-id=106 --mojo-platform-channel-handle=6612 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>87</ProcessIndex>
<ProcessId>11432</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755605761168</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=9DD318D38190D474A9A0F5AFD262A449 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=9DD318D38190D474A9A0F5AFD262A449 --renderer-client-id=109 --mojo-platform-channel-handle=4152 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>88</ProcessIndex>
<ProcessId>10384</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755746873891</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=7E669976FFDCEE94D9B90B02CADE1179 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E669976FFDCEE94D9B90B02CADE1179 --renderer-client-id=112 --mojo-platform-channel-handle=5412 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>90</ProcessIndex>
<ProcessId>6936</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795756360200321</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --renderer-client-id=116 --mojo-platform-channel-handle=4024 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>98</ProcessIndex>
<ProcessId>6080</ProcessId>
<ParentProcessId>84</ParentProcessId>
<ParentProcessIndex>97</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795771125310655</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MCLauncher.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe&quot; </CommandLine>
<CompanyName></CompanyName>
<Version>1.0</Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795771127806606</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>2830336</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Version>1.0</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771129292604</Timestamp>
<BaseAddress>0x750000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771335510731</Timestamp>
<BaseAddress>0x11000000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771334241016</Timestamp>
<BaseAddress>0x12000000</BaseAddress>
<Size>360448</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771129285523</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795771129286235</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795771129295328</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795771135408057</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795771129575672</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129398434</Timestamp>
<BaseAddress>0x66680000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771136825814</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795771129423112</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771129349562</Timestamp>
<BaseAddress>0x6b830000</BaseAddress>
<Size>2584576</Size>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795771329638947</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795771329610149</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795771329592759</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795771136045859</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795771131298623</Timestamp>
<BaseAddress>0x6d180000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795771136082794</Timestamp>
<BaseAddress>0x6dca0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Script Runtime</Description>
</module>
<module>
<Timestamp>131795771133718253</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795771129406131</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795771329618480</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795771329601483</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795771336447829</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771135435621</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795771135446667</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771136073867</Timestamp>
<BaseAddress>0x70e90000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Script Host Runtime Library</Description>
</module>
<module>
<Timestamp>131795771135423397</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795771135552456</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795771136181434</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771328759427</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771135541570</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795771347140137</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795771347110306</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795771135314174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771347090516</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795771347075776</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795771328179609</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795771130913562</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795771135359123</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795771129415027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795771130899582</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795771133098293</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795771132990161</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795771131765102</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795771129389543</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795771129317462</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795771129360685</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795771129360034</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771129496759</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795771129358136</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129357408</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795771129365891</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795771129359203</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795771129353720</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771135412052</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795771129350362</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795771129366695</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795771136054082</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795771131750596</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795771129363162</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795771328737550</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795771135228888</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795771129301509</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771129362062</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795771135227735</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795771129363985</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795771129356607</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795771129364960</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795771129354665</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795771129370252</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795771129352041</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795771129367584</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795771129351257</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771129361361</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795771129369244</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129368545</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795771131168008</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795771129352931</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771133704572</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795771129355632</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795771347076821</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795771127807387</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795771127807116</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>104</ProcessIndex>
<ProcessId>12696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777567759490</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=E83DB721798C8A70C76CD26F6F4EE1BC --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=E83DB721798C8A70C76CD26F6F4EE1BC --renderer-client-id=119 --mojo-platform-channel-handle=7052 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777567991690</Timestamp>
<BaseAddress>0xc00000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777567961139</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777569452751</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777567980184</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777567981270</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777567994943</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777570994535</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777570968696</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777570908362</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777570920904</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777570943637</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777570874151</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777570891841</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777568100773</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777570569484</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777570619251</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777570607590</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777570676211</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777570557202</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777570691164</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777570539079</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777569494420</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777570658737</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777569526517</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777569154123</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777570594964</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777570630821</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777570523174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777570582120</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777570646486</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777570953652</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777569213807</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777568156054</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777569481011</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777568142933</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777568179155</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777568043561</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777568042430</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777569239058</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777568075566</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777568073430</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777568086784</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777568041126</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777568081914</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777568046844</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777568038347</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777568088134</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777569468247</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777569466798</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777568077279</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777569469408</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777568024100</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777568039823</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777569470854</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777568036731</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777568054568</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777568078714</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777568050811</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777568084892</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777568089486</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777568083413</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777568044758</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777569464930</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777569463567</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777568116745</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777568080182</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777569457550</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777568052363</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777570632192</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777567961904</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777567961630</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>106</ProcessIndex>
<ProcessId>5556</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777595302537</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=3ADFA2396247AD5E547F61590603D06D --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=3ADFA2396247AD5E547F61590603D06D --renderer-client-id=121 --mojo-platform-channel-handle=6636 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777595490187</Timestamp>
<BaseAddress>0x1020000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595475498</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595491301</Timestamp>
<BaseAddress>0x5550000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777596381097</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595481485</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777595482474</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777595494304</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777597543015</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777597521210</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777597472595</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777597484525</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777597497517</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777597428793</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777597448444</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777595565558</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777597103476</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777597165296</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777597153510</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777597221087</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777597072535</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777597233493</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777597059294</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777596424202</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777597205195</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777596436120</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777596128973</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777597128037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777597177209</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777597044137</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777597116160</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777597192860</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777597506812</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777596148547</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777595627397</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777596410831</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777595610560</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777595638942</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777595529014</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777595527983</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777596182171</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777595541526</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777595540326</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777595551866</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777595526606</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777595547732</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777595531563</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777595524005</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777595553384</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777596396507</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777596394953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777595543299</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777596397607</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777595508927</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595525398</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777596398892</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777595522182</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777595538927</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777595544568</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777595535397</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777595550455</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777595554628</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777595549128</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777595530150</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777596393437</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777596392132</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777595583766</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777595545878</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777596385979</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777595536930</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777597178434</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777595476066</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777595475814</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>111</ProcessIndex>
<ProcessId>9032</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777895284069</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>explorer.exe</ProcessName>
<ImagePath>C:\Windows\explorer.exe</ImagePath>
<CommandLine>C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795777911330291</Timestamp>
<BaseAddress>0x4d80000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795777920515787</Timestamp>
<BaseAddress>0x6530000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\Microsoft Office\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795777903881315</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795777903867506</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795777895813346</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\explorer.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795777906005639</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\duser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795777922060868</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795777918507242</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795777907532495</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\System32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795777910997447</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795777915260331</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795777910978745</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\System32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795778008622616</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795778007235790</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\devrtl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795777909146457</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795777902950088</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\System32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795778007048279</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795777902932644</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795777909802797</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777909791020</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777917395017</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\linkinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795777918158137</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795777966565943</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795777908125051</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795777905900322</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\dui70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795777908270107</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795777922014669</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\System32\networkexplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795778007216762</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795777919764442</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795777915281766</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795777909775471</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795777910387599</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795777905243222</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795777919412503</Timestamp>
<BaseAddress>0x7ffac1710000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\amd64\FileSyncShell64.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795777904716802</Timestamp>
<BaseAddress>0x7ffac18b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg64.dll</Path>
<Version>1, 0, 0, 1140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795777944562485</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795777903915791</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777922001525</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795777903903305</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777909321798</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777909330655</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777906462233</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795777910949757</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795777920555307</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795777906356495</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795777905097743</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\System32\ExplorerFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795777908567233</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795777911007559</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795777914831974</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795777905390625</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777902894862</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795777906986296</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795777906995835</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795777903975733</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795777906257948</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795777919424461</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795777902880674</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777908138610</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795777902921260</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778008641775</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795777907005063</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795777918659102</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777918649579</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777909306748</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795777902905939</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795777906474194</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902941219</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795778008632518</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795777918171528</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795777907014508</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777903933947</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777902985171</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777903008375</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777902974089</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777905657867</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795777902999880</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777902852334</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777902849489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777902853126</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777902855116</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777902843222</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777902836309</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902838974</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777902841617</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777902844144</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777902848566</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777902824318</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777902854301</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777902835470</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902847555</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777902846521</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777902834719</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777916996283</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795777902838016</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777902833378</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777904879129</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777902823359</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777905449820</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795777920556415</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795777902842396</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777903888252</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777903413262</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777902840664</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777902837229</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777903887407</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795777902850328</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777903886124</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777902845086</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777902851375</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777895813598</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>115</ProcessIndex>
<ProcessId>13252</ProcessId>
<ParentProcessId>360</ParentProcessId>
<ParentProcessIndex>26</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131795777983764572</CreateTime>
<FinishTime>131795781000857179</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>AUDIODG.EXE</ProcessName>
<ImagePath>C:\Windows\system32\AUDIODG.EXE</ImagePath>
<CommandLine>C:\Windows\system32\AUDIODG.EXE 0x3f4</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Изоляция графов аудиоустройств Windows </Description>
<modulelist>
<module>
<Timestamp>131795777983831921</Timestamp>
<BaseAddress>0x7ff644450000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\System32\audiodg.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Изоляция графов аудиоустройств Windows </Description>
</module>
<module>
<Timestamp>131795777987657478</Timestamp>
<BaseAddress>0x7ffab0410000</BaseAddress>
<Size>1802240</Size>
<Path>C:\Windows\System32\WMALFXGFXDSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SysFx DSP</Description>
</module>
<module>
<Timestamp>131795777987006767</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\AudioSes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795777987325185</Timestamp>
<BaseAddress>0x7ffac13e0000</BaseAddress>
<Size>552960</Size>
<Path>C:\Windows\System32\AudioEng.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Audio Engine</Description>
</module>
<module>
<Timestamp>131795777988064426</Timestamp>
<BaseAddress>0x7ffac15d0000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\System32\AUDIOKSE.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Audio Ks Endpoint</Description>
</module>
<module>
<Timestamp>131795777987334885</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\avrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795777987120263</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795777985530541</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795777985553442</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777985542529</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\devobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795777985878753</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777987008327</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777985919594</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777985543302</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777985558083</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777985917139</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777985559169</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777985509811</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777985555822</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777985544141</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777985554295</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777985531383</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777985518799</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777986012477</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777985508789</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777985918125</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777985916103</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777985556758</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777985532267</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777983832182</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>118</ProcessIndex>
<ProcessId>11456</ProcessId>
<ParentProcessId>9032</ParentProcessId>
<ParentProcessIndex>111</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795778005314623</CreateTime>
<FinishTime>131795780493060245</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Wireshark-win64-2.6.2.exe</ProcessName>
<ImagePath>C:\Users\User\Downloads\Wireshark-win64-2.6.2.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\Downloads\Wireshark-win64-2.6.2.exe&quot; </CommandLine>
<CompanyName>Wireshark development team</CompanyName>
<Version>2.6.2.0</Version>
<Description>Wireshark installer for 64-bit Windows</Description>
<modulelist>
<module>
<Timestamp>131795778009231982</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>503808</Size>
<Path>C:\Users\User\Downloads\Wireshark-win64-2.6.2.exe</Path>
<Version>2.6.2.0</Version>
<Company>Wireshark development team</Company>
<Description>Wireshark installer for 64-bit Windows</Description>
</module>
<module>
<Timestamp>131795778009245222</Timestamp>
<BaseAddress>0x480000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778015682938</Timestamp>
<BaseAddress>0x2030000</BaseAddress>
<Size>36864</Size>
<Path>C:\Users\User\AppData\Local\Temp\nswB814.tmp\InstallOptions.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795778014254891</Timestamp>
<BaseAddress>0x10000000</BaseAddress>
<Size>24576</Size>
<Path>C:\Users\User\AppData\Local\Temp\nswB814.tmp\System.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795778009238221</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795778009238911</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795778009248228</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795778011325628</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795778089634780</Timestamp>
<BaseAddress>0x6b7b0000</BaseAddress>
<Size>503808</Size>
<Path>C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795778014814877</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\riched20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795780324262128</Timestamp>
<BaseAddress>0x6eb70000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795780325637135</Timestamp>
<BaseAddress>0x6fd20000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795780321590840</Timestamp>
<BaseAddress>0x70190000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\linkinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795778010985816</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795778014835906</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795780324994498</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795778011360794</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795778011372913</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795778014843868</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795778011346828</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795778011030934</Timestamp>
<BaseAddress>0x72510000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\shfolder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Folder Service</Description>
</module>
<module>
<Timestamp>131795778010950569</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778010974639</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778010712877</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795778011384519</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778009666389</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795778011008939</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795778010727286</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795778009272418</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795778009635084</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795778009634444</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795778009721108</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795778009632885</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778009632164</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778009640473</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778009633660</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778009627476</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778011330122</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795778009629360</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778009641448</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778010997934</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778011330953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778009637786</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778014972924</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795778009254650</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778009636664</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778009638589</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778009631391</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778009639548</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778009628515</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778010731370</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795778009625102</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778009642327</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778009624246</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778009635799</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778010952511</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778010951613</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778009648281</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795778009626440</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778015684351</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795778009630333</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778009232688</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795778009232417</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>122</ProcessIndex>
<ProcessId>9112</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778233163324</CreateTime>
<FinishTime>131795780247575416</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>vssvc.exe</ProcessName>
<ImagePath>C:\Windows\system32\vssvc.exe</ImagePath>
<CommandLine>C:\Windows\system32\vssvc.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Microsoft® Volume Shadow Copy Service</Description>
<modulelist>
<module>
<Timestamp>131795778233223054</Timestamp>
<BaseAddress>0x7ff69d210000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\VSSVC.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service</Description>
</module>
<module>
<Timestamp>131795778236960155</Timestamp>
<BaseAddress>0x7ffac1690000</BaseAddress>
<Size>516096</Size>
<Path>C:\Windows\System32\catsrvut.dll</Path>
<Version>2001.12.10941.16384 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog Server Utilities</Description>
</module>
<module>
<Timestamp>131795778235339682</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795778235353194</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fltLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795778236101503</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795778235330886</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\virtdisk.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Disk API DLL</Description>
</module>
<module>
<Timestamp>131795778236181536</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795778235312630</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\vsstrace.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795778235292965</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\System32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795778236970418</Timestamp>
<BaseAddress>0x7ffac7e80000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\mfcsubs.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795778235749019</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795778236589454</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778236331302</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\samlib.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795778235302884</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\devobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795778235322056</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\authz.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795778236321713</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795778235650165</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778235659934</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778235271662</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778235274566</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778235658261</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778236590535</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778235260874</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778235271000</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778235303684</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778235270235</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778235273593</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778235268950</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778235730902</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778235259923</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778235659139</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778235293960</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778235657454</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778235272840</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778235277370</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778235275560</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778233223370</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>123</ProcessIndex>
<ProcessId>284</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778236890994</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k swprv</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795778236948261</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795778237990704</Timestamp>
<BaseAddress>0x7ffabd220000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\System32\swprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик программного обеспечения Microsoft® Volume Shadow Copy Service</Description>
</module>
<module>
<Timestamp>131795778238024341</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fltLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795778238689559</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795778238016772</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\virtdisk.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Disk API DLL</Description>
</module>
<module>
<Timestamp>131795778238009807</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\vsstrace.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795778238797239</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\System32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795778238379317</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795778238002742</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\devobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795778238084884</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795778238106525</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778238119208</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778237848893</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778238069532</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778238117518</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778238087879</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778237826515</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778238085768</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778238691232</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778238003645</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778238690445</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778237846089</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778237991665</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778238360028</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778237825108</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778238118419</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778238798278</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778238116693</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778238067953</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778237992699</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778237844499</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778236948497</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>124</ProcessIndex>
<ProcessId>8572</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778253406568</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>msiexec.exe</ProcessName>
<ImagePath>C:\Windows\system32\msiexec.exe</ImagePath>
<CommandLine>C:\Windows\system32\msiexec.exe /V</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Установщик Windows®</Description>
<modulelist>
<module>
<Timestamp>131795778259596194</Timestamp>
<BaseAddress>0x238870a0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\System32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778253563850</Timestamp>
<BaseAddress>0x7ff766ba0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\msiexec.exe</Path>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Установщик Windows®</Description>
</module>
<module>
<Timestamp>131795778259570059</Timestamp>
<BaseAddress>0x7ffaad900000</BaseAddress>
<Size>4726784</Size>
<Path>C:\Windows\AppPatch\apppatch64\AcLayers.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795778267501772</Timestamp>
<BaseAddress>0x7ffab1260000</BaseAddress>
<Size>10350592</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll</Path>
<Version>4.7.2117.0 built by: NET47REL1LAST</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Common Language Runtime - WorkStation</Description>
</module>
<module>
<Timestamp>131795778276928618</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\devrtl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795778275324308</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795778275333446</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795778259610277</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795778259661596</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778265457583</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795778267747643</Timestamp>
<BaseAddress>0x7ffabfa00000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\msvcr120_clr0400.dll</Path>
<Version>12.00.52519.0 built by: VSWINSERVICING</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778260359664</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795778399983100</Timestamp>
<BaseAddress>0x7ffac1010000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\System32\mscoree.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795778400005719</Timestamp>
<BaseAddress>0x7ffac1240000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll</Path>
<Version>4.7.2623.0 built by: NET471REL1LAST_C</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795778262571338</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795778267189195</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795778417041748</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795778400053783</Timestamp>
<BaseAddress>0x7ffac5b30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Assembly manager</Description>
</module>
<module>
<Timestamp>131795778259951873</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795778264680084</Timestamp>
<BaseAddress>0x7ffac7cc0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\msisip.dll</Path>
<Version>5.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSI Signature SIP Provider</Description>
</module>
<module>
<Timestamp>131795778265630538</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795778262583238</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795778323770185</Timestamp>
<BaseAddress>0x7ffac97f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\perfproc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов производительности системных процессов Windows</Description>
</module>
<module>
<Timestamp>131795778272914974</Timestamp>
<BaseAddress>0x7ffaca210000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\RstrtMgr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер перезапуска</Description>
</module>
<module>
<Timestamp>131795778281798291</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778259533909</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795778265279256</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795778264074461</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795778264625720</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795778265470245</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795778262605488</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795778261744074</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795778264613136</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795778264639501</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795778273070150</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795778272956330</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795778261891434</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795778259633594</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778260278752</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778260602827</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778260604728</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778264076719</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795778259576609</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778259578595</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778259572597</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778264077537</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778260603797</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778260601744</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778259515815</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778264075791</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778272946115</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778260600162</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778260598868</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778272945223</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778262622754</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795778259577351</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778265716961</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795778259571021</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778260302861</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778259514798</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778276914178</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795778259573318</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778259571855</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778259575900</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778259912248</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778259914551</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795778259575080</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778259913185</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778253564149</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>128</ProcessIndex>
<ProcessId>12664</ProcessId>
<ParentProcessId>11456</ParentProcessId>
<ParentProcessIndex>118</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795778472532085</CreateTime>
<FinishTime>131795780252629767</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>WinPcap_4_1_3.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\WinPcap_4_1_3.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\WinPcap_4_1_3.exe&quot;</CommandLine>
<CompanyName>Riverbed Technology, Inc.</CompanyName>
<Version>4.1.0.2980</Version>
<Description>WinPcap 4.1.3 installer</Description>
<modulelist>
<module>
<Timestamp>131795778474370909</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Wireshark\WinPcap_4_1_3.exe</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>WinPcap 4.1.3 installer</Description>
</module>
<module>
<Timestamp>131795780215605526</Timestamp>
<BaseAddress>0x480000</BaseAddress>
<Size>24576</Size>
<Path>C:\Users\User\AppData\Local\Temp\nsy6E15.tmp\System.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780223446317</Timestamp>
<BaseAddress>0x700000</BaseAddress>
<Size>20480</Size>
<Path>C:\Users\User\AppData\Local\Temp\nsy6E15.tmp\ExecDos.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795778481441454</Timestamp>
<BaseAddress>0x10000000</BaseAddress>
<Size>36864</Size>
<Path>C:\Users\User\AppData\Local\Temp\nsy6E15.tmp\InstallOptions.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795778474378741</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795778474379428</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795778474388380</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795778478947902</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795778475429642</Timestamp>
<BaseAddress>0x66680000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778475455924</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778476129447</Timestamp>
<BaseAddress>0x68890000</BaseAddress>
<Size>2506752</Size>
<Path>C:\Windows\AppPatch\AcGenral.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795778474677141</Timestamp>
<BaseAddress>0x6b830000</BaseAddress>
<Size>2584576</Size>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795778480464294</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\riched20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795778477256204</Timestamp>
<BaseAddress>0x6e070000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\msacm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795778475437968</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795778476670529</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795778480530862</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795778478980362</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795778478991569</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795778480522492</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795778478967471</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795778479094944</Timestamp>
<BaseAddress>0x72510000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\shfolder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Folder Service</Description>
</module>
<module>
<Timestamp>131795778477334993</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795778479412597</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778477303386</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778477311770</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795778476643968</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795778475447551</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778477321345</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795778476661893</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795778478915573</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795778477286525</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795778477294825</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795778475176915</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795778474424278</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795778475146383</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795778475145740</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795778478799256</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795778475144147</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778475143114</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778475151896</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778475144928</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778475139437</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778478951681</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795778475135689</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778475152658</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778479395683</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778478952460</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778475149237</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778480549998</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795778474394583</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778475147716</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778475150048</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778475142341</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778475150968</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778475140388</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778475156318</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795778475137512</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778475153528</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778475136714</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778475147048</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778475155357</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778475154692</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778476634451</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795778475138620</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778481442448</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795778475141404</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778474371565</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795778474371291</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>132</ProcessIndex>
<ProcessId>5748</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778806993759</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k wsappx</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795778807042136</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795778809771371</Timestamp>
<BaseAddress>0x7ffaafc30000</BaseAddress>
<Size>2297856</Size>
<Path>C:\Windows\System32\AppXDeploymentServer.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера развертывания AppX</Description>
</module>
<module>
<Timestamp>131795778810217417</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795778809793544</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fltLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795778809909001</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795778810725123</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795778810201985</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795778809816672</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795778809822524</Timestamp>
<BaseAddress>0x7ffacb720000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\mintdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795778809799027</Timestamp>
<BaseAddress>0x7ffacb820000</BaseAddress>
<Size>712704</Size>
<Path>C:\Windows\System32\tdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795778810317823</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795778809809854</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795778810208064</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778809594468</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778809776574</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778809778372</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795778809607454</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778809572087</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778809580973</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778809605642</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778810318817</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778809772360</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778809561432</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778809777533</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778809774521</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778809773756</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778809570735</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778809595255</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778810493271</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778809560537</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778809606459</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778809600563</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778809580022</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778809775513</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778809569904</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778807042435</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>133</ProcessIndex>
<ProcessId>3432</ProcessId>
<ParentProcessId>12664</ParentProcessId>
<ParentProcessIndex>128</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795780225629048</CreateTime>
<FinishTime>131795780237553222</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>net.exe</ProcessName>
<ImagePath>C:\Windows\SysWOW64\net.exe</ImagePath>
<CommandLine>net start npf</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Net Command</Description>
<modulelist>
<module>
<Timestamp>131795780226910532</Timestamp>
<BaseAddress>0x170000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\net.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Command</Description>
</module>
<module>
<Timestamp>131795780226926637</Timestamp>
<BaseAddress>0x32a0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780226917769</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795780226918627</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795780226929419</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795780230647131</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795780230656119</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795780230633877</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795780230624296</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795780230698730</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780230710430</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780230615508</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795780230571969</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795780230604972</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780230604257</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780230625308</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780230603279</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780230599638</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780226936362</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780230602268</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780230601348</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780226935132</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780230605861</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780226911103</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795780226910839</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>134</ProcessIndex>
<ProcessId>628</ProcessId>
<ParentProcessId>3432</ParentProcessId>
<ParentProcessIndex>133</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795780228710407</CreateTime>
<FinishTime>131795780238003474</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Conhost.exe</ProcessName>
<ImagePath>C:\Windows\System32\Conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795780228712258</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795780229733719</Timestamp>
<BaseAddress>0x7ffabe520000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795780230451316</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780229763613</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780230409173</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780230230071</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780230209305</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780230206332</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780230210092</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780229746494</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780229742189</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780229744103</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780229748137</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780229765511</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780230205374</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780229710233</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780229750423</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780230204254</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780230202886</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780229749730</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780229742956</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780229718534</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780229709333</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780230388633</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795780229745098</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780229748941</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780229747436</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780229741377</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780230207188</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780230208410</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780229764675</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780228712496</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>135</ProcessIndex>
<ProcessId>10452</ProcessId>
<ParentProcessId>3432</ParentProcessId>
<ParentProcessIndex>133</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795780234304124</CreateTime>
<FinishTime>131795780237516174</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>net1.exe</ProcessName>
<ImagePath>C:\Windows\SysWOW64\net1.exe</ImagePath>
<CommandLine>C:\Windows\system32\net1 start npf</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Net Command</Description>
<modulelist>
<module>
<Timestamp>131795780234380464</Timestamp>
<BaseAddress>0xe80000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SysWOW64\net1.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Command</Description>
</module>
<module>
<Timestamp>131795780234400728</Timestamp>
<BaseAddress>0x3200000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780234401906</Timestamp>
<BaseAddress>0x3330000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780234392134</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795780234393004</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795780234404560</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795780235692217</Timestamp>
<BaseAddress>0x6d050000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795780235114117</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795780235142260</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795780235123634</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795780235150799</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795780235241635</Timestamp>
<BaseAddress>0x72500000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\dsrole.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795780235505669</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780235097962</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780235101860</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780235115114</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780235100915</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780235095380</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780234411941</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780235099987</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780234410569</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780235099056</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780234381135</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795780234380880</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>136</ProcessIndex>
<ProcessId>9796</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795780239620520</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchProtocolHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchProtocolHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchProtocolHost.exe&quot; Global\UsGthrFltPipeMssGthrPipe287_ Global\UsGthrCtrlFltPipeMssGthrPipe287 1 -2147483646 &quot;Software\Microsoft\Windows Search&quot; &quot;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)&quot; &quot;C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc&quot; &quot;DownLevelDaemon&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Protocol Host</Description>
<modulelist>
<module>
<Timestamp>131795780239737964</Timestamp>
<BaseAddress>0x7ff71ad80000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\SearchProtocolHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Protocol Host</Description>
</module>
<module>
<Timestamp>131795780369815326</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\System32\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795780418459536</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795780240300022</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\System32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795780243315314</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795780243903335</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795780441683903</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\linkinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795780243600064</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795780427898780</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780243436640</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795780430442742</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795780410780027</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795780241991790</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795780410796187</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780431995807</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780410763398</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780417487601</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780413476937</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780242057291</Timestamp>
<BaseAddress>0x7ffac7cd0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\mssph.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик протоколов поиска Microsoft</Description>
</module>
<module>
<Timestamp>131795780240397027</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795780412021532</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795780242909541</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780369785371</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795780242712385</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795780242660417</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\authz.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795780412012220</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795780243425796</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780412832818</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780240244868</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780240240128</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780240251850</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780240242580</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780240232121</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780240234675</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780240244079</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780240238319</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780240239247</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780240221401</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780240231486</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780243144631</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780243143464</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780240230763</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780240233764</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780240229489</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780240634076</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780240220498</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780240241837</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780240368757</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780240243394</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780240233035</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780240236451</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780241097467</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780240240989</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780240237313</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780239738429</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>137</ProcessIndex>
<ProcessId>12508</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795780241037362</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchFilterHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchFilterHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchFilterHost.exe&quot; 0 708 712 720 8192 716 </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Filter Host</Description>
<modulelist>
<module>
<Timestamp>131795780241063145</Timestamp>
<BaseAddress>0x7ff68a750000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\SearchFilterHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Filter Host</Description>
</module>
<module>
<Timestamp>131795780247134349</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\System32\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795780241521132</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\System32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795780248688938</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795780241889503</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795780248698505</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780248678892</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780336696287</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780248844250</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795780369734185</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780248709490</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795780245297442</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795780248857657</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780241586648</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780248634862</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780248647646</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780241557344</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780241423082</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780241426099</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780241555681</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780241892382</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780248633959</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780241412105</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780241422398</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780248632826</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780248631779</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780241421633</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780241424805</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780241420314</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780241785125</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780241411149</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780241556540</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780241553299</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780241554210</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780241423999</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780241427039</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780248630299</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780248623921</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780241505282</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780241063419</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>138</ProcessIndex>
<ProcessId>12816</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780328696510</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>backgroundTaskHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\backgroundTaskHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\backgroundTaskHost.exe&quot; -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Background Task Host</Description>
<modulelist>
<module>
<Timestamp>131795780329749381</Timestamp>
<BaseAddress>0x7ff6c9470000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\backgroundTaskHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Task Host</Description>
</module>
<module>
<Timestamp>131795780412645902</Timestamp>
<BaseAddress>0x7ffab52c0000</BaseAddress>
<Size>2445312</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780458670386</Timestamp>
<BaseAddress>0x7ffab5db0000</BaseAddress>
<Size>9781248</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780430264262</Timestamp>
<BaseAddress>0x7ffab9d50000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780415005192</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795780669717689</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795780455059889</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795780464027032</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795780460179577</Timestamp>
<BaseAddress>0x7ffabe770000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780426479724</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795780434238517</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795780444160476</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795780435161488</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795780414048080</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795780336747714</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795780431439143</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795780415109582</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795780447463685</Timestamp>
<BaseAddress>0x7ffac37b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795780458880946</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795780431346631</Timestamp>
<BaseAddress>0x7ffac3bf0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionMgr.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana Action Manager</Description>
</module>
<module>
<Timestamp>131795780454034058</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780439433205</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795780439202248</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795780453275113</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795780414060032</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795780412035947</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795780417041804</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795780335537874</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795780440780442</Timestamp>
<BaseAddress>0x7ffac6bb0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\Windows.Cortana.PAL.Desktop.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.PAL.Desktop</Description>
</module>
<module>
<Timestamp>131795780334206479</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795780412505075</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795780431250324</Timestamp>
<BaseAddress>0x7ffac7c50000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\BingConfigurationClient.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bing Configuration Client DLL</Description>
</module>
<module>
<Timestamp>131795780734626399</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795780460761885</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795780330302623</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795780735708696</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795780456573704</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780353237616</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795780329775228</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795780354090093</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780414037017</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795780329952250</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795780416468722</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795780458075843</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795780416610948</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780417362058</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780416587207</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780416598309</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780329987780</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780329937663</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780440064693</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780334214070</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780416574039</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780332551041</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780329815850</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780329817545</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780332549409</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780330307702</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780440061460</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780329756590</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780416541236</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780415545554</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780415544634</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780329816609</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780329812830</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780329755673</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780332550210</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780416575003</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780332564758</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780332548246</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780329814985</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780414009539</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780461878432</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780440069381</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780329975442</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780329749700</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>139</ProcessIndex>
<ProcessId>9096</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780345290303</CreateTime>
<FinishTime>131795780401278955</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795780345573177</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795780348240345</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795780348272478</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780348029043</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780346945095</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780347808033</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780346919647</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780346922645</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780347731424</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780348251926</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780346910446</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780348274285</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780348273434</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780346921678</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780346945926</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780346951259</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780346909501</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780347732333</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780347843368</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780347725833</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780346920866</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780347218701</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780345573504</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>140</ProcessIndex>
<ProcessId>10548</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780480985741</CreateTime>
<FinishTime>131795780542565974</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795780481001553</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795780490611931</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795780490332304</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\System32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795780481418375</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795780490519093</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795780481441631</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780481360002</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780481044679</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780481254937</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780481018489</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780481021276</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780481253383</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780481419248</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780481009961</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780481443418</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780481442584</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780481020378</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780481045463</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780481050544</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780481009080</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780481254203</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780481272184</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780481252571</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780481019630</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780481215653</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780481001785</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>141</ProcessIndex>
<ProcessId>4416</ProcessId>
<ParentProcessId>904</ParentProcessId>
<ParentProcessIndex>22</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795780514347741</CreateTime>
<FinishTime>131795781004090841</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>compattelrunner.exe</ProcessName>
<ImagePath>C:\Windows\system32\compattelrunner.exe</ImagePath>
<CommandLine>C:\Windows\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Description>Microsoft Compatibility Telemetry</Description>
<modulelist>
<module>
<Timestamp>131795780514361835</Timestamp>
<BaseAddress>0x7ff70d700000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\CompatTelRunner.exe</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Compatibility Telemetry</Description>
</module>
<module>
<Timestamp>131795780522700638</Timestamp>
<BaseAddress>0x7ffaafa00000</BaseAddress>
<Size>2240512</Size>
<Path>C:\Windows\System32\OpcServices.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Native Code OPC Services Library</Description>
</module>
<module>
<Timestamp>131795780522152025</Timestamp>
<BaseAddress>0x7ffababa0000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\System32\AppxPackaging.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пакетов машинного кода Appx</Description>
</module>
<module>
<Timestamp>131795780518192285</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795780519285351</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795780526644057</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795780517476435</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795780517083301</Timestamp>
<BaseAddress>0x7ffac1660000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\System32\aeinv.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Inventory Component</Description>
</module>
<module>
<Timestamp>131795780522718984</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780517734774</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780517488909</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795780537308307</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795780537245894</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795780516975529</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795780519923937</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780534738440</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795780519489095</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795780517766654</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795780516985179</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780517465971</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780517465170</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780517467459</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780534262934</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780516955127</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780516950237</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780516951894</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780516956687</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780517466672</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780517464292</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780515134971</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780534261862</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780516958252</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780517463322</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780517462206</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780516957529</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780516950982</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780516947569</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780518177038</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780515134073</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780516954224</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780516955947</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780516949497</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780516960050</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780516948721</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780516959141</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780516952719</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780514362068</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>142</ProcessIndex>
<ProcessId>12684</ProcessId>
<ParentProcessId>4416</ParentProcessId>
<ParentProcessIndex>141</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795780515368679</CreateTime>
<FinishTime>131795781004122026</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>Conhost.exe</ProcessName>
<ImagePath>C:\Windows\System32\Conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795780515888821</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795780515919012</Timestamp>
<BaseAddress>0x7ffabe520000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795780516232908</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780516652172</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780516649553</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780516657375</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780516215409</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780516211528</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780516213284</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780516216875</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780516234504</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780516648714</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780515894958</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780516218956</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780516647725</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780516646589</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780516218299</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780516212262</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780515904489</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780515894121</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780516214650</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780516217581</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780516216177</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780516210780</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780516650349</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780516651202</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780516233739</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780515889062</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>143</ProcessIndex>
<ProcessId>10640</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780604526348</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>backgroundTaskHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\backgroundTaskHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\backgroundTaskHost.exe&quot; -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Background Task Host</Description>
<modulelist>
<module>
<Timestamp>131795780604942096</Timestamp>
<BaseAddress>0x7ff6c9470000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\backgroundTaskHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Task Host</Description>
</module>
<module>
<Timestamp>131795780982599698</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2936832</Size>
<Path>C:\Windows\System32\CertEnroll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент регистрации служб сертификатов Active Directory Microsoft®</Description>
</module>
<module>
<Timestamp>131795780624085064</Timestamp>
<BaseAddress>0x7ffaad5b0000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentDeliveryManager.Background.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780633868268</Timestamp>
<BaseAddress>0x7ffaadf00000</BaseAddress>
<Size>2260992</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentManagementSDK.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780984186979</Timestamp>
<BaseAddress>0x7ffab1dc0000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\certca.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ЦС служб сертификации Microsoft® Active Directory</Description>
</module>
<module>
<Timestamp>131795780989018507</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795780638521291</Timestamp>
<BaseAddress>0x7ffab8f60000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\CryptoWinRT.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto WinRT Library</Description>
</module>
<module>
<Timestamp>131795780656495804</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795780968504887</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795780965909656</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795780850515848</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795780881658829</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795780632764734</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795780627995893</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795780626074133</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795780637000038</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795780979874979</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795780639367373</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795780949324967</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780638058893</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795780979208878</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795780624149045</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795780641809268</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795780979197823</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780606360545</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795780918011378</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795780971614143</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780631634537</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780624161030</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795780642339398</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795780642310850</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795780631607870</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795780972492970</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795780622245977</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795780965988464</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795780966015364</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795780606285280</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795780983258989</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\dsparse.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795780605748575</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795780624526113</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795780622740074</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795780624112925</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\slc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795780626644547</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795780975579967</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795780968868492</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795780626601326</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795780605036791</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795780630151168</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795780634233098</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780621646470</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795780621784723</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780624171938</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795780605004500</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795780624123309</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795780967018140</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795780644959783</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795780966160644</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795780977616543</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795780979753360</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795780979288601</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795780966000176</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780971557025</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795780967499686</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795780968849434</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795780979741934</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780640855968</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780639253750</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780639155938</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780624100929</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780605016566</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780604988979</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780634211474</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780606271616</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780882167263</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780605130292</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780604960936</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780604962598</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780605128610</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780979290330</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795780605041481</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780634210377</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780604949997</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780882158799</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780624152029</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780624151198</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780604961659</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780968869207</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795780604958974</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780604949078</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780985065294</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\Wldap32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795780605129419</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780965914856</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780605144205</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780605127632</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780604960157</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780624086344</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780634212438</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780605005539</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780604942528</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>144</ProcessIndex>
<ProcessId>12892</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780695167004</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Wireshark.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\Wireshark.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\Wireshark.exe&quot; </CommandLine>
<CompanyName>The Wireshark developer community, http://www.wireshark.org/</CompanyName>
<Version>2.6.2</Version>
<Description>Wireshark</Description>
<modulelist>
<module>
<Timestamp>131795780706141890</Timestamp>
<BaseAddress>0xbd0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\libwinpthread-1.dll</Path>
<Version>1, 0, 0, 0</Version>
<Company>MingW-W64 Project. All rights reserved.</Company>
<Description>POSIX WinThreads for Windows</Description>
</module>
<module>
<Timestamp>131795780721765742</Timestamp>
<BaseAddress>0xbf0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\k5sprt64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>Kerberos v5 support - internal support code for MIT Kerberos v5 /GSS distribution</Description>
</module>
<module>
<Timestamp>131795780722106261</Timestamp>
<BaseAddress>0xc00000</BaseAddress>
<Size>45056</Size>
<Path>C:\Program Files\Wireshark\comerr64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>COM_ERR - Common Error Handler for MIT Kerberos v5 / GSS distribution</Description>
</module>
<module>
<Timestamp>131795780719731475</Timestamp>
<BaseAddress>0x1c000000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\krb5_64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>Kerberos v5 - MIT GSS / Kerberos v5 distribution</Description>
</module>
<module>
<Timestamp>131795780773060331</Timestamp>
<BaseAddress>0x5af30000</BaseAddress>
<Size>348160</Size>
<Path>C:\Program Files\Wireshark\Qt5Svg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780721210805</Timestamp>
<BaseAddress>0x5af90000</BaseAddress>
<Size>1286144</Size>
<Path>C:\Program Files\Wireshark\libxml2-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780696840198</Timestamp>
<BaseAddress>0x5b0d0000</BaseAddress>
<Size>5865472</Size>
<Path>C:\Program Files\Wireshark\Qt5Core.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780696801039</Timestamp>
<BaseAddress>0x5b670000</BaseAddress>
<Size>5619712</Size>
<Path>C:\Program Files\Wireshark\Qt5Widgets.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780721068755</Timestamp>
<BaseAddress>0x5bcf0000</BaseAddress>
<Size>733184</Size>
<Path>C:\Program Files\Wireshark\libsmi-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720701584</Timestamp>
<BaseAddress>0x5bdb0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Program Files\Wireshark\liblz4.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720048995</Timestamp>
<BaseAddress>0x5bdf0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Program Files\Wireshark\libcares-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780701085625</Timestamp>
<BaseAddress>0x5be10000</BaseAddress>
<Size>122880</Size>
<Path>C:\Program Files\Wireshark\libbcg729.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700086118</Timestamp>
<BaseAddress>0x5be30000</BaseAddress>
<Size>1261568</Size>
<Path>C:\Program Files\Wireshark\Qt5Network.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780701499544</Timestamp>
<BaseAddress>0x61cc0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Wireshark\libintl-8.dll</Path>
<Version>0.18.1</Version>
<Company>Free Software Foundation</Company>
<Description>LGPLed libintl for Windows NT/2000/XP/Vista/7 and Windows 95/98/ME</Description>
</module>
<module>
<Timestamp>131795780704834900</Timestamp>
<BaseAddress>0x646c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libgpg-error6-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780703191110</Timestamp>
<BaseAddress>0x64840000</BaseAddress>
<Size>1220608</Size>
<Path>C:\Program Files\Wireshark\libgnutls-30.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720700188</Timestamp>
<BaseAddress>0x64a00000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\lua52.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780702785552</Timestamp>
<BaseAddress>0x653c0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\libgcrypt-20.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780706408972</Timestamp>
<BaseAddress>0x65f00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Program Files\Wireshark\libtasn1-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705520711</Timestamp>
<BaseAddress>0x66f00000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Wireshark\libhogweed-4-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780696518462</Timestamp>
<BaseAddress>0x685c0000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Program Files\Wireshark\libglib-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GLib</Description>
</module>
<module>
<Timestamp>131795780706610973</Timestamp>
<BaseAddress>0x68ec0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\Wireshark\libp11-kit-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720967901</Timestamp>
<BaseAddress>0x69340000</BaseAddress>
<Size>815104</Size>
<Path>C:\Program Files\Wireshark\libsnappy-1.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705423287</Timestamp>
<BaseAddress>0x69c80000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\libnettle-6-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700701891</Timestamp>
<BaseAddress>0x6a680000</BaseAddress>
<Size>122880</Size>
<Path>C:\Program Files\Wireshark\libsbc-1.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705248323</Timestamp>
<BaseAddress>0x6acc0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files\Wireshark\libgmp-10.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780707311684</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\libffi-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700957949</Timestamp>
<BaseAddress>0x6d7c0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files\Wireshark\libspandsp-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720746780</Timestamp>
<BaseAddress>0x6dc80000</BaseAddress>
<Size>167936</Size>
<Path>C:\Program Files\Wireshark\libnghttp2-14.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780698864675</Timestamp>
<BaseAddress>0x6dd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\Wireshark\libgmodule-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GModule</Description>
</module>
<module>
<Timestamp>131795780759720376</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\wpcap.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008)</Description>
</module>
<module>
<Timestamp>131795780760417804</Timestamp>
<BaseAddress>0x190ac770000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795780695991379</Timestamp>
<BaseAddress>0x7ff7f1130000</BaseAddress>
<Size>8298496</Size>
<Path>C:\Program Files\Wireshark\Wireshark.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark</Description>
</module>
<module>
<Timestamp>131795780718751145</Timestamp>
<BaseAddress>0x7ffaa6f50000</BaseAddress>
<Size>64282624</Size>
<Path>C:\Program Files\Wireshark\libwireshark.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark dissector library</Description>
</module>
<module>
<Timestamp>131795780697272337</Timestamp>
<BaseAddress>0x7ffaaaca0000</BaseAddress>
<Size>6094848</Size>
<Path>C:\Program Files\Wireshark\Qt5Gui.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896758694</Timestamp>
<BaseAddress>0x7ffab1e90000</BaseAddress>
<Size>593920</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimax.dll</Path>
<Version>1.2.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimax dissector</Description>
</module>
<module>
<Timestamp>131795780766458881</Timestamp>
<BaseAddress>0x7ffab1f30000</BaseAddress>
<Size>614400</Size>
<Path>C:\Windows\System32\riched20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795780699399720</Timestamp>
<BaseAddress>0x7ffab2280000</BaseAddress>
<Size>1916928</Size>
<Path>C:\Program Files\Wireshark\WinSparkle.dll</Path>
<Version>0.5.7</Version>
<Company>winsparkle.org</Company>
<Description>WinSparkle updater</Description>
</module>
<module>
<Timestamp>131795780771263589</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795780765326722</Timestamp>
<BaseAddress>0x7ffab9010000</BaseAddress>
<Size>1388544</Size>
<Path>C:\Program Files\Wireshark\platforms\qwindows.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896746168</Timestamp>
<BaseAddress>0x7ffab9b10000</BaseAddress>
<Size>135168</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\unistim.dll</Path>
<Version>0.0.2.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>unistim dissector</Description>
</module>
<module>
<Timestamp>131795780896708383</Timestamp>
<BaseAddress>0x7ffabaef0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\profinet.dll</Path>
<Version>0.2.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>profinet dissector</Description>
</module>
<module>
<Timestamp>131795780773615377</Timestamp>
<BaseAddress>0x7ffabb070000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files\Wireshark\imageformats\qwebp.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780702318544</Timestamp>
<BaseAddress>0x7ffabb0f0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780773096445</Timestamp>
<BaseAddress>0x7ffabb250000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files\Wireshark\imageformats\qtiff.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896696149</Timestamp>
<BaseAddress>0x7ffabc110000</BaseAddress>
<Size>237568</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\opcua.dll</Path>
<Version>1.0.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>opcua dissector</Description>
</module>
<module>
<Timestamp>131795780696290907</Timestamp>
<BaseAddress>0x7ffabc150000</BaseAddress>
<Size>729088</Size>
<Path>C:\Program Files\Wireshark\Qt5Multimedia.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780699299849</Timestamp>
<BaseAddress>0x7ffabcbb0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Program Files\Wireshark\libwiretap.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark capture file library</Description>
</module>
<module>
<Timestamp>131795780702235327</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795780699512168</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795780773039075</Timestamp>
<BaseAddress>0x7ffabe940000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\imageformats\qjpeg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896684027</Timestamp>
<BaseAddress>0x7ffabeb80000</BaseAddress>
<Size>163840</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\mate.dll</Path>
<Version>1.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>mate dissector</Description>
</module>
<module>
<Timestamp>131795780767100288</Timestamp>
<BaseAddress>0x7ffabebb0000</BaseAddress>
<Size>233472</Size>
<Path>C:\Windows\System32\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795780967804060</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795780703722010</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780896660120</Timestamp>
<BaseAddress>0x7ffabf990000</BaseAddress>
<Size>135168</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\gryphon.dll</Path>
<Version>0.0.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>gryphon dissector</Description>
</module>
<module>
<Timestamp>131795780896781202</Timestamp>
<BaseAddress>0x7ffabff40000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimaxmacphy.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimaxmacphy dissector</Description>
</module>
<module>
<Timestamp>131795780975772674</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795780967709675</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780896602379</Timestamp>
<BaseAddress>0x7ffac0b10000</BaseAddress>
<Size>180224</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\ethercat.dll</Path>
<Version>0.1.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>ethercat dissector</Description>
</module>
<module>
<Timestamp>131795780696305369</Timestamp>
<BaseAddress>0x7ffac12f0000</BaseAddress>
<Size>585728</Size>
<Path>C:\Program Files\Wireshark\Qt5WinExtras.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780696268510</Timestamp>
<BaseAddress>0x7ffac1380000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files\Wireshark\Qt5PrintSupport.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896769846</Timestamp>
<BaseAddress>0x7ffac1640000</BaseAddress>
<Size>81920</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimaxasncp.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimaxasncp dissector</Description>
</module>
<module>
<Timestamp>131795780703633136</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\zlib1.dll</Path>
<Version>1.2.11</Version>
<Company></Company>
<Description>zlib data compression library</Description>
</module>
<module>
<Timestamp>131795780968289847</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795780896672499</Timestamp>
<BaseAddress>0x7ffac21f0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\irda.dll</Path>
<Version>0.0.6.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>irda dissector</Description>
</module>
<module>
<Timestamp>131795780943468609</Timestamp>
<BaseAddress>0x7ffac2950000</BaseAddress>
<Size>32768</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\codecs\l16mono.dll</Path>
<Version>0.1.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>l16mono dissector</Description>
</module>
<module>
<Timestamp>131795780696778265</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780698025500</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libwsutil.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark utility library</Description>
</module>
<module>
<Timestamp>131795780964290332</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780896734845</Timestamp>
<BaseAddress>0x7ffac3730000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\transum.dll</Path>
<Version>2.0.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>transum dissector</Description>
</module>
<module>
<Timestamp>131795780962958391</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780891504201</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795780896719593</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\stats_tree.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>stats_tree dissector</Description>
</module>
<module>
<Timestamp>131795780893701095</Timestamp>
<BaseAddress>0x7ffac4c50000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\wiretap\usbdump.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>usbdump dissector</Description>
</module>
<module>
<Timestamp>131795780891269455</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795780965552062</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795780963571749</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795780963646684</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795780773109195</Timestamp>
<BaseAddress>0x7ffac6aa0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qwbmp.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773083338</Timestamp>
<BaseAddress>0x7ffac6ab0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qtga.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780700311672</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780700270884</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780773051219</Timestamp>
<BaseAddress>0x7ffac7710000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qsvg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773027062</Timestamp>
<BaseAddress>0x7ffac7c70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\imageformats\qico.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773014999</Timestamp>
<BaseAddress>0x7ffac7cc0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files\Wireshark\imageformats\qicns.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773002354</Timestamp>
<BaseAddress>0x7ffac7e80000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\imageformats\qgif.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780968266724</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795780968255503</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795780966275544</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795780892525330</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795780963686201</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795780892534590</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795780698877286</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wsock32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795780891204535</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795780696645603</Timestamp>
<BaseAddress>0x7ffaca540000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\libwscodecs.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark codecs library</Description>
</module>
<module>
<Timestamp>131795780700298298</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780892543743</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795780766486586</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795780704258643</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795780702045466</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795780946467813</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795780696789076</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780891516231</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795780892568770</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795780892552823</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795780966945740</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795780735395573</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795780967734879</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795780699490686</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780703368899</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795780963669913</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795780735383654</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780725077080</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780735352973</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780735341669</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780963187802</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780703358385</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780696324267</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780696320774</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780696326027</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780700094061</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780696281753</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780696314418</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780696011047</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780967736295</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795780696325096</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780696319762</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780696000095</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780700093105</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780700405929</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780696318427</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780719380090</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795780696316518</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780700405056</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780696313332</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780703813608</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795780696317482</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780891250440</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780695999112</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780892432004</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795780696011842</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780696829366</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780722304611</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780696010125</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780696013618</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795780696312465</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780696321680</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780696311589</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780696323259</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780696315318</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780695991736</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>145</ProcessIndex>
<ProcessId>6448</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795780773898509</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k WerSvcGroup</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795780773932265</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795780777692104</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795780777685690</Timestamp>
<BaseAddress>0x7ffabdfa0000</BaseAddress>
<Size>393216</Size>
<Path>C:\Windows\System32\Faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795780777697839</Timestamp>
<BaseAddress>0x7ffabe110000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\weretw.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>WERETW.DLL</Description>
</module>
<module>
<Timestamp>131795780777657500</Timestamp>
<BaseAddress>0x7ffac1940000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\wersvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба регистрации ошибок Windows</Description>
</module>
<module>
<Timestamp>131795780777719777</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.dll</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795780777705622</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\System32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795780777679409</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795780778138106</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795780781946447</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795780777672965</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780781977480</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780777713476</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780777659234</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780778139963</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780777601321</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780777665390</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780778140821</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795780777686685</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780777591206</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780778139073</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780777699394</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780777698612</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780777599983</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780777658345</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780777590325</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780777664133</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780777666249</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780777599157</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780773932520</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>146</ProcessIndex>
<ProcessId>12128</ProcessId>
<ParentProcessId>8596</ParentProcessId>
<ParentProcessIndex>71</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780785349726</CreateTime>
<FinishTime>131795780870658388</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>WerFault.exe</ProcessName>
<ImagePath>C:\Windows\system32\WerFault.exe</ImagePath>
<CommandLine>C:\Windows\system32\WerFault.exe -u -p 8596 -s 736</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Отчет об ошибках Windows</Description>
<modulelist>
<module>
<Timestamp>131795780797694531</Timestamp>
<BaseAddress>0x22623790000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\System32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795780789154686</Timestamp>
<BaseAddress>0x7ff651260000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\System32\WerFault.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Отчет об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795780800678915</Timestamp>
<BaseAddress>0x7ffaa69e0000</BaseAddress>
<Size>5648384</Size>
<Path>C:\Windows\System32\dbgeng.dll</Path>
<Version>10.0.14321.1024 (rs1_release.170706-2004)</Version>
<Company>Microsoft</Company>
<Description>Windows Symbolic Debugger Engine</Description>
</module>
<module>
<Timestamp>131795780800689959</Timestamp>
<BaseAddress>0x7ffab1e80000</BaseAddress>
<Size>675840</Size>
<Path>C:\Windows\System32\DbgModel.dll</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160906-1818)</Version>
<Company>Microsoft</Company>
<Description>Windows Debugger Data Model</Description>
</module>
<module>
<Timestamp>131795780826043748</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\duser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795780797724403</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\devrtl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795780820120198</Timestamp>
<BaseAddress>0x7ffabaef0000</BaseAddress>
<Size>475136</Size>
<Path>C:\Windows\System32\werui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сообщений об ошибках пользовательского интерфейса Windows</Description>
</module>
<module>
<Timestamp>131795780797090228</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795780820971057</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\dui70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795780797130226</Timestamp>
<BaseAddress>0x7ffabdfa0000</BaseAddress>
<Size>393216</Size>
<Path>C:\Windows\System32\Faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795780797703303</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795780797619779</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795780853599499</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795780835537425</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795780851368314</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795780850799498</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780836692566</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795780840687512</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795780839235315</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795780803359241</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780797664969</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780827887916</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795780836720812</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795780842923571</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795780839651561</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795780839612817</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795780803340052</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780820960717</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780834768107</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795780840406821</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795780840233129</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795780843955643</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795780841524886</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795780797141735</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.dll</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795780797102141</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\System32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795780834620822</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795780826365521</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780797487817</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780821036686</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795780846664054</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795780797736070</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795780836290719</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795780840155235</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780842875465</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795780841118589</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795780797112021</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780797747981</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780851045887</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780851036248</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780803349032</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780797120809</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780797528752</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780797626439</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780797627398</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780797168080</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780797072094</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780797073881</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780797166446</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780797075566</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795780797070496</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780797625461</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780797060912</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780797077134</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780820945554</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780797624342</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780797623228</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780820944748</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780797072870</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780840217972</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795780797069138</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780823242362</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780797059912</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780797713490</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795780797167269</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780839618242</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780797180908</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780797165562</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780797071332</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780797079076</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780797620737</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780797621973</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780797078140</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780789154946</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>147</ProcessIndex>
<ProcessId>5240</ProcessId>
<ParentProcessId>10064</ParentProcessId>
<ParentProcessIndex>70</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780785349889</CreateTime>
<FinishTime>131795780870681625</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>WerFault.exe</ProcessName>
<ImagePath>C:\Windows\system32\WerFault.exe</ImagePath>
<CommandLine>C:\Windows\system32\WerFault.exe -u -p 10064 -s 760</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Отчет об ошибках Windows</Description>
<modulelist>
<module>
<Timestamp>131795780793641029</Timestamp>
<BaseAddress>0x224f3dc0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\System32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795780789330514</Timestamp>
<BaseAddress>0x7ff651260000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\System32\WerFault.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Отчет об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795780800173116</Timestamp>
<BaseAddress>0x7ffaa69e0000</BaseAddress>
<Size>5648384</Size>
<Path>C:\Windows\System32\dbgeng.dll</Path>
<Version>10.0.14321.1024 (rs1_release.170706-2004)</Version>
<Company>Microsoft</Company>
<Description>Windows Symbolic Debugger Engine</Description>
</module>
<module>
<Timestamp>131795780800722033</Timestamp>
<BaseAddress>0x7ffab1e80000</BaseAddress>
<Size>675840</Size>
<Path>C:\Windows\System32\DbgModel.dll</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160906-1818)</Version>
<Company>Microsoft</Company>
<Description>Windows Debugger Data Model</Description>
</module>
<module>
<Timestamp>131795780826139640</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\duser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795780796229719</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\devrtl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795780820342275</Timestamp>
<BaseAddress>0x7ffabaef0000</BaseAddress>
<Size>475136</Size>
<Path>C:\Windows\System32\werui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сообщений об ошибках пользовательского интерфейса Windows</Description>
</module>
<module>
<Timestamp>131795780789369213</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795780821401114</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\dui70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795780789429318</Timestamp>
<BaseAddress>0x7ffabdfa0000</BaseAddress>
<Size>393216</Size>
<Path>C:\Windows\System32\Faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795780793649629</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795780791100819</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795780853824585</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795780836214124</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795780851901999</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795780851224646</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780836276988</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795780840913695</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795780839414365</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795780803329574</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780793200884</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780827490732</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795780836982137</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795780843225434</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795780840323239</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795780839723529</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795780803310446</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780821009690</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780834882063</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795780840650639</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795780840413465</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795780844377849</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795780841650817</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795780789440206</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.dll</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795780789401523</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\System32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795780834684833</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795780826383059</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780789895395</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780821047369</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795780847404046</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795780796367435</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795780836823553</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795780840333296</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780842937617</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795780841531425</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795780789411475</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780796382111</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780851252180</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780851234116</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780803319492</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780789420219</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780790265941</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780791608884</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780791609851</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780789466526</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780789351143</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780789352969</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780789464872</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780789354573</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795780789349298</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780791607923</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780789338341</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780789356125</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780821000516</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780791606798</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780791605648</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780820999738</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780789351977</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780840338688</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795780789347919</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780823303223</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780789337377</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780795208748</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795780789465703</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780839729597</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780789479041</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780789464008</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780789350127</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780789358075</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780791602914</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780791604216</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780789357131</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780789330769</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>148</ProcessIndex>
<ProcessId>7304</ProcessId>
<ParentProcessId>12892</ParentProcessId>
<ParentProcessIndex>144</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780945343791</CreateTime>
<FinishTime>131795780951257505</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>dumpcap.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\dumpcap.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\dumpcap.exe&quot; -D -Z none</CommandLine>
<CompanyName>The Wireshark developer community</CompanyName>
<Version>2.6.2</Version>
<Description>Dumpcap</Description>
<modulelist>
<module>
<Timestamp>131795780948130002</Timestamp>
<BaseAddress>0xec0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\libwinpthread-1.dll</Path>
<Version>1, 0, 0, 0</Version>
<Company>MingW-W64 Project. All rights reserved.</Company>
<Description>POSIX WinThreads for Windows</Description>
</module>
<module>
<Timestamp>131795780948069856</Timestamp>
<BaseAddress>0x61cc0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Wireshark\libintl-8.dll</Path>
<Version>0.18.1</Version>
<Company>Free Software Foundation</Company>
<Description>LGPLed libintl for Windows NT/2000/XP/Vista/7 and Windows 95/98/ME</Description>
</module>
<module>
<Timestamp>131795780948090461</Timestamp>
<BaseAddress>0x646c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libgpg-error6-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780948036169</Timestamp>
<BaseAddress>0x64840000</BaseAddress>
<Size>1220608</Size>
<Path>C:\Program Files\Wireshark\libgnutls-30.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780948026056</Timestamp>
<BaseAddress>0x653c0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\libgcrypt-20.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780948139719</Timestamp>
<BaseAddress>0x65f00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Program Files\Wireshark\libtasn1-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780948105979</Timestamp>
<BaseAddress>0x66f00000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Wireshark\libhogweed-4-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780947960028</Timestamp>
<BaseAddress>0x685c0000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Program Files\Wireshark\libglib-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GLib</Description>
</module>
<module>
<Timestamp>131795780948122838</Timestamp>
<BaseAddress>0x68ec0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\Wireshark\libp11-kit-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780948115634</Timestamp>
<BaseAddress>0x69c80000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\libnettle-6-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780948098698</Timestamp>
<BaseAddress>0x6acc0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files\Wireshark\libgmp-10.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780948176154</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\libffi-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780947969085</Timestamp>
<BaseAddress>0x6dd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\Wireshark\libgmodule-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GModule</Description>
</module>
<module>
<Timestamp>131795780948355961</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\wpcap.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008)</Description>
</module>
<module>
<Timestamp>131795780948368872</Timestamp>
<BaseAddress>0x1cbcd090000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795780946481497</Timestamp>
<BaseAddress>0x7ff79b530000</BaseAddress>
<Size>438272</Size>
<Path>C:\Program Files\Wireshark\dumpcap.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community</Company>
<Description>Dumpcap</Description>
</module>
<module>
<Timestamp>131795780948146756</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\zlib1.dll</Path>
<Version>1.2.11</Version>
<Company></Company>
<Description>zlib data compression library</Description>
</module>
<module>
<Timestamp>131795780948382450</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780947926084</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libwsutil.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark utility library</Description>
</module>
<module>
<Timestamp>131795780948008200</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780948842845</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795780948829519</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795780947982517</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wsock32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795780948165222</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795780948081260</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795780948296657</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795780947994727</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780948283007</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780948316771</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780948267644</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780948244692</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780948256628</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780947948822</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780947940826</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780947951118</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780948038349</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780947944901</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780947911693</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780947939271</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780947947522</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780947950138</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780947936368</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780946489462</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780948037036</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780947934653</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780947929635</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780947908330</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780948818886</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795780947905975</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780946488154</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780947943704</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780947927787</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780948198006</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780947946386</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780947937745</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780947904418</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780947960896</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780947942289</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780947907233</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780946481757</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>149</ProcessIndex>
<ProcessId>12220</ProcessId>
<ParentProcessId>7304</ParentProcessId>
<ParentProcessIndex>148</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780947067298</CreateTime>
<FinishTime>131795780951467436</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Conhost.exe</ProcessName>
<ImagePath>C:\Windows\System32\Conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795780947068844</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795780947102997</Timestamp>
<BaseAddress>0x7ffabe520000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795780947700363</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780947131664</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780947658758</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780947418816</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780947399225</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780947396574</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780947399960</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780947115068</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780947111284</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780947112905</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780947116614</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780947133509</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780947395676</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780947075231</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780947118809</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780947394632</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780947393515</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780947118138</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780947112013</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780947084537</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780947074050</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780947641029</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795780947113711</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780947117382</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780947115947</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780947110516</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780947397369</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780947398358</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780947132498</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780947069085</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>150</ProcessIndex>
<ProcessId>6220</ProcessId>
<ParentProcessId>12892</ParentProcessId>
<ParentProcessIndex>144</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780951607574</CreateTime>
<FinishTime>131795780955087550</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>dumpcap.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\dumpcap.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\dumpcap.exe&quot; -i \Device\NPF_{8742EB38-E176-4D94-AB83-DB4440CD90E6} -L --list-time-stamp-types -Z none</CommandLine>
<CompanyName>The Wireshark developer community</CompanyName>
<Version>2.6.2</Version>
<Description>Dumpcap</Description>
<modulelist>
<module>
<Timestamp>131795780952840337</Timestamp>
<BaseAddress>0xd80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\libwinpthread-1.dll</Path>
<Version>1, 0, 0, 0</Version>
<Company>MingW-W64 Project. All rights reserved.</Company>
<Description>POSIX WinThreads for Windows</Description>
</module>
<module>
<Timestamp>131795780952771331</Timestamp>
<BaseAddress>0x61cc0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Wireshark\libintl-8.dll</Path>
<Version>0.18.1</Version>
<Company>Free Software Foundation</Company>
<Description>LGPLed libintl for Windows NT/2000/XP/Vista/7 and Windows 95/98/ME</Description>
</module>
<module>
<Timestamp>131795780952792246</Timestamp>
<BaseAddress>0x646c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libgpg-error6-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780952742645</Timestamp>
<BaseAddress>0x64840000</BaseAddress>
<Size>1220608</Size>
<Path>C:\Program Files\Wireshark\libgnutls-30.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780952735203</Timestamp>
<BaseAddress>0x653c0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\libgcrypt-20.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780952848333</Timestamp>
<BaseAddress>0x65f00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Program Files\Wireshark\libtasn1-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780952807545</Timestamp>
<BaseAddress>0x66f00000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Wireshark\libhogweed-4-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780952678853</Timestamp>
<BaseAddress>0x685c0000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Program Files\Wireshark\libglib-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GLib</Description>
</module>
<module>
<Timestamp>131795780952832876</Timestamp>
<BaseAddress>0x68ec0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\Wireshark\libp11-kit-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780952817641</Timestamp>
<BaseAddress>0x69c80000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\libnettle-6-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780952800264</Timestamp>
<BaseAddress>0x6acc0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files\Wireshark\libgmp-10.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780952886243</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\libffi-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780952687771</Timestamp>
<BaseAddress>0x6dd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\Wireshark\libgmodule-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GModule</Description>
</module>
<module>
<Timestamp>131795780953068332</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\wpcap.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008)</Description>
</module>
<module>
<Timestamp>131795780953081659</Timestamp>
<BaseAddress>0x1a795fc0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795780951635609</Timestamp>
<BaseAddress>0x7ff79b530000</BaseAddress>
<Size>438272</Size>
<Path>C:\Program Files\Wireshark\dumpcap.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community</Company>
<Description>Dumpcap</Description>
</module>
<module>
<Timestamp>131795780952855661</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\zlib1.dll</Path>
<Version>1.2.11</Version>
<Company></Company>
<Description>zlib data compression library</Description>
</module>
<module>
<Timestamp>131795780953095719</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780952648415</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libwsutil.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark utility library</Description>
</module>
<module>
<Timestamp>131795780952721985</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780953190431</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795780953177315</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795780952698529</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wsock32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795780952874931</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795780952783062</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795780953005216</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795780952709279</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780952993691</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780953026059</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780952977935</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780952952911</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780952963927</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780952661251</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780952655669</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780952669895</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780952744376</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780952658597</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780952640128</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780952654682</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780952660403</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780952668491</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780952652784</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780951643827</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780952743445</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780952651715</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780952650540</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780952638217</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780953166371</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795780952636651</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780951642857</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780952657749</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780952649357</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780952908565</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780952659581</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780952653740</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780952635482</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780952679642</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780952656777</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780952637483</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780951635942</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>151</ProcessIndex>
<ProcessId>11628</ProcessId>
<ParentProcessId>6220</ParentProcessId>
<ParentProcessIndex>150</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780951985999</CreateTime>
<FinishTime>131795780955157039</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Conhost.exe</ProcessName>
<ImagePath>C:\Windows\System32\Conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795780951987681</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795780952017415</Timestamp>
<BaseAddress>0x7ffabe520000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795780952546766</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780952049412</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780952506623</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780952362867</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780952336669</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780952334073</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780952337420</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780952029220</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780952025532</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780952027164</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780952030746</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780952051251</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780952333031</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780951994053</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780952033101</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780952331962</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780952330768</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780952032437</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780952026269</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780952002562</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780951993200</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780952485739</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795780952027904</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780952031680</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780952030087</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780952024765</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780952334885</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780952335807</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780952050246</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780951987916</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>152</ProcessIndex>
<ProcessId>2432</ProcessId>
<ParentProcessId>12892</ParentProcessId>
<ParentProcessIndex>144</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780956883979</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>dumpcap.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\dumpcap.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\dumpcap.exe&quot; -S -Z 12892.dummy</CommandLine>
<CompanyName>The Wireshark developer community</CompanyName>
<Version>2.6.2</Version>
<Description>Dumpcap</Description>
<modulelist>
<module>
<Timestamp>131795780958439058</Timestamp>
<BaseAddress>0xa80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\libwinpthread-1.dll</Path>
<Version>1, 0, 0, 0</Version>
<Company>MingW-W64 Project. All rights reserved.</Company>
<Description>POSIX WinThreads for Windows</Description>
</module>
<module>
<Timestamp>131795780958377059</Timestamp>
<BaseAddress>0x61cc0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Wireshark\libintl-8.dll</Path>
<Version>0.18.1</Version>
<Company>Free Software Foundation</Company>
<Description>LGPLed libintl for Windows NT/2000/XP/Vista/7 and Windows 95/98/ME</Description>
</module>
<module>
<Timestamp>131795780958399096</Timestamp>
<BaseAddress>0x646c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libgpg-error6-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958347475</Timestamp>
<BaseAddress>0x64840000</BaseAddress>
<Size>1220608</Size>
<Path>C:\Program Files\Wireshark\libgnutls-30.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958339828</Timestamp>
<BaseAddress>0x653c0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\libgcrypt-20.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958446503</Timestamp>
<BaseAddress>0x65f00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Program Files\Wireshark\libtasn1-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958414603</Timestamp>
<BaseAddress>0x66f00000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Wireshark\libhogweed-4-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958277889</Timestamp>
<BaseAddress>0x685c0000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Program Files\Wireshark\libglib-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GLib</Description>
</module>
<module>
<Timestamp>131795780958431545</Timestamp>
<BaseAddress>0x68ec0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\Wireshark\libp11-kit-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958424372</Timestamp>
<BaseAddress>0x69c80000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\libnettle-6-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958407305</Timestamp>
<BaseAddress>0x6acc0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files\Wireshark\libgmp-10.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958485579</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\libffi-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958289420</Timestamp>
<BaseAddress>0x6dd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\Wireshark\libgmodule-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GModule</Description>
</module>
<module>
<Timestamp>131795780958713554</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\wpcap.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008)</Description>
</module>
<module>
<Timestamp>131795780958729518</Timestamp>
<BaseAddress>0x2a56ecc0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795780956897031</Timestamp>
<BaseAddress>0x7ff79b530000</BaseAddress>
<Size>438272</Size>
<Path>C:\Program Files\Wireshark\dumpcap.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community</Company>
<Description>Dumpcap</Description>
</module>
<module>
<Timestamp>131795780958453942</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\zlib1.dll</Path>
<Version>1.2.11</Version>
<Company></Company>
<Description>zlib data compression library</Description>
</module>
<module>
<Timestamp>131795780958743457</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780958247042</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libwsutil.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark utility library</Description>
</module>
<module>
<Timestamp>131795780958327006</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780959264331</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795780958822800</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795780958303451</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wsock32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795780958474513</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795780958389609</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795780958646709</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795780958314117</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780958635383</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780958674359</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780958618023</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780958596049</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780958607187</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780958263131</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780958255689</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780958265389</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780958349084</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780958259529</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780958230643</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780958254658</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780958262008</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780958264244</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780958252245</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780956903750</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780958348162</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780958250835</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780958249546</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780958228230</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780958812040</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795780958226523</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780956902794</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780958258379</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780958248189</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780958549690</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780958260931</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780958253539</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780958224678</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780958278826</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780958257207</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780958227462</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780956897313</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>153</ProcessIndex>
<ProcessId>4460</ProcessId>
<ParentProcessId>2432</ParentProcessId>
<ParentProcessIndex>152</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780957221117</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Conhost.exe</ProcessName>
<ImagePath>C:\Windows\System32\Conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795780957224666</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795780957254960</Timestamp>
<BaseAddress>0x7ffabe520000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795780958156057</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780957284286</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780958109132</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780957764987</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780957662947</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780957660016</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780957663767</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780957266937</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780957263269</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780957264898</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780957268718</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780957285965</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780957659076</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780957231155</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780957270871</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780957656755</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780957655580</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780957270220</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780957263997</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780957239575</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780957230291</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780958089236</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795780957265615</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780957269477</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780957268031</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780957262479</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780957660847</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780957661778</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780957285128</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780957224946</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>1</ProcessIndex>
<ProcessId>11372</ProcessId>
<ParentProcessId>10560</ParentProcessId>
<ParentProcessIndex>2</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770632346846</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon64.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Temp\Procmon64.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Temp\Procmon64.exe&quot;  /originalpath &quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot;</CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>2</ProcessIndex>
<ProcessId>10560</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770594566098</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon.exe</ProcessName>
<ImagePath>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot; </CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x1000000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x62530000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\RICHED20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cd0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72520000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\Riched32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wrapper Dll for Richedit 1.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>3</ProcessIndex>
<ProcessId>4048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765778109600457</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchIndexer.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchIndexer.exe</ImagePath>
<CommandLine>C:\Windows\system32\SearchIndexer.exe /Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Индексатор службы Microsoft Windows Search</Description>
<modulelist>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ff63db40000</BaseAddress>
<Size>929792</Size>
<Path>C:\Windows\system32\SearchIndexer.exe</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индексатор службы Microsoft Windows Search</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\MSSRCH.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabd990000</BaseAddress>
<Size>720896</Size>
<Path>C:\Windows\system32\ElsLad.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ELS Language Detection</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\Msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>4</ProcessIndex>
<ProcessId>580</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776275984299</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>services.exe</ProcessName>
<ImagePath>C:\Windows\system32\services.exe</ImagePath>
<CommandLine>C:\Windows\system32\services.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Приложение служб и контроллеров</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>6</ProcessIndex>
<ProcessId>664</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776282506625</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k DcomLaunch</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc6a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\SebBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; SEB Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc7e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\SmartCardBackgroundPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartCardBackgroundPolicy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8c0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\CbtBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; CBT Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8d0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\ACPBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; ACP Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc900000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BackgroundMediaPolicy.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Background Media Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\RmClient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca740000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\DAB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL брокера активности компьютера</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacabd0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\OnDemandBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OnDemandBrokerClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacae70000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\systemeventsbrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер системных событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacafc0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy RM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb010000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SYSTEM32\psmserviceexthost.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager PSM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb390000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\psmsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process State Manager (PSM) Service</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb4f0000</BaseAddress>
<Size>794624</Size>
<Path>c:\windows\system32\bisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба инфраструктуры фоновых задач</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb720000</BaseAddress>
<Size>344064</Size>
<Path>c:\windows\system32\mintdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>c:\windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb820000</BaseAddress>
<Size>712704</Size>
<Path>C:\Windows\SYSTEM32\tdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8d0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\umpoext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения службы пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8f0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\umpo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb940000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\umpnpmgr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский режим службы самонастройки (Plug-and-Play)</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>7</ProcessIndex>
<ProcessId>884</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776292813936</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9230000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\bluetoothapis.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Usermode Api host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9580000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\BthRadioMedia.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab95a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WlanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wlan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaba920000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\rmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Radio Manager API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabae80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\NfcRadioMedia.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NFC Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabb8a0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\XboxGipRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Xbox GIP Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc0e0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\WwanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wwan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac78c0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\shacct.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Classes</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7f80000</BaseAddress>
<Size>208896</Size>
<Path>c:\windows\system32\wscsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8490000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\dhcpcore6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8c90000</BaseAddress>
<Size>385024</Size>
<Path>c:\windows\system32\dhcpcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>c:\windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac9c30000</BaseAddress>
<Size>1732608</Size>
<Path>c:\windows\system32\wevtsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба протоколирования событий</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca2a0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\timebrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер событий времени</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca330000</BaseAddress>
<Size>36864</Size>
<Path>c:\windows\system32\nrpsrv.DLL</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Name Resolution Proxy (NRP) RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4d0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lmhsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб транспорта TCPIP NetBios</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>8</ProcessIndex>
<ProcessId>0</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:00000000</AuthenticationId>
<CreateTime>131765775874898587</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>4294967295</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity></Integrity>
<Owner></Owner>
<ProcessName>Idle</ProcessName>
<ImagePath>Idle</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>9</ProcessIndex>
<ProcessId>4</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775907178738</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>System</ProcessName>
<ImagePath>System</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b6e00000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\System32\win32kfull.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Win32k Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7190000</BaseAddress>
<Size>1576960</Size>
<Path>C:\Windows\System32\win32kbase.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Базовый драйвер ядра Win32k</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7320000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\TSDDD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Framebuffer Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7330000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\cdd.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Canonical Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b74a0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\win32k.sys</Path>
<Version>10.0.14393.594 (rs1_release_inmarket.161213-1754)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Multi-User Win32 Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80278934000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\kd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Kernel Debugger</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80279678000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92e00000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\ksecdd.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ee0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\cmimcext.sys</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Configuration Manager Initial Configuration Extension Host Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ef0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\ntosext.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTOS extension host driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92fa0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\drivers\cng.sys</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Cryptography, Next Generation</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93040000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\system32\drivers\Wdf01000.sys</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения платформы драйвера режима ядра</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93120000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\drivers\WDFLDR.SYS</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Mode Driver Framework Loader</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93140000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\Drivers\acpiex.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPIEx Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93170000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\Drivers\WppRecorder.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WPP Trace Recorder</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93180000</BaseAddress>
<Size>733184</Size>
<Path>C:\Windows\System32\drivers\ACPI.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPI драйвер для NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93240000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\WMILIB.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMILIB WMI support library Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93260000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\intelpep.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Power Engine Plugin</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93280000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\drivers\WindowsTrustedRT.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932a0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Service Proxy Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\pcw.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Performance Counters for Windows Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932d0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\msisadrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ISA Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932e0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\isapnp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер шины PNP ISA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932f0000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\drivers\pci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Plug and Play PCI-перечислитель</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93350000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\vdrvroot.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Drive Root Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93370000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\drivers\pdc.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Power Dependency Coordinator Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933a0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\CEA.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation Kernel Mode Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\partmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Partition driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\nvraid.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) RAID Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93420000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\CLASSPNP.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI Class System Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93490000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\vmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Дочерний драйвер шины виртуальной машины Microsoft Hyper-V</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d934c0000</BaseAddress>
<Size>1212416</Size>
<Path>C:\Windows\System32\drivers\NDIS.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS (Network Driver Interface Specification)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d935f0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\drivers\NETIO.SYS</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network I/O Subsystem</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93670000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\hvsocket.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Hyper-V Socket Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\vmbkmcl.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V VMBus KMCL</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\winhv.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Hypervisor Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\pciide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Generic PCI IDE Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936e0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\PCIIDEX.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PCI IDE Bus Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93700000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\drivers\spaceport.sys</Path>
<Version>10.0.14393.1914 (rs1_release_inmarket.171117-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Spaces Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937a0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\intelide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel PCI IDE Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937b0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\volmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937d0000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\drivers\volmgrx.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер расширения диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93830000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\drivers\mountmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер точек подключения</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93850000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\nvstor.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) Sata Performance Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\drivers\storport.sys</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Storage Port Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93910000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\atapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI IDE Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93920000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\System32\drivers\ataport.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93960000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\storahci.sys</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS AHCI Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93990000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\stornvme.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft NVM Express Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\drivers\EhStorClass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enhanced Storage Class driver for IEEE 1667 devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\fileinfo.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FileInfo Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939f0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\Drivers\Wof.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр оверлея Windows</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93a80000</BaseAddress>
<Size>2297856</Size>
<Path>C:\Windows\System32\Drivers\NTFS.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер файловой системы NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\storvsc.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage VSC Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cd0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\Drivers\Fs_Rec.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>File System Recognizer Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93d10000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\System32\drivers\USBPORT.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта USB 1.1 и 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93db0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\mcupdate_GenuineIntel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Microcode Update Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93e50000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\System32\drivers\CLFS.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Common Log File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ec0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\tm.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Transaction Manager Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ef0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\PSHED.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер аппаратных ошибок, специфичных для платформы</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f10000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\BOOTVID.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>VGA Boot Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f20000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\FLTMGR.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер фильтров файловых систем Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\drivers\msrpc.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Remote Procedure Call Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94000000</BaseAddress>
<Size>430080</Size>
<Path>C:\Windows\System32\drivers\fwpkclnt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FWP/IPsec Kernel-Mode API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94070000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\wfplwfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WFP NDIS 6.30 Lightweight Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d940b0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DRIVERS\fvevol.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BitLocker Drive Encryption Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94160000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\volume.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94170000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\System32\drivers\volsnap.sys</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume Shadow Copy driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d941e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\scmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Class Memory Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\drivers\rdyboost.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ReadyBoost Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94250000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\Drivers\mup.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер поставщика множественных UNC</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94280000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\drivers\iorate.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>I/O rate control Filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942a0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\disk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PnP Disk Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942e0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\crashdmp.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crash Dump Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d943c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\drivers\cdrom.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI CD-ROM Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94400000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\drivers\filecrypt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows sandboxing and encryption filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94420000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\tbs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Export driver for kernel mode TPM API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94430000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Null.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NULL Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94440000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Beep.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BEEP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94450000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\BasicDisplay.sys</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94470000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\watchdog.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Watchdog Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94490000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\System32\drivers\dxgkrnl.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Kernel</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\BasicRender.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Render Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\Npfs.SYS</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPFS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94700000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\DRIVERS\tdx.sys</Path>
<Version>10.0.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDI Translation Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94740000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\DRIVERS\netbt.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>MBT Transport driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94790000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\drivers\afd.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер дополнительных функций для Winsock</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94830000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\vwififlt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual WiFi Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94850000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\pacer.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Планировщик пакетов QoS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\drivers\netbios.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetBIOS interface driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d948a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\rdbss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер подсистемы буферизации перенаправленного диска</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94920000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\drivers\csc.sys</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Client Side Caching Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\nsiproxy.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\npsvctrig.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Named pipe service triggers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\gpuenergydrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GPU Energy Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a00000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Drivers\dfsc.sys</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DFS Namespace Client Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a50000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\DRIVERS\ahcache.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Compatibility Cache</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a90000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-Transport Composite Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\kdnic.sys</Path>
<Version>6.01.00.0000 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Kernel Debugger Network Miniport</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ac0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\drivers\umbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User-Mode Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ae0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\i8042prt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта i8042</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b10000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\drivers\kbdclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса клавиатуры</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b30000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\mouclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса мыши</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b80000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\HDAudBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ba0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\drivers\portcls.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Port Class (Class Driver for Port/Miniport Devices)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c10000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\drmk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trusted Audio Drivers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c40000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\drivers\ks.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel CSA Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cb0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\usbohci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OHCI USB Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\CmBatt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Control Method Battery Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cd0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\BATTC.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Class Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ce0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\intelppm.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Processor Device Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d10000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\NdisVirtualBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечислитель виртуальных сетевых адаптеров (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d20000</BaseAddress>
<Size>2588672</Size>
<Path>C:\Windows\System32\drivers\tcpip.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fa0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\swenum.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Plug and Play Software Device Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fb0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\rdpbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft RDP Bus Device driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95200000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\DRIVERS\udfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UDF File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95280000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\Drivers\dump_diskdump.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d952c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\Drivers\dump_storahci.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95310000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\Drivers\dump_dumpfve.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95330000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\system32\drivers\HTTP.sys</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Стек протокола HTTP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95450000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\drivers\WudfPf.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - User-mode Driver Framework Platform Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95470000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\DRIVERS\bowser.sys</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Lan Manager Datagram Receiver Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d954a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT SMB Minirdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95520000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\mpsdrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Protection Service Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95540000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb20.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB 2.0 Redirector</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95580000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\DRIVERS\srvnet.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Network driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d955d0000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\System32\DRIVERS\srv2.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер сервера SMB 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95690000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb10.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB Downlevel SubRdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d956e0000</BaseAddress>
<Size>573440</Size>
<Path>C:\Windows\System32\DRIVERS\srv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95770000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\tcpipreg.sys</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>TCP/IP Registry Compatibility Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95860000</BaseAddress>
<Size>684032</Size>
<Path>C:\Windows\System32\drivers\dxgmms2.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics MMS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95910000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\luafv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра виртуализации файлов LUA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95960000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\storqosflt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр качества обслуживания хранилища</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95980000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\registry.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Registry Containment Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959a0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\drivers\lltdio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Mapper I/O Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959c0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\drivers\mslldp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер протокола Microsoft LLDP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\rspndr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Responder Driver for NDIS 6</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95ae0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\USBD.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Universal Serial Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95af0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\DRIVERS\HdAudio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Function Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95b60000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\ksthunk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Streaming WOW Thunk Service</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95bc0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\HIDPARSE.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hid Parsing Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97020000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\Drivers\360AntiHacker64.sys</Path>
<Version>1.0.0.1149</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络防黑模块</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97060000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\DRIVERS\360AvFlt.sys</Path>
<Version>1.1.0.1056</Version>
<Company>360.cn</Company>
<Description>360杀毒 文件监控驱动</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97080000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\DRIVERS\BAPIDRV64.sys</Path>
<Version>2.0.0.1221</Version>
<Company>360.cn</Company>
<Description>BAPIDRV</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d970c0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\drivers\360netmon.sys</Path>
<Version>2.1.11.5195</Version>
<Company>360.cn</Company>
<Description>360netmon</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97120000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\system32\DRIVERS\360Box64.sys</Path>
<Version>2.1.0.1253</Version>
<Company>360.cn</Company>
<Description>360Box64</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97180000</BaseAddress>
<Size>811008</Size>
<Path>C:\Windows\system32\DRIVERS\360FsFlt.sys</Path>
<Version>6.9.1.1751</Version>
<Company>360.cn</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97330000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\hidusb.sys</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>USB Miniport Driver for Input Devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97350000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\HIDCLASS.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека классов HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97380000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\mouhid.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра мыши HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97390000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\rassstp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS SSTP Miniport Call Manager</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973b0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\DRIVERS\NDProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\drivers\AgileVpn.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер вызовов минипорта RAS Agile VPN</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97420000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\drivers\rasl2tp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS L2TP mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97460000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\raspptp.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Peer-to-Peer Tunneling Protocol</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974a0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\raspppoe.sys</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS PPPoE mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\DRIVERS\ndistapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS 3.0 connection wrapper driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974d0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\drivers\ndiswan.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS PPP Framing Driver (Strong Encryption)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97510000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\DRIVERS\wanarp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS Remote Access and Routing ARP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97550000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\E1G6032E.sys</Path>
<Version>8.4.13.0 built by: WinDDK</Version>
<Company>Intel Corporation</Company>
<Description>Intel(R) PRO/1000 Adapter NDIS 6 deserialized driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97580000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\tunnel.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер интерфейса туннеля (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97600000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\Drivers\PROCMON24.SYS</Path>
<Version>3.10</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor Driver</Description>
</module>
<module>
<Timestamp>131795780236159256</Timestamp>
<BaseAddress>0xfffff80d97620000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\npf.sys</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>npf.sys (NT5/6 AMD64) Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97a60000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\system32\drivers\peauth.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Protected Environment Authentication and Authorization Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b30000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\Ndu.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Network Data Usage Monitoring Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b60000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\drivers\mmcss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMCSS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97bb0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\condrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Driver</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>10</ProcessIndex>
<ProcessId>320</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775908989732</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>smss.exe</ProcessName>
<ImagePath>C:\Windows\System32\smss.exe</ImagePath>
<CommandLine>\SystemRoot\System32\smss.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер сеанса  Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>11</ProcessIndex>
<ProcessId>3108</ProcessId>
<ParentProcessId>3092</ParentProcessId>
<ParentProcessIndex>12</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777624392598</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Explorer.EXE</ProcessName>
<ImagePath>C:\Windows\Explorer.EXE</ImagePath>
<CommandLine>C:\Windows\Explorer.EXE</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x31b0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5db0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Program Files\Uninstall Tool\utshellext.dll</Path>
<Version>1.1.0.15</Version>
<Company>CrystalIDEA Software</Company>
<Description>Uninstall Tool Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x81a0000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\MICROS~1\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x8cb0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5bf70000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_08e394a1a83e212f\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\Notepad++\NppShell_06.dll</Path>
<Version>0.1</Version>
<Company></Company>
<Description>ShellHandler for Notepad++ (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\Explorer.EXE</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2093056</Size>
<Path>C:\Windows\system32\wpdshext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки для переносных устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab350000</BaseAddress>
<Size>1683456</Size>
<Path>C:\Windows\System32\comsvcs.dll</Path>
<Version>2001.12.10941.16384 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Services</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab4f0000</BaseAddress>
<Size>1400832</Size>
<Path>C:\Windows\system32\connect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Мастера подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab650000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\system32\rasgcw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Страницы мастера RAS</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\System32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\system32\ieframe.DLL</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0df0000</BaseAddress>
<Size>1626112</Size>
<Path>C:\Windows\SYSTEM32\d3d9.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 9 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0f80000</BaseAddress>
<Size>1777664</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoViewer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Просмотр фотографий Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab27c0000</BaseAddress>
<Size>516096</Size>
<Path>C:\Windows\System32\imapi2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>IMAPI версии 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2840000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\bthprops.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложение панели управления Bluetooth</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2880000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\cscobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Внутрипроцессный COM-объект используемый клиентами CSC API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab29a0000</BaseAddress>
<Size>1912832</Size>
<Path>C:\Windows\System32\pnidui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Значок сетевой системы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2b80000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\system32\SettingMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Change Monitor</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2bc0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\PortableDeviceTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device (Parameter) Types Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab34f0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\System32\Actioncenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5120000</BaseAddress>
<Size>1691648</Size>
<Path>C:\Windows\system32\BatMeter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Meter Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\MsftEdit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7e40000</BaseAddress>
<Size>3420160</Size>
<Path>C:\Windows\System32\SyncCenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр синхронизации Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\system32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\system32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab99b0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\dxp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки компонента Device Stage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9ba0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\SYSTEM32\searchfolder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SearchFolder</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabac60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\EhStorAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Enhanced Storage API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae20000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msiltcfg.dll</Path>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer Configuration API Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaea0000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\system32\SHDOCVW.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\SYSTEM32\settingsynccore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SYSTEM32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SYSTEM32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd3c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\InputSwitch.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переключатель ввода Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd670000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\framedynos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI SDK Provider Framework</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd6c0000</BaseAddress>
<Size>1306624</Size>
<Path>C:\Windows\System32\werconcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PRS CPL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd800000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\NPSMDesktopProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Библиотека DLL локального поставщика рабочего стола NPSM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabda60000</BaseAddress>
<Size>1241088</Size>
<Path>C:\Windows\System32\wscui.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdeb0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\wpdshserviceobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device Shell Service Object</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabded0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\stobject.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Объект службы оболочки Systray</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe470000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\wscinterop.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Health Center WSC Interop</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe580000</BaseAddress>
<Size>831488</Size>
<Path>C:\Program Files (x86)\360\Total Security\MenuEx64.dll</Path>
<Version>9, 6, 0, 1001</Version>
<Company></Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe650000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\system32\zipfldr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сжатые ZIP-папки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9a0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\Syncreg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Synchronization Framework Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\system32\NetworkExplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0b0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\playtomenu.dll</Path>
<Version>12.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека меню функции &quot;Передать на устройство&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\System32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf590000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\syncui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Портфель Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfba0000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\WSCAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\MICROS~1\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b40000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\dlnashext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLNA Namespace DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\srchadmin.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры индексирования</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0f60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SYSTEM32\CHARTV.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Chart View</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1cc0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.Sockets.PushEnabledApplication DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac27a0000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.111.0603.0006\amd64\FileSyncShell64.dll</Path>
<Version>18.111.0603.0006</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac32e0000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\twext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Свойства: Предыдущие версии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3350000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\OLEACCHOOKS.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Event Hooks Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\dsreg.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5140000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\AboveLockAppHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AboveLockAppHost</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5190000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\NotificationController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5570000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\system32\twinui.pcshell.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Twinui.PCShell</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac55d0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\windows.immersiveshell.serviceprovider.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.ImmersiveShell.ServiceProvider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\system32\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5c70000</BaseAddress>
<Size>65536</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoBase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Base Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6650000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\npsm.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPSM</Description>
</module>
<module>
<Timestamp>131795780903771340</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac78f0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\hgcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Панель управления домашней группы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795782572474169</Timestamp>
<BaseAddress>0x7ffac7ce0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\ploptin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Prelaunch OptIn</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d40000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\SYNCENG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Briefcase Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d90000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\SYSTEM32\SndVolSSO.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Громкость SCA </Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7f50000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\acppage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека расширений для вкладки &quot;Совместимость&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\SYSTEM32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795778062352400</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\ploptin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Prelaunch OptIn</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ea0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\hcproviders.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщики компонента &quot;Центр безопасности и обслуживания&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca190000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\WorkFoldersShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки рабочих папок (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795780604813666</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac80000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SYSTEM32\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>13</ProcessIndex>
<ProcessId>404</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776186257169</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>15</ProcessIndex>
<ProcessId>468</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776223665667</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>17</ProcessIndex>
<ProcessId>484</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226419105</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>wininit.exe</ProcessName>
<ImagePath>C:\Windows\system32\wininit.exe</ImagePath>
<CommandLine>wininit.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Автозагрузка приложений Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>18</ProcessIndex>
<ProcessId>520</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226825613</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>winlogon.exe</ProcessName>
<ImagePath>C:\Windows\system32\winlogon.exe</ImagePath>
<CommandLine>winlogon.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Программа входа в систему Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ff7b5570000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\winlogon.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа входа в систему Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaee0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\dwminit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMInit</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacafa0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\UXINIT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows User Experience Session Initialization Dll</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>19</ProcessIndex>
<ProcessId>588</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776277547408</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>lsass.exe</ProcessName>
<ImagePath>C:\Windows\system32\lsass.exe</ImagePath>
<CommandLine>C:\Windows\system32\lsass.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Description>Local Security Authority Process</Description>
<modulelist>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x222e3610000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\msprivs.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переводы привилегий Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ff6b2d20000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\lsass.exe</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Security Authority Process</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffab9170000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\vaultsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба диспетчера учетных данных</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf170000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\hmkd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows HMAC Key Derivation API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf190000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\ngcpopkeysrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Passport Proof-of-possession Key Service</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\keyiso.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба изоляции ключей CNG</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SYSTEM32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf270000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SecureTimeAggregator.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Secure Time Aggregator</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb9b0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\scecli.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент редактора конфигураций безопасности</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\SspiSrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA SSPI RPC interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\dpapisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DPAPI Server</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbad0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\efslsaext.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA extension for EFS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbb70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wdigest.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Digest Access</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc00000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\MicrosoftAccountCloudAP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MicrosoftAccount Cloud AP Plugin</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc50000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\cloudAP.DLL</Path>
<Version>10.0.14393.1358 (rs1_release.170602-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cloud AP Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbcb0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\system32\pku2u.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pku2u Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd00000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\tspkg.DLL</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Web Service Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe30000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\gmsaclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;gmsaclient.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe60000</BaseAddress>
<Size>843776</Size>
<Path>C:\Windows\system32\netlogon.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека службы Net Logon</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc030000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\KerbClientShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kerberos Client Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc180000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\negoexts.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NegoExtender Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\JOINUTIL.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\netprovfw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Provisioning Service Framework DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc260000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\SYSTEM32\samsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сервера диспетчера учетных записей</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc380000</BaseAddress>
<Size>1527808</Size>
<Path>C:\Windows\system32\lsasrv.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера LSA</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>20</ProcessIndex>
<ProcessId>704</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776284978539</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k RPCSS</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8250000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\wshhyperv.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V Winsock2 Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6a0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\RpcRtRemote.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote RPC Extension</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\rpcepmap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сопоставитель конечных точек RPC
</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>21</ProcessIndex>
<ProcessId>808</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0000c8d4</AuthenticationId>
<CreateTime>131765776288401882</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>Window Manager\DWM-1</Owner>
<ProcessName>dwm.exe</ProcessName>
<ImagePath>C:\Windows\system32\dwm.exe</ImagePath>
<CommandLine>&quot;dwm.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер окон рабочего стола</Description>
<modulelist>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ff683990000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\dwm.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\system32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7b70000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\System32\Windows.Gaming.Input.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Gaming Input API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\avrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9a30000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SYSTEM32\ism32k.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca110000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\dwmghost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMGhost</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca8d0000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\system32\dwmcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека ядра Microsoft DWM</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacac90000</BaseAddress>
<Size>856064</Size>
<Path>C:\Windows\SYSTEM32\udwm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\dwmredir.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компонент перенаправления диспетчера окон рабочего стола Microsoft</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>22</ProcessIndex>
<ProcessId>904</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776293087855</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x259b0640000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\SFC.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab830000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\netman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>c:\windows\system32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>c:\windows\system32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab1260000</BaseAddress>
<Size>10350592</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll</Path>
<Version>4.7.2117.0 built by: NET47REL1LAST</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Common Language Runtime - WorkStation</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>c:\windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795778252487651</Timestamp>
<BaseAddress>0x7ffabc160000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\System32\aeinv.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Inventory Component</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778007496118</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabfa00000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\SYSTEM32\MSVCR120_CLR0400.dll</Path>
<Version>12.00.52519.0 built by: VSWINSERVICING</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\MSI.DLL</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0fc0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\spp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих точек защиты Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1010000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\system32\MSCOREE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac10f0000</BaseAddress>
<Size>421888</Size>
<Path>c:\windows\system32\storsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы хранения</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1240000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll</Path>
<Version>4.7.2623.0 built by: NET471REL1LAST_C</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795781037721051</Timestamp>
<BaseAddress>0x7ffac1660000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\System32\aeinv.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Inventory Component</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2420000</BaseAddress>
<Size>466944</Size>
<Path>c:\windows\system32\das.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сопоставления устройств</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795778007645121</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac41c0000</BaseAddress>
<Size>139264</Size>
<Path>c:\windows\system32\trkwks.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент отслеживания изменившихся связей</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4650000</BaseAddress>
<Size>516096</Size>
<Path>c:\windows\system32\pcasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба помощника по совместимости программ</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Assembly manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b50000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\dssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы NT для службы совместного доступа к данным</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6120000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\sysmain.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост службы Superfetch</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b10000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\SYSTEM32\WUDFPlatform.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - библиотека платформ пользовательского режима</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b50000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\wudfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation (WDF) - служба среды выполнения платформы драйвера режима пользователя</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9800000</BaseAddress>
<Size>376832</Size>
<Path>c:\windows\system32\audioendpointbuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство построения конечных точек Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9de0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\portabledeviceconnectapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Portable Device Connection API Components</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SYSTEM32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca2d0000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\ncbservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Посредник подключений к сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>c:\windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca710000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\pcadm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Diagnostic Module</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\system32\SXS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>c:\windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>23</ProcessIndex>
<ProcessId>96</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776304995849</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2510000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\energyprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2580000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\ncuprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Connectivity Statistics Provider for System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2b90000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\nduprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик сетевой статистики для службы отслеживания использования ресурсов системы</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bb0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\appsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bd0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\eeprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy Estimator SRUM provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2c20000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\wfapigp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall GPO Helper dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2d70000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\wpnsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SRUM provider for WPN</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3310000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\srumsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3730000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\pnpts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PlugPlay Troubleshooter</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3bd0000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\ncdautosetup.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы автоматической настройки сетевых устройств</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac41f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\adhapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD harvest sites and subnets API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4500000</BaseAddress>
<Size>200704</Size>
<Path>c:\windows\system32\dps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба политики диагностики WDI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4cd0000</BaseAddress>
<Size>933888</Size>
<Path>c:\windows\system32\mpssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба защиты (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6740000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\dtsh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API состояния общего доступа и обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac74b0000</BaseAddress>
<Size>827392</Size>
<Path>c:\windows\system32\bfe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба базовой фильтрации</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\coremessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\system32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\CFGMGR32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>24</ProcessIndex>
<ProcessId>348</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776305446235</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k netsvcs</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaa0aa0000</BaseAddress>
<Size>2138112</Size>
<Path>c:\windows\system32\wlidsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба учетных записей Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0750000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\system32\rascustom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль настраиваемых протоколов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab07b0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\vpnike.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>VPNIKE Protocol Engine - Test dll</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab09b0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\system32\rasppp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access PPP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0a00000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\rastapi.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access TAPI Compliance Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab3440000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\rasmans.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер подключений удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4c50000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\eappprxy.dll</Path>
<Version>10.0.14393.187 (rs1_release_inmarket.160906-1818)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft EAPHost Peer Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab9a90000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\dmEnrollEngine.DLL</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enroll Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabc210000</BaseAddress>
<Size>2355200</Size>
<Path>c:\windows\system32\wuaueng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Агент Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabdf60000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\raschap.dll</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>Удаленные доступ через PPP CHAP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4a0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\appinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о приложении</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabed80000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\system32\wbem\wbemess.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee10000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee30000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\system32\wbem\wmiprvsd.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf090000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>c:\windows\system32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfda0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\wbem\ncprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Non-COM WMI Event Provision APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0000000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wbem\repdrvfs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Repository Driver</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\shacctprofile.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Profile Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795783766785197</Timestamp>
<BaseAddress>0x7ffac13e0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\usocore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обновление ядра оркестратора сеанса</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1530000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SYSTEM32\dpx.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft(R) Delta Package Expander</Description>
</module>
<module>
<Timestamp>131795783773591339</Timestamp>
<BaseAddress>0x7ffac1660000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\System32\updatehandlers.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Session Orchestrator Update Handlers</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1900000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\appxapplicabilityblob.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Appx Applicability Blob DLL</Description>
</module>
<module>
<Timestamp>131795783942703101</Timestamp>
<BaseAddress>0x7ffac1940000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1970000</BaseAddress>
<Size>1073152</Size>
<Path>c:\windows\system32\qmgr.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фоновая интеллектуальная служба передачи</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1c30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\DMProcessXMLFiltered.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmprocessxmlfiltered</Description>
</module>
<module>
<Timestamp>131795779661934902</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1cf0000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\SYSTEM32\wuuhext.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update Agent plugin for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1df0000</BaseAddress>
<Size>61440</Size>
<Path>c:\windows\system32\NCI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CoInstaller: NET</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e20000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f10000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\DMCmnUtils.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmcmnutils</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f50000</BaseAddress>
<Size>471040</Size>
<Path>C:\Windows\system32\wbem\esscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20f0000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\CLUSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API кластера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2210000</BaseAddress>
<Size>1351680</Size>
<Path>C:\Windows\system32\wbem\wbemcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инструментарий управления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2370000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\adhsvc.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD Harvest Sites and Subnets Service</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2390000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\httpprxm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager</Description>
</module>
<module>
<Timestamp>131795775850813653</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac24a0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\system32\RESUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служебной программы ресурсов кластера (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795784861928280</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2640000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\wmidcom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2670000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\miutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура управления</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac26f0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\sscoreext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Core DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2720000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SYSTEM32\WPTaskScheduler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WP Task Scheduler DLL</Description>
</module>
<module>
<Timestamp>131795784861934949</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2770000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\SSCORE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основная DLL-библиотека службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2940000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CSystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Classic System Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>c:\windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a40000</BaseAddress>
<Size>974848</Size>
<Path>c:\windows\system32\iphlpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Эта служба предоставляет автоматическое подключение IPv6 в сети IPv4.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c60000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\WDSCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Panther Engine Module</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\system32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3740000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3b40000</BaseAddress>
<Size>245760</Size>
<Path>c:\windows\system32\wbem\wmisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3fa0000</BaseAddress>
<Size>331776</Size>
<Path>c:\windows\system32\srvsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) ресурсов для службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4160000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\wpnservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба системы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4480000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\taskcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оснастка обратной совместимости диспетчера задач</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4540000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\ProximityServicePAL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service PAL</Description>
</module>
<module>
<Timestamp>131795775380234927</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4cc0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ProximityCommonPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Common PAL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4dc0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\ProximityCommon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Универсальная реализация близкого взаимодействия</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4ee0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\ProximityService.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service Implementation</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5ef0000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\System32\MbaeApiPublic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Mobile Broadband Account API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7700000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\CredentialMigrationHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Migration Handler</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\sqmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SQM Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795783776936389</Timestamp>
<BaseAddress>0x7ffac7ce0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\usoapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Session Orchestrator API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d60000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\UpdatePolicy.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Policy Reader</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e90000</BaseAddress>
<Size>749568</Size>
<Path>c:\windows\system32\FVEAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows BitLocker Drive Encryption API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac82d0000</BaseAddress>
<Size>643072</Size>
<Path>c:\windows\system32\shsvcs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8590000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\LocationWinPalMisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Location Platform Abstraction Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac85c0000</BaseAddress>
<Size>1810432</Size>
<Path>c:\windows\system32\LocationFramework.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа географического положения Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8780000</BaseAddress>
<Size>274432</Size>
<Path>c:\windows\system32\UBPM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL единого диспетчера фоновых процессов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8b60000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\schedsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба планировщика заданий</Description>
</module>
<module>
<Timestamp>131795783774133461</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac91c0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\profsvcext.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvcExt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92a0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\sens.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба уведомления о системных событиях (SENS)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\themeservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы темы оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9420000</BaseAddress>
<Size>380928</Size>
<Path>c:\windows\system32\profsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvc</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9a70000</BaseAddress>
<Size>1257472</Size>
<Path>c:\windows\system32\gpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca700000</BaseAddress>
<Size>32768</Size>
<Path>c:\windows\system32\DABAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Desktop Activity Broker API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca720000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\bitsigd.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service IGD Support</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacab70000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба географического положения</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac40000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\seclogon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL службы вторичного входа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac50000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\bitsperf.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Perfmon Counter Access</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\MSWSOCK.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>25</ProcessIndex>
<ProcessId>372</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776305463443</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>c:\windows\system32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab91f0000</BaseAddress>
<Size>233472</Size>
<Path>c:\windows\system32\sstpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обеспечивает возможность использования SSTP для подключения к удаленным компьютерам с помощью VPN.</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795780812578370</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabc610000</BaseAddress>
<Size>540672</Size>
<Path>c:\windows\system32\w32time.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба времени Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabef00000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\cdpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба CDP Майкрософт (R)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05e0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\sbservicetrigger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Socket Broker Service Trigger</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795780812550384</Timestamp>
<BaseAddress>0x7ffac3290000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\fthsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль диагностики отказоустойчивой кучи Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4130000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\fdphost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба размещения поставщиков функций обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4200000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\perftrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Performance PerfTrack</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5b80000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\AuthBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API WinRT для веб-проверки подлинности</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66e0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\fdssdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery SSDP Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6960000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\fdwsd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery WS Discovery Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac76d0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\vmictimeprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Machine Integration Component Time Sync Provider Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7a10000</BaseAddress>
<Size>544768</Size>
<Path>c:\windows\system32\netprofmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер списка сетей</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7f70000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\licensemanagersvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManagerSvc</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90a0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\nsisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RPC-сервер интерфейса сохранения сети</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac91f0000</BaseAddress>
<Size>172032</Size>
<Path>c:\windows\system32\FontProvider.dll</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Font Provider Library</Description>
</module>
<module>
<Timestamp>131795780812573070</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9860000</BaseAddress>
<Size>1896448</Size>
<Path>c:\windows\system32\fntcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэша шрифтов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>c:\windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795780812567382</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>26</ProcessIndex>
<ProcessId>360</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311216195</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffabaad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\deviceaccess.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Broker And Policy COM Server</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac7e70000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\coreaudiopolicymanagerext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;coreaudiopolicymanagerext.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac87d0000</BaseAddress>
<Size>237568</Size>
<Path>c:\windows\system32\AUDIOSRVPOLICYMANAGER.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Audio Service Policy Manager</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac90d0000</BaseAddress>
<Size>978944</Size>
<Path>c:\windows\system32\audiosrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\POWRPROF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>27</ProcessIndex>
<ProcessId>1040</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311708649</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8820000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SYSTEM32\cmintegrator.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>cmintegrator.dll</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8c50000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wcmcsp.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Service Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8fe0000</BaseAddress>
<Size>737280</Size>
<Path>c:\windows\system32\wcmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы диспетчера подключений Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>28</ProcessIndex>
<ProcessId>1068</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776312395030</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\CRYPTNET.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\cryptcatsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Catalog Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65f0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\crypttpmeksvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic TPM Endorsement Key Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6680000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\cryptsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6f00000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\wkssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы рабочей станции</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79e0000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\netjoin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL присоединения к домену</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\WlanApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7c00000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\ssdpapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8260000</BaseAddress>
<Size>425984</Size>
<Path>c:\windows\system32\ncsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индикатор работоспособности сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8370000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\nlasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о подключенных сетях 2</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8410000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dnsext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DNS extension DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SYSTEM32\Fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8830000</BaseAddress>
<Size>290816</Size>
<Path>c:\windows\system32\dnsrslvr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэширующего сопоставителя DNS</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\JoinUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>29</ProcessIndex>
<ProcessId>1248</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776322176070</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>spoolsv.exe</ProcessName>
<ImagePath>C:\Windows\System32\spoolsv.exe</ImagePath>
<CommandLine>C:\Windows\System32\spoolsv.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер очереди печати</Description>
<modulelist>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ff639680000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\spoolsv.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер очереди печати</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffab8a60000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaba980000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\jscript.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabb7d0000</BaseAddress>
<Size>851968</Size>
<Path>C:\Windows\System32\win32spl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик печати с исполнением на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\prntvpt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Ticket Services Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd70000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_53d78f68bc1697cc\Amd64\PrintConfig.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc0c0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPFILEQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPFILEQ</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc590000</BaseAddress>
<Size>118784</Size>
<Path>C:\Program Files\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc5b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\amsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Anti-Malware Scan Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd040000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdPnp.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pnp Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd060000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\WSDMon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер порта принтера WSD</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd100000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\usbmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Standard Dynamic Printing Port Monitor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd160000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\wsnmp32.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft WinSNMP v2.0 Manager API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd2a0000</BaseAddress>
<Size>1159168</Size>
<Path>C:\Windows\System32\localspl.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека локального диспетчера очереди</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabde60000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\System32\tcpmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека монитора портов TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe3f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\spool\PRTPROCS\x64\winprint.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Print Processor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe6c0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\PrintIsolationProxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Sandbox COM Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe8a0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\snmpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SNMP Utility Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe980000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\SPOOLSS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Spooler SubSystem DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f00000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\FXSMON.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft  Fax Print Monitor</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac4e90000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\wshirda.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Sockets Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac7e00000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\inetpp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Internet Print Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>30</ProcessIndex>
<ProcessId>1512</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776336551242</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffabe9f0000</BaseAddress>
<Size>258048</Size>
<Path>c:\windows\system32\ssdpsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы SSDP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69b0000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\fdrespub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба публикации ресурсов обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>c:\windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>31</ProcessIndex>
<ProcessId>1556</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776339471770</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k utcsvc</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x272f9bf0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf140000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\CourtesyEngine.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Feedback Courtesy Engine DLL Server</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfde0000</BaseAddress>
<Size>143360</Size>
<Path>c:\windows\system32\CRYPTXML.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API-интерфейс XML DigSig</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\Netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\DSREG.DLL</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac5fd0000</BaseAddress>
<Size>1056768</Size>
<Path>c:\windows\system32\WindowsPerformanceRecorderControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Performance Recorder Control Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>c:\windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6210000</BaseAddress>
<Size>2007040</Size>
<Path>c:\windows\system32\diagtrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диагностическое отслеживание Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795784851898943</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795784853041383</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>32</ProcessIndex>
<ProcessId>1636</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776343009549</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k appmodel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>c:\windows\system32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3c10000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\tileobjserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер моделей данных плиток</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>c:\windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>c:\windows\system32\windows.staterepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795780599947775</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795780600943570</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>33</ProcessIndex>
<ProcessId>1744</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776348255325</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>MemCompression</ProcessName>
<ImagePath>MemCompression</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>34</ProcessIndex>
<ProcessId>2100</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776438403561</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffabff90000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\ipsecsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows IPsec SPD Server DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac1e00000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\FwRemoteSvr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall Remote APIs Server</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>35</ProcessIndex>
<ProcessId>2648</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777555980720</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>sihost.exe</ProcessName>
<ImagePath>C:\Windows\system32\sihost.exe</ImagePath>
<CommandLine>sihost.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Shell Infrastructure Host</Description>
<modulelist>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ff7bbae0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\sihost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Infrastructure Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb910000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\container.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Containers</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb970000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\daxexec.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>daxexec</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc450000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\system32\ShareHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShareHost</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc800000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\windowmanagement.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Window Management</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc850000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\AppointmentActivation.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL for AppointmentActivation</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc8b0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\NotificationPlatformComponent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationPlatformComponent</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc9a0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\activationmanager.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Activation Manager</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabca10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\ClipboardServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Modern Clipboard</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcde0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Windows\System32\modernexecserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Modern Execution</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcf10000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\desktopshellext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DesktopHost Extensions</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\system32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>36</ProcessIndex>
<ProcessId>840</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777563791648</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k UnistackSvcGroup</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf6a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\PhoneUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Phone utilities</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf700000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\System32\PIMSTORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>POOM</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab05d0000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\AccountAccessor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync data model to access accounts</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab0630000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\SyncController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SyncController for managing sync of mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb20000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\CEMAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CEMAPI</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcd80000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\cdpusersvc.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP User Components</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabd630000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\MCCSEngineShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Utilies shared among OneSync engines</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabdde0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\SYNCUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabed20000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\aphostservice.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>c:\windows\system32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4100000</BaseAddress>
<Size>151552</Size>
<Path>c:\windows\system32\NetworkHelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac97b0000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\InprocLogger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>In-proc Private Event Trace Logger</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca1d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\UserDataTypeHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Type Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca270000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\UserDataLanguageUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Language-related helper functions for user data</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca520000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\APHostClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service RPC Client </Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacabf0000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\MCCSPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform abstraction layer dll for MCCS</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacac20000</BaseAddress>
<Size>86016</Size>
<Path>c:\windows\system32\UserDataPlatformHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>37</ProcessIndex>
<ProcessId>528</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777565618284</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\system32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb440000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\system32\MTFServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;MTFServer.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb510000</BaseAddress>
<Size>2854912</Size>
<Path>C:\Windows\system32\InputService.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Text InputService Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8c0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\InputLocaleManager.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;InputLocaleManager.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8f0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\EditBufferTestHook.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;EditBufferTestHook.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb9f0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\system32\MSUTB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) сервера MSUTB</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabba70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\MsCtfMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MsCtfMonitor DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabbc20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\PlaySndSrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба PlaySound</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\system32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac7d10000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\KBDUS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>United States Keyboard Layout</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab10000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\WordBreakers.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;WordBreakers.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>38</ProcessIndex>
<ProcessId>3632</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777941176116</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>RuntimeBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\RuntimeBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\RuntimeBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Runtime Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7a45f0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\RuntimeBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Runtime Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\System32\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795780843802542</Timestamp>
<BaseAddress>0x7ffaad3f0000</BaseAddress>
<Size>1826816</Size>
<Path>C:\Windows\System32\Wpc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека параметров родительского контроля</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\mssrch.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795780489291214</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795780917042363</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795780917592192</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795780613006289</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795780733496994</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795780611542837</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795780918057976</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe880000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\FeClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT File Encryption Client Interfaces</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe8c0000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\system32\windows.cortana.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.Desktop</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780443980999</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf9c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\system32\windows.cortana.onecore.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.OneCore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795780634363506</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795779561161209</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780447369522</Timestamp>
<BaseAddress>0x7ffac37b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795771234179313</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795780489961900</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795780846908833</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5ca0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\AppExtension.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API AppExtension</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795780451650645</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795780641878393</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7d00000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SYSTEM32\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795780849625720</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780918548230</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\samlib.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795780611842861</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>39</ProcessIndex>
<ProcessId>3164</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778119045372</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ShellExperienceHost.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe&quot; -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Windows Shell Experience Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ff697570000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Experience Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f760000</BaseAddress>
<Size>3796992</Size>
<Path>C:\Windows\System32\MFMediaEngine.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Media Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaabad0000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\mfsrcsnk.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Source and Sink DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaafe70000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\System32\mfcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Core DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab0be0000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\ShellExperiences\NetworkUX.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab9eb0000</BaseAddress>
<Size>2899968</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.ActionCenter.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActionCenter Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaba180000</BaseAddress>
<Size>7880704</Size>
<Path>C:\Windows\ShellExperiences\StartUI.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Start UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SYSTEM32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd420000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\RTMediaFrame.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime MediaFrame DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe410000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\SYSTEM32\globcollationhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GlobCollationHost</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795780594734370</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0080000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\System32\resampledmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Resampler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0110000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\QuickActionsDataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>QuickActionsDataModel</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0160000</BaseAddress>
<Size>491520</Size>
<Path>C:\Windows\ShellExperiences\QuickActions.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac40f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4eb0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5b20000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\CompPkgSup.DLL</Path>
<Version>10.0.14393.969 (rs1_release_inmarket.170315-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Component Package Support DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5e90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\Windows.Media.MediaControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера MediaControl среды выполнения Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>40</ProcessIndex>
<ProcessId>4856</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778391112136</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MSASCuiL.exe</ProcessName>
<ImagePath>C:\Program Files\Windows Defender\MSASCuiL.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Windows Defender\MSASCuiL.exe&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Description>Windows Defender notification icon</Description>
<modulelist>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x23622c70000</BaseAddress>
<Size>733184</Size>
<Path>C:\Program Files\Windows Defender\EppManifest.dll</Path>
<Version>4.10.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль ресурсов настройки пользовательского интерфейса</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ff63bef0000</BaseAddress>
<Size>651264</Size>
<Path>C:\Program Files\Windows Defender\MSASCuiL.exe</Path>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Defender notification icon</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4560000</BaseAddress>
<Size>950272</Size>
<Path>C:\Program Files\Windows Defender\mpclient.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Client Interface</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>41</ProcessIndex>
<ProcessId>4928</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778406250112</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>uTorrent.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe&quot;  /MINIMIZED</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>3.5.4.44498</Version>
<Description>µTorrent</Description>
<modulelist>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>5406720</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</Path>
<Version>3.5.4.44498</Version>
<Company>BitTorrent Inc.</Company>
<Description>µTorrent</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e140000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SysWOW64\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1c0000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\SysWOW64\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6ef20000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70af0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fc0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fd0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fe0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>42</ProcessIndex>
<ProcessId>3608</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778496229053</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ApplicationFrameHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\ApplicationFrameHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\ApplicationFrameHost.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Application Frame Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ff6aa270000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\ApplicationFrameHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Frame Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5240000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\ApplicationFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фрейм приложения</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\system32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\D3D10Warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>43</ProcessIndex>
<ProcessId>5952</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778883326814</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54150_1240996307 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>44</ProcessIndex>
<ProcessId>5800</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765779120650795</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\esent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>45</ProcessIndex>
<ProcessId>340</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765800389528045</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54870_1839591030 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c50000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\Ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>46</ProcessIndex>
<ProcessId>2736</ProcessId>
<ParentProcessId>3976</ParentProcessId>
<ParentProcessIndex>47</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765800903010156</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Taskmgr.exe</ProcessName>
<ImagePath>C:\Windows\System32\Taskmgr.exe</ImagePath>
<CommandLine>&quot;C:\Windows\System32\Taskmgr.exe&quot; /2 </CommandLine>
<CompanyName>Microsoft® Windows® Operating System</CompanyName>
<Version>1, 0, 0, 1</Version>
<Description>Task Manager</Description>
<modulelist>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ff7c2a70000</BaseAddress>
<Size>1286144</Size>
<Path>C:\Windows\System32\Taskmgr.exe</Path>
<Version>1, 0, 0, 1</Version>
<Company>Microsoft® Windows® Operating System</Company>
<Description>Task Manager</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdfa0000</BaseAddress>
<Size>393216</Size>
<Path>C:\Windows\System32\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\System32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>49</ProcessIndex>
<ProcessId>6724</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803507001117</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHActiveDefense.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe&quot;</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1008</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795778431738530</Timestamp>
<BaseAddress>0x10000</BaseAddress>
<Size>413696</Size>
<Path>C:\ProgramData\Package Cache\{b8e12890-118d-4721-8e54-05d978086712}\VC_redist.x64.exe</Path>
<Version>14.0.24516.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24516</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0xd0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</Path>
<Version>10,0,0,1008</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795778469924367</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Wireshark\WinPcap_4_1_3.exe</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>WinPcap 4.1.3 installer</Description>
</module>
<module>
<Timestamp>131795778203065490</Timestamp>
<BaseAddress>0x840000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files\Wireshark\vcredist_x64.exe</Path>
<Version>14.12.25810.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810</Description>
</module>
<module>
<Timestamp>131795780232774368</Timestamp>
<BaseAddress>0x34c0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x3c80000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795780944214585</Timestamp>
<BaseAddress>0x40a0000</BaseAddress>
<Size>438272</Size>
<Path>C:\Program Files\Wireshark\dumpcap.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community</Company>
<Description>Dumpcap</Description>
</module>
<module>
<Timestamp>131795780231568066</Timestamp>
<BaseAddress>0x4630000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SysWOW64\net1.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Command</Description>
</module>
<module>
<Timestamp>131795778389953959</Timestamp>
<BaseAddress>0xa8e0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778421734438</Timestamp>
<BaseAddress>0xe830000</BaseAddress>
<Size>6127616</Size>
<Path>C:\Windows\System32\mfc140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>MFCDLL Shared Library - Retail Version</Description>
</module>
<module>
<Timestamp>131795780691287613</Timestamp>
<BaseAddress>0xf730000</BaseAddress>
<Size>8298496</Size>
<Path>C:\Program Files\Wireshark\Wireshark.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark</Description>
</module>
<module>
<Timestamp>131795780222197886</Timestamp>
<BaseAddress>0x10000000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fb90000</BaseAddress>
<Size>2736128</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\deepscan.dll</Path>
<Version>3, 5, 1, 2130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60190000</BaseAddress>
<Size>475136</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360SafeCamera.tpi</Path>
<Version>2, 0, 0, 1031</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60210000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\jcloudscan.dll</Path>
<Version>1, 0, 0, 1012</Version>
<Company>360.cn</Company>
<Description>360安全卫士 移动云查询模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604a0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appdext.dll</Path>
<Version>1, 0, 0, 1483</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604e0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\DrvUtility.dll</Path>
<Version>1, 0, 0, 1081</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60510000</BaseAddress>
<Size>409600</Size>
<Path>C:\Program Files (x86)\360\Total Security\SafeScan.dll</Path>
<Version>1, 0, 0, 1074</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60580000</BaseAddress>
<Size>204800</Size>
<Path>C:\Program Files (x86)\360\Total Security\ScanStub.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x605c0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360gameidentify.dll</Path>
<Version>1, 0, 1, 1050</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏识别模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60640000</BaseAddress>
<Size>430080</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\Netgm.dll</Path>
<Version>9,0,0,1005</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏模式判断模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60a50000</BaseAddress>
<Size>479232</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\DsSysRepair.dll</Path>
<Version>1, 0, 0, 1062</Version>
<Company>QIHU360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security System Repair Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61000000</BaseAddress>
<Size>184320</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\qutmipc.dll</Path>
<Version>7, 3, 0, 1267</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61030000</BaseAddress>
<Size>262144</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg.dll</Path>
<Version>3, 0, 0, 1160</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x610d0000</BaseAddress>
<Size>1097728</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\SomAdvUtils.dll</Path>
<Version>3, 1, 1, 2020</Version>
<Company>360.cn</Company>
<Description>360 Safeguard PC Boost</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61480000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qex\qex.dll</Path>
<Version>4.1.13.3366</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2017 Antivirus</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x616a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SelfProtectAPI2.dll</Path>
<Version>7, 1, 1, 1033</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61700000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360procmon.dll</Path>
<Version>7, 1, 1, 1221</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61780000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\netdefender.dll</Path>
<Version>1, 0, 0, 1129</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x617e0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appd.dll</Path>
<Version>7, 3, 6, 3113</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360HipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61ab0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\fileMgr.dll</Path>
<Version>7, 3, 0, 1963</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x621a0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\yhregd.dll</Path>
<Version>7, 2, 0, 1903</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62280000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\360SoftMgrS.dll</Path>
<Version>2, 1, 6, 1490</Version>
<Company>360.cn</Company>
<Description>360软件管家 服务模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62470000</BaseAddress>
<Size>405504</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll</Path>
<Version>7, 2, 1, 1279</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x624e0000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\360box.dll</Path>
<Version>2, 0, 0, 1043</Version>
<Company>360.cn</Company>
<Description>360隔离沙箱模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\deepscan\DsRes.dll</Path>
<Version>1,0,0,1012</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security Resource</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b70000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\gamemode.tpi</Path>
<Version>9,0,0,1001</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Game Mode Control</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67130000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\devenum.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечисление устройств.</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\fltlib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6c0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6ea80000</BaseAddress>
<Size>860160</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\QVM\360QVM.dll</Path>
<Version>5.0.2.1003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security QVM Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70210000</BaseAddress>
<Size>966656</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEngine.dll</Path>
<Version>1, 0, 0, 2016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70300000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEI.dll</Path>
<Version>1, 0, 0, 2003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>50</ProcessIndex>
<ProcessId>6340</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765803510844292</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>QHSafeTray.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</ImagePath>
<CommandLine>/showtrayicon</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1024</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0xec0000</BaseAddress>
<Size>2351104</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</Path>
<Version>10,0,0,1024</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x68f0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c480000</BaseAddress>
<Size>245760</Size>
<Path>C:\Program Files (x86)\360\Total Security\PDown.dll</Path>
<Version>1, 3, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Security Center Network Module </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5fe30000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll</Path>
<Version>9,6,0,1001</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60020000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360netctrl.dll</Path>
<Version>5, 3, 15, 2232</Version>
<Company>360.cn</Company>
<Description>360 Total Security NetwokrMonCtrl</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60090000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\netmon.tpi</Path>
<Version>5, 1, 1, 3157</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360安全卫士 流量防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60350000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Program Files (x86)\360\Total Security\ToolBox.dll</Path>
<Version>1, 0, 0, 1094</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x606b0000</BaseAddress>
<Size>598016</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe.dll</Path>
<Version>1, 0, 0, 1120</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x609b0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360GuardBase.dll</Path>
<Version>3, 1, 0, 1060</Version>
<Company>360.cn</Company>
<Description>360保镖</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61070000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SomProxy.dll</Path>
<Version>1, 0, 0, 1900</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x611e0000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360connect.tpi</Path>
<Version>9,2,0,1030</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Connect</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x618c0000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files (x86)\360\Total Security\sites.dll</Path>
<Version>11, 1, 0, 1212</Version>
<Company>360.cn</Company>
<Description>360安全卫士</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360hipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\softmgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\Cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62210000</BaseAddress>
<Size>446464</Size>
<Path>C:\Program Files (x86)\360\Total Security\360TSCommon.dll</Path>
<Version>9, 0, 0, 1016</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62960000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\CleanPlusCache.tpi</Path>
<Version>1, 0, 0, 1004</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>CleanPlusCache</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795771279916892</Timestamp>
<BaseAddress>0x68850000</BaseAddress>
<Size>2764800</Size>
<Path>C:\Windows\SysWOW64\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e6e0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e770000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SysWOW64\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71170000</BaseAddress>
<Size>466944</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\CQhCltHttpW.dll</Path>
<Version>1, 4, 0, 1030</Version>
<Company>QIHU 360 SOFTWARE  CO. LIMITED</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>51</ProcessIndex>
<ProcessId>6860</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803555957830</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHWatchdog.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe&quot; /watch</CommandLine>
<CompanyName>QIHU 360 SOFTWARE CO. LIMITED</CompanyName>
<Version>8,2,0,1000</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0xdf0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</Path>
<Version>8,2,0,1000</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>52</ProcessIndex>
<ProcessId>5924</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765805232900810</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>wmiprvse.exe</ProcessName>
<ImagePath>C:\Windows\sysWOW64\wbem\wmiprvse.exe</ImagePath>
<CommandLine>C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Description>WMI Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x950000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\sysWOW64\wbem\wmiprvse.exe</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Provider Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\storagewmi_passthru.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60160000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x604d0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\delegatorprovider.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>54</ProcessIndex>
<ProcessId>4408</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765812380694767</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x17826230000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1140000</BaseAddress>
<Size>1134592</Size>
<Path>C:\Windows\System32\ReAgent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>C:\Windows\System32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\system32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe000000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\system32\WinSATAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Assessment Tool API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf050000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\sdiageng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема выполнения сценариев диагностики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4ae0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sdiagschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запланированная задача сценариев проверки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4b00000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\MemoryDiagnostic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач средства проверки памяти Windows (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac5c80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\TempSignedLicenseExchangeTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TempSignedLicenseExchangeTask Task</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca200000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\ReAgentTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca210000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\RstrtMgr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер перезапуска</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacac00000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\radarrs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>программа устранения нехватки системных ресурсов Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>55</ProcessIndex>
<ProcessId>6944</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131767576301455145</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SkypeHost.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe&quot; -ServerName:SkypeHost.ServerServer</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>12.1815.210.0</Version>
<Description>Microsoft Skype</Description>
<modulelist>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ff7e8670000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaae130000</BaseAddress>
<Size>22437888</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkyWrap.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabe150000</BaseAddress>
<Size>2691072</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\skypert.dll</Path>
<Version>2018.15.01.31</Version>
<Company></Company>
<Description>SkypeRT shared library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1a80000</BaseAddress>
<Size>978944</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7c80000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>56</ProcessIndex>
<ProcessId>1048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131768729449405953</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>sedsvc.exe</ProcessName>
<ImagePath>C:\Program Files\rempl\sedsvc.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\rempl\sedsvc.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Description>sedsvc</Description>
<modulelist>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ff751430000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\rempl\sedsvc.exe</Path>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>sedsvc</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>57</ProcessIndex>
<ProcessId>7744</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081112364684</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; </CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x11330000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60900000</BaseAddress>
<Size>720896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\urlproc.dll</Path>
<Version>2, 9, 5, 1260</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x68b00000</BaseAddress>
<Size>44998656</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ce30000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6dc80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files (x86)\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6df70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\SysWOW64\shdocvw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e070000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e090000</BaseAddress>
<Size>233472</Size>
<Path>C:\Windows\SysWOW64\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e110000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e120000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multimedia Realtime Runtime</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e2a0000</BaseAddress>
<Size>4440064</Size>
<Path>C:\Windows\SysWOW64\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb60000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb70000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ec40000</BaseAddress>
<Size>442368</Size>
<Path>C:\Windows\SysWOW64\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd00000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd20000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe40000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe50000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SysWOW64\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ff90000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\SysWOW64\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ffe0000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\SysWOW64\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70190000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x701a0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\dllyupdate.dll</Path>
<Version>1.2.0.1831</Version>
<Company>Yandex LLC</Company>
<Description>Yandex updater (CU)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b30000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\WINUSB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows USB Driver User Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b60000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x711f0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>58</ProcessIndex>
<ProcessId>5696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081114193232</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe --type=crashpad-handler &quot;--user-data-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler &quot;--database=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data\Crashpad&quot; &quot;--metrics-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; --url=https://crash-reports.browser.yandex.net/submit --annotation=machine_id=c46245ef0fec9d5c44d2fa20241f2070 --annotation=main_process_pid=7744 --annotation=metrics_client_id=520f4dd3247d4cdfb744f32b1130b1bf --annotation=plat=Win32 --annotation=prod=Yandex --annotation=ver=18.6.1.770 --initial-client-data=0x1c4,0x1cc,0x1d0,0x1c0,0x1d4,0x700b800c,0x700b7ffc,0x700b7fe0,0x1c8</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>59</ProcessIndex>
<ProcessId>4664</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081123844756</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=gpu-process --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --service-request-channel-token=CC1AC8FA9C8EFF1EEBC2375FE4F704C6 --mojo-platform-channel-handle=1588 --ignored=&quot; --type=renderer &quot; /prefetch:2</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ecb0000</BaseAddress>
<Size>2228224</Size>
<Path>C:\Windows\SysWOW64\mfh264enc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation H264 Encoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f250000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\SysWOW64\ddraw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectDraw</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f340000</BaseAddress>
<Size>3784704</Size>
<Path>C:\Windows\SysWOW64\D3DCompiler_47.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D HLSL Compiler</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f6e0000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\SysWOW64\msvproc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Video Processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fbe0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\mf.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff20000</BaseAddress>
<Size>118784</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\swiftshader\libegl.dll</Path>
<Version>4.0.0.3</Version>
<Company></Company>
<Description>SwiftShader libEGL 32-bit Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dxva2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Video Acceleration 2.0 DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x705d0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\DCIMAN32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DCI Manager</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>60</ProcessIndex>
<ProcessId>8968</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081206363215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=183F52B8A6577BFD721F95F3A9641348 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=183F52B8A6577BFD721F95F3A9641348 --renderer-client-id=4 --mojo-platform-channel-handle=2640 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>61</ProcessIndex>
<ProcessId>4992</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081244357280</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=7E8A8199C364F4B0114F2A163B757250 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E8A8199C364F4B0114F2A163B757250 --renderer-client-id=10 --mojo-platform-channel-handle=3904 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>63</ProcessIndex>
<ProcessId>9504</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956266598229</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgent.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgent.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgent.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>InstallAgent</Description>
<modulelist>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ff63d380000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\InstallAgent.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffabea60000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\VEStoreEventHandlers.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDL Store Event Handlers</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4ad0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\EAMProgressHandler.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>EAMProgressHandler</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>64</ProcessIndex>
<ProcessId>8768</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956321853179</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgentUserBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgentUserBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgentUserBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>InstallAgentUserBroker</Description>
<modulelist>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x22530450000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ff74f890000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\InstallAgentUserBroker.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgentUserBroker</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>65</ProcessIndex>
<ProcessId>9636</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956424585250</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettingsBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\SystemSettingsBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\SystemSettingsBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>System Settings Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ff6015f0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\SystemSettingsBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Broker</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>66</ProcessIndex>
<ProcessId>10592</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956519902643</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettings.exe</ProcessName>
<ImagePath>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</ImagePath>
<CommandLine>&quot;C:\Windows\ImmersiveControlPanel\SystemSettings.exe&quot; -ServerName:microsoft.windows.immersivecontrolpanel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Параметры</Description>
<modulelist>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x18099ef0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\WMI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI DC and DP functionality</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ff7937a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaabce0000</BaseAddress>
<Size>2535424</Size>
<Path>C:\Windows\System32\NetworkMobileSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System settings network mobile handlers group</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac220000</BaseAddress>
<Size>4952064</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Application</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaadd90000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\NetworkDesktopSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Группа обработчиков системных параметров сетевого рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaaf920000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettingsViewModel.Desktop.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings View Model Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0970000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\credprovhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост инфраструктуры поставщика учетных данных</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0a70000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\System32\fhcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигураций истории файлов</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\SYSTEM32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\SYSTEM32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab91d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\ImmersiveControlPanel\Telemetry.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Telemetry Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcc60000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\System32\MiracastReceiver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API приемника Miracast</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2bf0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\EFSUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>EFS Utility Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\SYSTEM32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\wmiclnt.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca560000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\NcaApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Network Connectivity Assistant API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>67</ProcessIndex>
<ProcessId>10964</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794956837373387</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{BA126F01-2166-11D1-B1D0-00805FC1270E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\system32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>69</ProcessIndex>
<ProcessId>10000</ProcessId>
<ParentProcessId>8940</ParentProcessId>
<ParentProcessIndex>68</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794957424930105</CreateTime>
<FinishTime>131795782451673064</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>AdobeIPCBroker.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe&quot; &quot;-launchedbyvulcan&quot;</CommandLine>
<CompanyName>Adobe Systems Incorporated</CompanyName>
<Version>5.0.0.76</Version>
<Description>Adobe IPC Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0xbe0000</BaseAddress>
<Size>798720</Size>
<Path>C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe</Path>
<Version>5.0.0.76</Version>
<Company>Adobe Systems Incorporated</Company>
<Description>Adobe IPC Broker</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645384008</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>76</ProcessIndex>
<ProcessId>11496</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958406617238</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SearchUI.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe&quot; -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>Search and Cortana application</Description>
<modulelist>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ff79c3c0000</BaseAddress>
<Size>10706944</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Search and Cortana application</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\SYSTEM32\chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\SYSTEM32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4c70000</BaseAddress>
<Size>4874240</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab52c0000</BaseAddress>
<Size>2445312</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5840000</BaseAddress>
<Size>3108864</Size>
<Path>C:\Windows\System32\Speech_OneCore\Common\sapi_onecore.dll</Path>
<Version>5.3.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Speech API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5db0000</BaseAddress>
<Size>9781248</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9d50000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;CortanaApi.ProxyStub.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe770000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabefa0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\Cortana.Persona.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana.Persona</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac10b0000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\PersonaX.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PersonaX</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\SYSTEM32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3bf0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionMgr.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana Action Manager</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bb0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\windows.cortana.pal.desktop.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.PAL.Desktop</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7c50000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\BingConfigurationClient.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bing Configuration Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\SYSTEM32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780654647361</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>79</ProcessIndex>
<ProcessId>5612</ProcessId>
<ParentProcessId>904</ParentProcessId>
<ParentProcessIndex>22</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131794965205293998</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>dashost.exe</ProcessName>
<ImagePath>C:\Windows\system32\dashost.exe</ImagePath>
<CommandLine>dashost.exe {609e1ffd-7b4d-4dbc-a36f725917d81f2d}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Device Association Framework Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ff6559c0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\dashost.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Framework Provider Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabb1a0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\DAFWSD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF WSD Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabc970000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\dafupnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF UPnP Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>80</ProcessIndex>
<ProcessId>9720</ProcessId>
<ParentProcessId>9180</ParentProcessId>
<ParentProcessIndex>81</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794969418818027</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Windows10UpgraderApp.exe</ProcessName>
<ImagePath>C:\Windows10Upgrade\Windows10UpgraderApp.exe</ImagePath>
<CommandLine>&quot;C:\Windows10Upgrade\Windows10UpgraderApp.exe&quot;  /Install /ClientID Win10Upgrade:VNL:NHV18:{} /SkipEULA /PostEosUi</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>1.4.9200.22452</Version>
<Description>Помощник по обновлению Windows 10</Description>
<modulelist>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0xb30000</BaseAddress>
<Size>1875968</Size>
<Path>C:\Windows10Upgrade\Windows10UpgraderApp.exe</Path>
<Version>1.4.9200.22452</Version>
<Company>Microsoft Corporation</Company>
<Description>Помощник по обновлению Windows 10</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d6e0000</BaseAddress>
<Size>634880</Size>
<Path>C:\Windows\SysWOW64\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d780000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\SysWOW64\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d860000</BaseAddress>
<Size>1245184</Size>
<Path>C:\Windows\SysWOW64\MFC42u.dll</Path>
<Version>6.06.8063.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека MFCDLL - розничная версия</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6ded0000</BaseAddress>
<Size>630784</Size>
<Path>C:\Windows\SysWOW64\ODBC32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ODBC Driver Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfc0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfd0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SysWOW64\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e010000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows10Upgrade\Downloader.dll</Path>
<Version>1.4.9200.22452 (win8_ldr.180426-0600)</Version>
<Company>Microsoft Corporation</Company>
<Description>Downloader</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e050000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.DLL</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>82</ProcessIndex>
<ProcessId>8944</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795005508439638</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>fontdrvhost.exe</ProcessName>
<ImagePath>C:\Windows\system32\fontdrvhost.exe</ImagePath>
<CommandLine>&quot;fontdrvhost.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Usermode Font Driver Host</Description>
<modulelist>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ff654db0000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\system32\fontdrvhost.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Usermode Font Driver Host</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>83</ProcessIndex>
<ProcessId>6684</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795006053748558</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Microsoft.Photos.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe&quot; -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ff705e40000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bb10000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bc70000</BaseAddress>
<Size>3158016</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bf80000</BaseAddress>
<Size>2994176</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9c260000</BaseAddress>
<Size>20144128</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9d5a0000</BaseAddress>
<Size>29011968</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9fb20000</BaseAddress>
<Size>7950336</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.3_1.3.24201.0_x64__8wekyb3d8bbwe\SharedLibrary.dll</Path>
<Version></Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Shared Framework</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa03f0000</BaseAddress>
<Size>4546560</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\FaceSdkStoreWrapper.dll</Path>
<Version>16.425.0.0</Version>
<Company>Microsoft Corporation</Company>
<Description>FaceSdkStoreWrapper</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa0850000</BaseAddress>
<Size>2371584</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\MediaEngine.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab270000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\System32\Windows.AccountsControl.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Accounts Control</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\Windows.System.Diagnostics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Diagnostics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f60000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\CryptoWinRT.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto WinRT Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9270000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9b40000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x64__8wekyb3d8bbwe\mrt100_app.dll</Path>
<Version>1.4.24201.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabea30000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\Windows.Energy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Energy Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0fa0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1c70000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCOMP140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C/C++ OpenMP Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2c00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\clrcompression.dll</Path>
<Version>1.0.23123.00 built by: PROJECTKREL</Version>
<Company>Microsoft Corporation</Company>
<Description>ClrCompression</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SYSTEM32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\mrt100.dll</Path>
<Version>1.0.24120.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OleAut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>84</ProcessIndex>
<ProcessId>6208</ProcessId>
<ParentProcessId>12140</ParentProcessId>
<ParentProcessIndex>85</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795181740423780</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>OneDrive.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</ImagePath>
<CommandLine> /updateInstalled /background</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>18.131.0701.0007</Version>
<Description>Microsoft OneDrive</Description>
<modulelist>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x11f0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x55a0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSync.Resources.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\MSHTML.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6bab0000</BaseAddress>
<Size>4472832</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Widgets.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d210000</BaseAddress>
<Size>4993024</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Gui.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\Wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ce0000</BaseAddress>
<Size>1519616</Size>
<Path>C:\Windows\SysWOW64\wpc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека параметров родительского контроля</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70f00000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71200000</BaseAddress>
<Size>708608</Size>
<Path>C:\Windows\SysWOW64\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x712b0000</BaseAddress>
<Size>602112</Size>
<Path>C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71350000</BaseAddress>
<Size>2867200</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Quick.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71630000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x716b0000</BaseAddress>
<Size>1294336</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LIBEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x717f0000</BaseAddress>
<Size>2637824</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Qml.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71a80000</BaseAddress>
<Size>4796416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Core.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71f20000</BaseAddress>
<Size>6033408</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SyncEngine.DLL</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Sync Engine</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72530000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72550000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72810000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72820000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SysWOW64\MicrosoftAccountTokenProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Token Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72850000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\SysWOW64\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728b0000</BaseAddress>
<Size>135168</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncFAL.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDriveFile Sync FAL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\SysWOW64\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72bb0000</BaseAddress>
<Size>1105920</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\platforms\qwindows.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e90000</BaseAddress>
<Size>299008</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SSLEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ee0000</BaseAddress>
<Size>950272</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Network.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72fd0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\loadperf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Загрузка и выгрузка счетчиков производительности</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ff0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\pdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль поддержки данных производительности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73040000</BaseAddress>
<Size>253952</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5WinExtras.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73080000</BaseAddress>
<Size>880640</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ADAL.dll</Path>
<Version>1.0.2110.0526</Version>
<Company>Microsoft</Company>
<Description>ADAL.Native</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73160000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WSOCK32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73170000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SysWOW64\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x731d0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\WnsClientApi.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive WNS Client Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73240000</BaseAddress>
<Size>520192</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LogUploader.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive Sync LogUploader Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x732c0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncViews.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Qt Components</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73400000</BaseAddress>
<Size>159744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\UpdateRingSettings.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Ring Settings</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73430000</BaseAddress>
<Size>1748992</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncSessions.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>P2P Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x735e0000</BaseAddress>
<Size>671744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\RemoteAccess.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73690000</BaseAddress>
<Size>188416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Telemetry.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Telemetry Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ETWLog.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>ETW Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736d0000</BaseAddress>
<Size>3600384</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncClient.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Client</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73af0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LoggingPlatform.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Logging Platform</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73dc0000</BaseAddress>
<Size>1171456</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ucrtbase.dll</Path>
<Version>10.0.17134.12 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73fb0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\MSWSOCK.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74090000</BaseAddress>
<Size>462848</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\MSVCP140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\VCRUNTIME140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74220000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>86</ProcessIndex>
<ProcessId>6140</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795747339404666</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=764E64A4EA650A23B18EB059FF0B4B51 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=764E64A4EA650A23B18EB059FF0B4B51 --renderer-client-id=106 --mojo-platform-channel-handle=6612 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>87</ProcessIndex>
<ProcessId>11432</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755605761168</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=9DD318D38190D474A9A0F5AFD262A449 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=9DD318D38190D474A9A0F5AFD262A449 --renderer-client-id=109 --mojo-platform-channel-handle=4152 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>88</ProcessIndex>
<ProcessId>10384</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755746873891</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=7E669976FFDCEE94D9B90B02CADE1179 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E669976FFDCEE94D9B90B02CADE1179 --renderer-client-id=112 --mojo-platform-channel-handle=5412 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>90</ProcessIndex>
<ProcessId>6936</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795756360200321</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --renderer-client-id=116 --mojo-platform-channel-handle=4024 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>98</ProcessIndex>
<ProcessId>6080</ProcessId>
<ParentProcessId>84</ParentProcessId>
<ParentProcessIndex>97</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795771125310655</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MCLauncher.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe&quot; </CommandLine>
<CompanyName></CompanyName>
<Version>1.0</Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795771127806606</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>2830336</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Version>1.0</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771129292604</Timestamp>
<BaseAddress>0x750000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771335510731</Timestamp>
<BaseAddress>0x11000000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771334241016</Timestamp>
<BaseAddress>0x12000000</BaseAddress>
<Size>360448</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771129285523</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795771129286235</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795771129295328</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795771135408057</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795771129575672</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129398434</Timestamp>
<BaseAddress>0x66680000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771136825814</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795771129423112</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771129349562</Timestamp>
<BaseAddress>0x6b830000</BaseAddress>
<Size>2584576</Size>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795771329638947</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795771329610149</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795771329592759</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795771136045859</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795771131298623</Timestamp>
<BaseAddress>0x6d180000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795771136082794</Timestamp>
<BaseAddress>0x6dca0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Script Runtime</Description>
</module>
<module>
<Timestamp>131795771133718253</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795771129406131</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795771329618480</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795771329601483</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795771336447829</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771135435621</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795771135446667</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771136073867</Timestamp>
<BaseAddress>0x70e90000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Script Host Runtime Library</Description>
</module>
<module>
<Timestamp>131795771135423397</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795771135552456</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795771136181434</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771328759427</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771135541570</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795771347140137</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795771347110306</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795771135314174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771347090516</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795771347075776</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795771328179609</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795771130913562</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795771135359123</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795771129415027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795771130899582</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795771133098293</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795771132990161</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795771131765102</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795771129389543</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795771129317462</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795771129360685</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795771129360034</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771129496759</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795771129358136</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129357408</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795771129365891</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795771129359203</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795771129353720</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771135412052</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795771129350362</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795771129366695</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795771136054082</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795771131750596</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795771129363162</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795771328737550</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795771135228888</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795771129301509</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771129362062</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795771135227735</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795771129363985</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795771129356607</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795771129364960</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795771129354665</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795771129370252</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795771129352041</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795771129367584</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795771129351257</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771129361361</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795771129369244</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129368545</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795771131168008</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795771129352931</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771133704572</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795771129355632</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795771347076821</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795771127807387</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795771127807116</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>104</ProcessIndex>
<ProcessId>12696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777567759490</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=E83DB721798C8A70C76CD26F6F4EE1BC --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=E83DB721798C8A70C76CD26F6F4EE1BC --renderer-client-id=119 --mojo-platform-channel-handle=7052 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777567991690</Timestamp>
<BaseAddress>0xc00000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777567961139</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777569452751</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777567980184</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777567981270</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777567994943</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777570994535</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777570968696</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777570908362</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777570920904</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777570943637</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777570874151</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777570891841</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777568100773</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777570569484</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777570619251</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777570607590</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777570676211</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777570557202</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777570691164</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777570539079</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777569494420</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777570658737</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777569526517</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777569154123</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777570594964</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777570630821</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777570523174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777570582120</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777570646486</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777570953652</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777569213807</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777568156054</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777569481011</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777568142933</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777568179155</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777568043561</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777568042430</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777569239058</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777568075566</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777568073430</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777568086784</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777568041126</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777568081914</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777568046844</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777568038347</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777568088134</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777569468247</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777569466798</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777568077279</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777569469408</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777568024100</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777568039823</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777569470854</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777568036731</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777568054568</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777568078714</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777568050811</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777568084892</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777568089486</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777568083413</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777568044758</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777569464930</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777569463567</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777568116745</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777568080182</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777569457550</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777568052363</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777570632192</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777567961904</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777567961630</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>106</ProcessIndex>
<ProcessId>5556</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777595302537</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=3ADFA2396247AD5E547F61590603D06D --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=3ADFA2396247AD5E547F61590603D06D --renderer-client-id=121 --mojo-platform-channel-handle=6636 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777595490187</Timestamp>
<BaseAddress>0x1020000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595475498</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595491301</Timestamp>
<BaseAddress>0x5550000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777596381097</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595481485</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777595482474</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777595494304</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777597543015</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777597521210</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777597472595</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777597484525</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777597497517</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777597428793</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777597448444</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777595565558</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777597103476</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777597165296</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777597153510</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777597221087</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777597072535</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777597233493</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777597059294</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777596424202</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777597205195</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777596436120</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777596128973</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777597128037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777597177209</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777597044137</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777597116160</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777597192860</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777597506812</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777596148547</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777595627397</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777596410831</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777595610560</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777595638942</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777595529014</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777595527983</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777596182171</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777595541526</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777595540326</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777595551866</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777595526606</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777595547732</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777595531563</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777595524005</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777595553384</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777596396507</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777596394953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777595543299</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777596397607</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777595508927</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595525398</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777596398892</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777595522182</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777595538927</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777595544568</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777595535397</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777595550455</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777595554628</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777595549128</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777595530150</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777596393437</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777596392132</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777595583766</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777595545878</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777596385979</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777595536930</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777597178434</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777595476066</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777595475814</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>111</ProcessIndex>
<ProcessId>9032</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777895284069</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>explorer.exe</ProcessName>
<ImagePath>C:\Windows\explorer.exe</ImagePath>
<CommandLine>C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795777911330291</Timestamp>
<BaseAddress>0x4d80000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795777920515787</Timestamp>
<BaseAddress>0x6530000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\Microsoft Office\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795777903881315</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795777903867506</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795777895813346</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\explorer.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795777906005639</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\duser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795777922060868</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795777918507242</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795777907532495</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\System32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795777910997447</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795777915260331</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795777910978745</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\System32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795778008622616</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795778007235790</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\devrtl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795777909146457</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795777902950088</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\System32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795778007048279</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795777902932644</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795777909802797</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777909791020</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777917395017</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\linkinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795777918158137</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795777966565943</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795777908125051</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795777905900322</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\dui70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795777908270107</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795777922014669</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\System32\networkexplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795778007216762</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795777919764442</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795777915281766</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795777909775471</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795777910387599</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795777905243222</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795777919412503</Timestamp>
<BaseAddress>0x7ffac1710000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\amd64\FileSyncShell64.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795777904716802</Timestamp>
<BaseAddress>0x7ffac18b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg64.dll</Path>
<Version>1, 0, 0, 1140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795777944562485</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795777903915791</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777922001525</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795777903903305</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777909321798</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777909330655</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777906462233</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795777910949757</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795777920555307</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795777906356495</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795777905097743</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\System32\ExplorerFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795777908567233</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795777911007559</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795777914831974</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795777905390625</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777902894862</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795777906986296</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795777906995835</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795777903975733</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795777906257948</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795777919424461</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795777902880674</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777908138610</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795777902921260</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778008641775</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795777907005063</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795777918659102</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777918649579</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777909306748</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795777902905939</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795777906474194</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902941219</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795778008632518</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795777918171528</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795777907014508</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777903933947</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777902985171</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777903008375</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777902974089</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777905657867</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795777902999880</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777902852334</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777902849489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777902853126</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777902855116</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777902843222</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777902836309</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902838974</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777902841617</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777902844144</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777902848566</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777902824318</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777902854301</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777902835470</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902847555</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777902846521</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777902834719</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777916996283</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795777902838016</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777902833378</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777904879129</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777902823359</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777905449820</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795777920556415</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795777902842396</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777903888252</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777903413262</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777902840664</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777902837229</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777903887407</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795777902850328</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777903886124</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777902845086</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777902851375</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777895813598</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>123</ProcessIndex>
<ProcessId>284</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778236890994</CreateTime>
<FinishTime>131795782047703513</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k swprv</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795778236948261</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795778237990704</Timestamp>
<BaseAddress>0x7ffabd220000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\System32\swprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик программного обеспечения Microsoft® Volume Shadow Copy Service</Description>
</module>
<module>
<Timestamp>131795778238024341</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fltLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795778238689559</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795778238016772</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\virtdisk.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Disk API DLL</Description>
</module>
<module>
<Timestamp>131795778238009807</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\vsstrace.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795778238797239</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\System32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795778238379317</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795778238002742</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\devobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795778238084884</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795778238106525</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778238119208</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778237848893</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778238069532</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778238117518</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778238087879</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778237826515</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778238085768</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778238691232</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778238003645</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778238690445</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778237846089</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778237991665</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778238360028</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778237825108</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778238118419</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778238798278</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795778238116693</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778238067953</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778237992699</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778237844499</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778236948497</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>124</ProcessIndex>
<ProcessId>8572</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778253406568</CreateTime>
<FinishTime>131795781433108472</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>msiexec.exe</ProcessName>
<ImagePath>C:\Windows\system32\msiexec.exe</ImagePath>
<CommandLine>C:\Windows\system32\msiexec.exe /V</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Установщик Windows®</Description>
<modulelist>
<module>
<Timestamp>131795778259596194</Timestamp>
<BaseAddress>0x238870a0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\System32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778253563850</Timestamp>
<BaseAddress>0x7ff766ba0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\msiexec.exe</Path>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Установщик Windows®</Description>
</module>
<module>
<Timestamp>131795778259570059</Timestamp>
<BaseAddress>0x7ffaad900000</BaseAddress>
<Size>4726784</Size>
<Path>C:\Windows\AppPatch\apppatch64\AcLayers.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795778267501772</Timestamp>
<BaseAddress>0x7ffab1260000</BaseAddress>
<Size>10350592</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll</Path>
<Version>4.7.2117.0 built by: NET47REL1LAST</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Common Language Runtime - WorkStation</Description>
</module>
<module>
<Timestamp>131795778276928618</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\devrtl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795778275324308</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795778275333446</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795778259610277</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795778259661596</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778265457583</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795778267747643</Timestamp>
<BaseAddress>0x7ffabfa00000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\msvcr120_clr0400.dll</Path>
<Version>12.00.52519.0 built by: VSWINSERVICING</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778260359664</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795778399983100</Timestamp>
<BaseAddress>0x7ffac1010000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\System32\mscoree.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795778400005719</Timestamp>
<BaseAddress>0x7ffac1240000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll</Path>
<Version>4.7.2623.0 built by: NET471REL1LAST_C</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795778262571338</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795778267189195</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795778417041748</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795778400053783</Timestamp>
<BaseAddress>0x7ffac5b30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Assembly manager</Description>
</module>
<module>
<Timestamp>131795778259951873</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795778264680084</Timestamp>
<BaseAddress>0x7ffac7cc0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\msisip.dll</Path>
<Version>5.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSI Signature SIP Provider</Description>
</module>
<module>
<Timestamp>131795778265630538</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795778262583238</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795778323770185</Timestamp>
<BaseAddress>0x7ffac97f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\perfproc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов производительности системных процессов Windows</Description>
</module>
<module>
<Timestamp>131795778272914974</Timestamp>
<BaseAddress>0x7ffaca210000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\RstrtMgr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер перезапуска</Description>
</module>
<module>
<Timestamp>131795778281798291</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778259533909</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795778265279256</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795778264074461</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795778264625720</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795778265470245</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795778262605488</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795778261744074</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795778264613136</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795778264639501</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795778273070150</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795778272956330</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795778261891434</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795778259633594</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778260278752</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778260602827</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795778260604728</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778264076719</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795778259576609</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778259578595</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778259572597</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778264077537</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778260603797</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778260601744</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795778259515815</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778264075791</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778272946115</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778260600162</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795778260598868</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795778272945223</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778262622754</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795778259577351</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778265716961</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795778259571021</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778260302861</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778259514798</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778276914178</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795778259573318</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778259571855</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778259575900</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778259912248</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778259914551</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795778259575080</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795778259913185</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778253564149</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>132</ProcessIndex>
<ProcessId>5748</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795778806993759</CreateTime>
<FinishTime>131795783985261040</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k wsappx</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795778807042136</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795778809771371</Timestamp>
<BaseAddress>0x7ffaafc30000</BaseAddress>
<Size>2297856</Size>
<Path>C:\Windows\System32\AppXDeploymentServer.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера развертывания AppX</Description>
</module>
<module>
<Timestamp>131795778810217417</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795778809793544</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fltLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795778809909001</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795778810725123</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795778810201985</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795778809816672</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795778809822524</Timestamp>
<BaseAddress>0x7ffacb720000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\mintdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795778809799027</Timestamp>
<BaseAddress>0x7ffacb820000</BaseAddress>
<Size>712704</Size>
<Path>C:\Windows\System32\tdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795778810317823</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795778809809854</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795778810208064</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795778809594468</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795778809776574</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795778809778372</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795778809607454</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778809572087</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778809580973</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795778809605642</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795778810318817</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795778809772360</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795778809561432</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778809777533</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795778809774521</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795778809773756</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795778809570735</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795778809595255</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795778810493271</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795778809560537</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795778809606459</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795778809600563</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795778809580022</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795778809775513</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795778809569904</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795778807042435</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>136</ProcessIndex>
<ProcessId>9796</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795780239620520</CreateTime>
<FinishTime>131795782184799043</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchProtocolHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchProtocolHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchProtocolHost.exe&quot; Global\UsGthrFltPipeMssGthrPipe287_ Global\UsGthrCtrlFltPipeMssGthrPipe287 1 -2147483646 &quot;Software\Microsoft\Windows Search&quot; &quot;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)&quot; &quot;C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc&quot; &quot;DownLevelDaemon&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Protocol Host</Description>
<modulelist>
<module>
<Timestamp>131795780239737964</Timestamp>
<BaseAddress>0x7ff71ad80000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\SearchProtocolHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Protocol Host</Description>
</module>
<module>
<Timestamp>131795780369815326</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\System32\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795780418459536</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795780240300022</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\System32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795780243315314</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795780243903335</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795780441683903</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\linkinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795780243600064</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795780427898780</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780243436640</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795780430442742</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795780410780027</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795780241991790</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795780410796187</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780431995807</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780410763398</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780417487601</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780413476937</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780242057291</Timestamp>
<BaseAddress>0x7ffac7cd0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\mssph.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик протоколов поиска Microsoft</Description>
</module>
<module>
<Timestamp>131795780240397027</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795780412021532</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795780242909541</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780369785371</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795780242712385</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795780242660417</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\authz.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795782184673221</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795780243425796</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780412832818</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780240244868</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780240240128</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780240251850</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780240242580</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780240232121</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780240234675</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780240244079</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780240238319</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780240239247</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780240221401</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780240231486</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780243144631</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780243143464</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780240230763</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780240233764</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780240229489</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780240634076</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780240220498</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780240241837</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780240368757</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780240243394</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780240233035</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780240236451</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780241097467</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780240240989</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780240237313</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780239738429</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>137</ProcessIndex>
<ProcessId>12508</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795780241037362</CreateTime>
<FinishTime>131795782185153365</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchFilterHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchFilterHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchFilterHost.exe&quot; 0 708 712 720 8192 716 </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Filter Host</Description>
<modulelist>
<module>
<Timestamp>131795780241063145</Timestamp>
<BaseAddress>0x7ff68a750000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\SearchFilterHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Filter Host</Description>
</module>
<module>
<Timestamp>131795780247134349</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\System32\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795780241521132</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\System32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795780248688938</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795780241889503</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795780248698505</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780248678892</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780336696287</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780248844250</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795780369734185</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780248709490</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795780245297442</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795780248857657</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780241586648</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780248634862</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780248647646</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780241557344</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780241423082</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780241426099</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780241555681</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780241892382</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780248633959</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780241412105</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780241422398</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780248632826</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780248631779</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780241421633</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780241424805</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780241420314</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780241785125</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780241411149</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780241556540</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780241553299</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780241554210</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780241423999</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780241427039</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780248630299</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780248623921</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780241505282</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780241063419</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>138</ProcessIndex>
<ProcessId>12816</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780328696510</CreateTime>
<FinishTime>131795781526202116</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>backgroundTaskHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\backgroundTaskHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\backgroundTaskHost.exe&quot; -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Background Task Host</Description>
<modulelist>
<module>
<Timestamp>131795780329749381</Timestamp>
<BaseAddress>0x7ff6c9470000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\backgroundTaskHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Task Host</Description>
</module>
<module>
<Timestamp>131795780412645902</Timestamp>
<BaseAddress>0x7ffab52c0000</BaseAddress>
<Size>2445312</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780458670386</Timestamp>
<BaseAddress>0x7ffab5db0000</BaseAddress>
<Size>9781248</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780430264262</Timestamp>
<BaseAddress>0x7ffab9d50000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780415005192</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795780669717689</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795780455059889</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795780464027032</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795780460179577</Timestamp>
<BaseAddress>0x7ffabe770000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780426479724</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795780434238517</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795780444160476</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795780435161488</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795780414048080</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795780336747714</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795780431439143</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795780415109582</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795780447463685</Timestamp>
<BaseAddress>0x7ffac37b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795780458880946</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795780431346631</Timestamp>
<BaseAddress>0x7ffac3bf0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionMgr.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana Action Manager</Description>
</module>
<module>
<Timestamp>131795780454034058</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780439433205</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795780439202248</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795780453275113</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795780414060032</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795780412035947</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795780417041804</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795780335537874</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795780440780442</Timestamp>
<BaseAddress>0x7ffac6bb0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\Windows.Cortana.PAL.Desktop.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.PAL.Desktop</Description>
</module>
<module>
<Timestamp>131795780334206479</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795780412505075</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795780431250324</Timestamp>
<BaseAddress>0x7ffac7c50000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\BingConfigurationClient.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bing Configuration Client DLL</Description>
</module>
<module>
<Timestamp>131795780734626399</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795780460761885</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795780330302623</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795780735708696</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795780456573704</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780353237616</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795780329775228</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795780354090093</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780414037017</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795780329952250</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795780416468722</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795780458075843</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795780416610948</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780417362058</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780416587207</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780416598309</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780329987780</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780329937663</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780440064693</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780334214070</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780416574039</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780332551041</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780329815850</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780329817545</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780332549409</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780330307702</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780440061460</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780329756590</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780416541236</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780415545554</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780415544634</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780329816609</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780329812830</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780329755673</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780332550210</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780416575003</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780332564758</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780332548246</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780329814985</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780414009539</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780461878432</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780440069381</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780329975442</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780329749700</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>143</ProcessIndex>
<ProcessId>10640</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780604526348</CreateTime>
<FinishTime>131795781058423316</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>backgroundTaskHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\backgroundTaskHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\backgroundTaskHost.exe&quot; -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Background Task Host</Description>
<modulelist>
<module>
<Timestamp>131795780604942096</Timestamp>
<BaseAddress>0x7ff6c9470000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\backgroundTaskHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Task Host</Description>
</module>
<module>
<Timestamp>131795780982599698</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2936832</Size>
<Path>C:\Windows\System32\CertEnroll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент регистрации служб сертификатов Active Directory Microsoft®</Description>
</module>
<module>
<Timestamp>131795780624085064</Timestamp>
<BaseAddress>0x7ffaad5b0000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentDeliveryManager.Background.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780633868268</Timestamp>
<BaseAddress>0x7ffaadf00000</BaseAddress>
<Size>2260992</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentManagementSDK.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780984186979</Timestamp>
<BaseAddress>0x7ffab1dc0000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\certca.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ЦС служб сертификации Microsoft® Active Directory</Description>
</module>
<module>
<Timestamp>131795780989018507</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795780638521291</Timestamp>
<BaseAddress>0x7ffab8f60000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\CryptoWinRT.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto WinRT Library</Description>
</module>
<module>
<Timestamp>131795780656495804</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795780968504887</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795780965909656</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795780850515848</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795780881658829</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795780632764734</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795780627995893</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795780626074133</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795780637000038</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795780979874979</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795780639367373</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795780949324967</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780638058893</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795780979208878</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795780624149045</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795780641809268</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795780979197823</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780606360545</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795780918011378</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795780971614143</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780631634537</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780624161030</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795780642339398</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795780642310850</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795780631607870</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795780972492970</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795780622245977</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795780965988464</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795780966015364</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795780606285280</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795780983258989</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\dsparse.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795780605748575</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795780624526113</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795780622740074</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795780624112925</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\slc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795780626644547</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795780975579967</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795780968868492</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795780626601326</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795780605036791</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795780630151168</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795780634233098</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780621646470</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795780621784723</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780624171938</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795780605004500</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795780624123309</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795780967018140</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795780644959783</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795780966160644</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795780977616543</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795780979753360</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795780979288601</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795780966000176</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780971557025</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795780967499686</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795780968849434</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795780979741934</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780640855968</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780639253750</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780639155938</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780624100929</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780605016566</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780604988979</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780634211474</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780606271616</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780882167263</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780605130292</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780604960936</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780604962598</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780605128610</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780979290330</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795780605041481</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780634210377</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780604949997</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780882158799</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780624152029</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780624151198</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780604961659</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780968869207</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795780604958974</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780604949078</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780985065294</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\Wldap32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795780605129419</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780965914856</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780605144205</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780605127632</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780604960157</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780624086344</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780634212438</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780605005539</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780604942528</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>144</ProcessIndex>
<ProcessId>12892</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780695167004</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Wireshark.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\Wireshark.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\Wireshark.exe&quot; </CommandLine>
<CompanyName>The Wireshark developer community, http://www.wireshark.org/</CompanyName>
<Version>2.6.2</Version>
<Description>Wireshark</Description>
<modulelist>
<module>
<Timestamp>131795780706141890</Timestamp>
<BaseAddress>0xbd0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\libwinpthread-1.dll</Path>
<Version>1, 0, 0, 0</Version>
<Company>MingW-W64 Project. All rights reserved.</Company>
<Description>POSIX WinThreads for Windows</Description>
</module>
<module>
<Timestamp>131795780721765742</Timestamp>
<BaseAddress>0xbf0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\k5sprt64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>Kerberos v5 support - internal support code for MIT Kerberos v5 /GSS distribution</Description>
</module>
<module>
<Timestamp>131795780722106261</Timestamp>
<BaseAddress>0xc00000</BaseAddress>
<Size>45056</Size>
<Path>C:\Program Files\Wireshark\comerr64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>COM_ERR - Common Error Handler for MIT Kerberos v5 / GSS distribution</Description>
</module>
<module>
<Timestamp>131795780719731475</Timestamp>
<BaseAddress>0x1c000000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\krb5_64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>Kerberos v5 - MIT GSS / Kerberos v5 distribution</Description>
</module>
<module>
<Timestamp>131795780773060331</Timestamp>
<BaseAddress>0x5af30000</BaseAddress>
<Size>348160</Size>
<Path>C:\Program Files\Wireshark\Qt5Svg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780721210805</Timestamp>
<BaseAddress>0x5af90000</BaseAddress>
<Size>1286144</Size>
<Path>C:\Program Files\Wireshark\libxml2-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780696840198</Timestamp>
<BaseAddress>0x5b0d0000</BaseAddress>
<Size>5865472</Size>
<Path>C:\Program Files\Wireshark\Qt5Core.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780696801039</Timestamp>
<BaseAddress>0x5b670000</BaseAddress>
<Size>5619712</Size>
<Path>C:\Program Files\Wireshark\Qt5Widgets.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780721068755</Timestamp>
<BaseAddress>0x5bcf0000</BaseAddress>
<Size>733184</Size>
<Path>C:\Program Files\Wireshark\libsmi-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720701584</Timestamp>
<BaseAddress>0x5bdb0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Program Files\Wireshark\liblz4.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720048995</Timestamp>
<BaseAddress>0x5bdf0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Program Files\Wireshark\libcares-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780701085625</Timestamp>
<BaseAddress>0x5be10000</BaseAddress>
<Size>122880</Size>
<Path>C:\Program Files\Wireshark\libbcg729.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700086118</Timestamp>
<BaseAddress>0x5be30000</BaseAddress>
<Size>1261568</Size>
<Path>C:\Program Files\Wireshark\Qt5Network.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780701499544</Timestamp>
<BaseAddress>0x61cc0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Wireshark\libintl-8.dll</Path>
<Version>0.18.1</Version>
<Company>Free Software Foundation</Company>
<Description>LGPLed libintl for Windows NT/2000/XP/Vista/7 and Windows 95/98/ME</Description>
</module>
<module>
<Timestamp>131795780704834900</Timestamp>
<BaseAddress>0x646c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libgpg-error6-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780703191110</Timestamp>
<BaseAddress>0x64840000</BaseAddress>
<Size>1220608</Size>
<Path>C:\Program Files\Wireshark\libgnutls-30.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720700188</Timestamp>
<BaseAddress>0x64a00000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\lua52.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780702785552</Timestamp>
<BaseAddress>0x653c0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\libgcrypt-20.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780706408972</Timestamp>
<BaseAddress>0x65f00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Program Files\Wireshark\libtasn1-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705520711</Timestamp>
<BaseAddress>0x66f00000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Wireshark\libhogweed-4-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780696518462</Timestamp>
<BaseAddress>0x685c0000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Program Files\Wireshark\libglib-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GLib</Description>
</module>
<module>
<Timestamp>131795780706610973</Timestamp>
<BaseAddress>0x68ec0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\Wireshark\libp11-kit-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720967901</Timestamp>
<BaseAddress>0x69340000</BaseAddress>
<Size>815104</Size>
<Path>C:\Program Files\Wireshark\libsnappy-1.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705423287</Timestamp>
<BaseAddress>0x69c80000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\libnettle-6-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700701891</Timestamp>
<BaseAddress>0x6a680000</BaseAddress>
<Size>122880</Size>
<Path>C:\Program Files\Wireshark\libsbc-1.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705248323</Timestamp>
<BaseAddress>0x6acc0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files\Wireshark\libgmp-10.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780707311684</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\libffi-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700957949</Timestamp>
<BaseAddress>0x6d7c0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files\Wireshark\libspandsp-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720746780</Timestamp>
<BaseAddress>0x6dc80000</BaseAddress>
<Size>167936</Size>
<Path>C:\Program Files\Wireshark\libnghttp2-14.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780698864675</Timestamp>
<BaseAddress>0x6dd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\Wireshark\libgmodule-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GModule</Description>
</module>
<module>
<Timestamp>131795780759720376</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\wpcap.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008)</Description>
</module>
<module>
<Timestamp>131795780760417804</Timestamp>
<BaseAddress>0x190ac770000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795780695991379</Timestamp>
<BaseAddress>0x7ff7f1130000</BaseAddress>
<Size>8298496</Size>
<Path>C:\Program Files\Wireshark\Wireshark.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark</Description>
</module>
<module>
<Timestamp>131795780718751145</Timestamp>
<BaseAddress>0x7ffaa6f50000</BaseAddress>
<Size>64282624</Size>
<Path>C:\Program Files\Wireshark\libwireshark.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark dissector library</Description>
</module>
<module>
<Timestamp>131795780697272337</Timestamp>
<BaseAddress>0x7ffaaaca0000</BaseAddress>
<Size>6094848</Size>
<Path>C:\Program Files\Wireshark\Qt5Gui.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896758694</Timestamp>
<BaseAddress>0x7ffab1e90000</BaseAddress>
<Size>593920</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimax.dll</Path>
<Version>1.2.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimax dissector</Description>
</module>
<module>
<Timestamp>131795780766458881</Timestamp>
<BaseAddress>0x7ffab1f30000</BaseAddress>
<Size>614400</Size>
<Path>C:\Windows\System32\riched20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795780699399720</Timestamp>
<BaseAddress>0x7ffab2280000</BaseAddress>
<Size>1916928</Size>
<Path>C:\Program Files\Wireshark\WinSparkle.dll</Path>
<Version>0.5.7</Version>
<Company>winsparkle.org</Company>
<Description>WinSparkle updater</Description>
</module>
<module>
<Timestamp>131795780771263589</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795780765326722</Timestamp>
<BaseAddress>0x7ffab9010000</BaseAddress>
<Size>1388544</Size>
<Path>C:\Program Files\Wireshark\platforms\qwindows.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896746168</Timestamp>
<BaseAddress>0x7ffab9b10000</BaseAddress>
<Size>135168</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\unistim.dll</Path>
<Version>0.0.2.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>unistim dissector</Description>
</module>
<module>
<Timestamp>131795780896708383</Timestamp>
<BaseAddress>0x7ffabaef0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\profinet.dll</Path>
<Version>0.2.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>profinet dissector</Description>
</module>
<module>
<Timestamp>131795780773615377</Timestamp>
<BaseAddress>0x7ffabb070000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files\Wireshark\imageformats\qwebp.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780702318544</Timestamp>
<BaseAddress>0x7ffabb0f0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780773096445</Timestamp>
<BaseAddress>0x7ffabb250000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files\Wireshark\imageformats\qtiff.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896696149</Timestamp>
<BaseAddress>0x7ffabc110000</BaseAddress>
<Size>237568</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\opcua.dll</Path>
<Version>1.0.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>opcua dissector</Description>
</module>
<module>
<Timestamp>131795780696290907</Timestamp>
<BaseAddress>0x7ffabc150000</BaseAddress>
<Size>729088</Size>
<Path>C:\Program Files\Wireshark\Qt5Multimedia.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780699299849</Timestamp>
<BaseAddress>0x7ffabcbb0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Program Files\Wireshark\libwiretap.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark capture file library</Description>
</module>
<module>
<Timestamp>131795780702235327</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795780699512168</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795780773039075</Timestamp>
<BaseAddress>0x7ffabe940000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\imageformats\qjpeg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896684027</Timestamp>
<BaseAddress>0x7ffabeb80000</BaseAddress>
<Size>163840</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\mate.dll</Path>
<Version>1.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>mate dissector</Description>
</module>
<module>
<Timestamp>131795780767100288</Timestamp>
<BaseAddress>0x7ffabebb0000</BaseAddress>
<Size>233472</Size>
<Path>C:\Windows\System32\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795780967804060</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795780703722010</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780896660120</Timestamp>
<BaseAddress>0x7ffabf990000</BaseAddress>
<Size>135168</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\gryphon.dll</Path>
<Version>0.0.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>gryphon dissector</Description>
</module>
<module>
<Timestamp>131795781117544658</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\NapiNSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795781117680972</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795780896781202</Timestamp>
<BaseAddress>0x7ffabff40000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimaxmacphy.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimaxmacphy dissector</Description>
</module>
<module>
<Timestamp>131795780975772674</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795781117813782</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795780967709675</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780896602379</Timestamp>
<BaseAddress>0x7ffac0b10000</BaseAddress>
<Size>180224</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\ethercat.dll</Path>
<Version>0.1.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>ethercat dissector</Description>
</module>
<module>
<Timestamp>131795780696305369</Timestamp>
<BaseAddress>0x7ffac12f0000</BaseAddress>
<Size>585728</Size>
<Path>C:\Program Files\Wireshark\Qt5WinExtras.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780696268510</Timestamp>
<BaseAddress>0x7ffac1380000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files\Wireshark\Qt5PrintSupport.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896769846</Timestamp>
<BaseAddress>0x7ffac1640000</BaseAddress>
<Size>81920</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimaxasncp.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimaxasncp dissector</Description>
</module>
<module>
<Timestamp>131795780703633136</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\zlib1.dll</Path>
<Version>1.2.11</Version>
<Company></Company>
<Description>zlib data compression library</Description>
</module>
<module>
<Timestamp>131795780968289847</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795780896672499</Timestamp>
<BaseAddress>0x7ffac21f0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\irda.dll</Path>
<Version>0.0.6.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>irda dissector</Description>
</module>
<module>
<Timestamp>131795780943468609</Timestamp>
<BaseAddress>0x7ffac2950000</BaseAddress>
<Size>32768</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\codecs\l16mono.dll</Path>
<Version>0.1.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>l16mono dissector</Description>
</module>
<module>
<Timestamp>131795780696778265</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780698025500</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libwsutil.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark utility library</Description>
</module>
<module>
<Timestamp>131795780964290332</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780896734845</Timestamp>
<BaseAddress>0x7ffac3730000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\transum.dll</Path>
<Version>2.0.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>transum dissector</Description>
</module>
<module>
<Timestamp>131795780962958391</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780891504201</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795780896719593</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\stats_tree.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>stats_tree dissector</Description>
</module>
<module>
<Timestamp>131795780893701095</Timestamp>
<BaseAddress>0x7ffac4c50000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\wiretap\usbdump.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>usbdump dissector</Description>
</module>
<module>
<Timestamp>131795780891269455</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795780965552062</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795780963571749</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795780963646684</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795780773109195</Timestamp>
<BaseAddress>0x7ffac6aa0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qwbmp.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773083338</Timestamp>
<BaseAddress>0x7ffac6ab0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qtga.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780700311672</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780700270884</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780773051219</Timestamp>
<BaseAddress>0x7ffac7710000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qsvg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773027062</Timestamp>
<BaseAddress>0x7ffac7c70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\imageformats\qico.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773014999</Timestamp>
<BaseAddress>0x7ffac7cc0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files\Wireshark\imageformats\qicns.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773002354</Timestamp>
<BaseAddress>0x7ffac7e80000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\imageformats\qgif.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780968266724</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795780968255503</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795780966275544</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795780892525330</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795780963686201</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795780892534590</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795781117718740</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795780698877286</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wsock32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795780891204535</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795780696645603</Timestamp>
<BaseAddress>0x7ffaca540000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\libwscodecs.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark codecs library</Description>
</module>
<module>
<Timestamp>131795780700298298</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780892543743</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795780766486586</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795780704258643</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795780702045466</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795780946467813</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795780696789076</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780891516231</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795780892568770</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795780892552823</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795780966945740</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795780735395573</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795780967734879</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795780699490686</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780703368899</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795780963669913</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795780735383654</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780725077080</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780735352973</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780735341669</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780963187802</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780703358385</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780696324267</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780696320774</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780696326027</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780700094061</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780696281753</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780696314418</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780696011047</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780967736295</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795780696325096</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780696319762</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780696000095</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780700093105</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780700405929</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780696318427</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780719380090</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795780696316518</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780700405056</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780696313332</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780703813608</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795780696317482</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780891250440</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780695999112</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780892432004</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795780696011842</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780696829366</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780722304611</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780696010125</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780696013618</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795780696312465</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780696321680</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780696311589</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780696323259</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780696315318</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780695991736</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>145</ProcessIndex>
<ProcessId>6448</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795780773898509</CreateTime>
<FinishTime>131795782061618939</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k WerSvcGroup</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795780773932265</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795780777692104</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795780777685690</Timestamp>
<BaseAddress>0x7ffabdfa0000</BaseAddress>
<Size>393216</Size>
<Path>C:\Windows\System32\Faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795780777697839</Timestamp>
<BaseAddress>0x7ffabe110000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\weretw.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>WERETW.DLL</Description>
</module>
<module>
<Timestamp>131795780777657500</Timestamp>
<BaseAddress>0x7ffac1940000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\wersvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба регистрации ошибок Windows</Description>
</module>
<module>
<Timestamp>131795780777719777</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.dll</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795780777705622</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\System32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795780777679409</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795780778138106</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795780781946447</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795780777672965</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780781977480</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780777713476</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780777659234</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780778139963</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780777601321</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780777665390</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780778140821</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795780777686685</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780777591206</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780778139073</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780777699394</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780777698612</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780777599983</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780777658345</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780777590325</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780777664133</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780777666249</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780777599157</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780773932520</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>152</ProcessIndex>
<ProcessId>2432</ProcessId>
<ParentProcessId>12892</ParentProcessId>
<ParentProcessIndex>144</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780956883979</CreateTime>
<FinishTime>131795781110076440</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>dumpcap.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\dumpcap.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\dumpcap.exe&quot; -S -Z 12892.dummy</CommandLine>
<CompanyName>The Wireshark developer community</CompanyName>
<Version>2.6.2</Version>
<Description>Dumpcap</Description>
<modulelist>
<module>
<Timestamp>131795780958439058</Timestamp>
<BaseAddress>0xa80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\libwinpthread-1.dll</Path>
<Version>1, 0, 0, 0</Version>
<Company>MingW-W64 Project. All rights reserved.</Company>
<Description>POSIX WinThreads for Windows</Description>
</module>
<module>
<Timestamp>131795780958377059</Timestamp>
<BaseAddress>0x61cc0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Wireshark\libintl-8.dll</Path>
<Version>0.18.1</Version>
<Company>Free Software Foundation</Company>
<Description>LGPLed libintl for Windows NT/2000/XP/Vista/7 and Windows 95/98/ME</Description>
</module>
<module>
<Timestamp>131795780958399096</Timestamp>
<BaseAddress>0x646c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libgpg-error6-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958347475</Timestamp>
<BaseAddress>0x64840000</BaseAddress>
<Size>1220608</Size>
<Path>C:\Program Files\Wireshark\libgnutls-30.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958339828</Timestamp>
<BaseAddress>0x653c0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\libgcrypt-20.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958446503</Timestamp>
<BaseAddress>0x65f00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Program Files\Wireshark\libtasn1-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958414603</Timestamp>
<BaseAddress>0x66f00000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Wireshark\libhogweed-4-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958277889</Timestamp>
<BaseAddress>0x685c0000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Program Files\Wireshark\libglib-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GLib</Description>
</module>
<module>
<Timestamp>131795780958431545</Timestamp>
<BaseAddress>0x68ec0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\Wireshark\libp11-kit-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958424372</Timestamp>
<BaseAddress>0x69c80000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\libnettle-6-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958407305</Timestamp>
<BaseAddress>0x6acc0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files\Wireshark\libgmp-10.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958485579</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\libffi-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780958289420</Timestamp>
<BaseAddress>0x6dd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\Wireshark\libgmodule-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GModule</Description>
</module>
<module>
<Timestamp>131795780958713554</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\wpcap.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008)</Description>
</module>
<module>
<Timestamp>131795780958729518</Timestamp>
<BaseAddress>0x2a56ecc0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795780956897031</Timestamp>
<BaseAddress>0x7ff79b530000</BaseAddress>
<Size>438272</Size>
<Path>C:\Program Files\Wireshark\dumpcap.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community</Company>
<Description>Dumpcap</Description>
</module>
<module>
<Timestamp>131795780958453942</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\zlib1.dll</Path>
<Version>1.2.11</Version>
<Company></Company>
<Description>zlib data compression library</Description>
</module>
<module>
<Timestamp>131795780958743457</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780958247042</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libwsutil.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark utility library</Description>
</module>
<module>
<Timestamp>131795780958327006</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780959264331</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795780958822800</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795780958303451</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wsock32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795780958474513</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795780958389609</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795780958646709</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795780958314117</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780958635383</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780958674359</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780958618023</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780958596049</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780958607187</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780958263131</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780958255689</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780958265389</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780958349084</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780958259529</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780958230643</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780958254658</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780958262008</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780958264244</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780958252245</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780956903750</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780958348162</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780958250835</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780958249546</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780958228230</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780958812040</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795780958226523</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780956902794</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780958258379</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780958248189</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780958549690</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780958260931</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780958253539</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780958224678</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780958278826</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780958257207</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780958227462</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780956897313</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>153</ProcessIndex>
<ProcessId>4460</ProcessId>
<ParentProcessId>2432</ParentProcessId>
<ParentProcessIndex>152</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780957221117</CreateTime>
<FinishTime>131795781110129729</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Conhost.exe</ProcessName>
<ImagePath>C:\Windows\System32\Conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795780957224666</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795780957254960</Timestamp>
<BaseAddress>0x7ffabe520000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795780958156057</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780957284286</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780958109132</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780957764987</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780957662947</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780957660016</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780957663767</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780957266937</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780957263269</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780957264898</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780957268718</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780957285965</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780957659076</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780957231155</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780957270871</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780957656755</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780957655580</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780957270220</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780957263997</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780957239575</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780957230291</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780958089236</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795780957265615</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780957269477</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780957268031</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780957262479</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780957660847</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780957661778</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780957285128</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780957224946</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>154</ProcessIndex>
<ProcessId>10368</ProcessId>
<ParentProcessId>12892</ParentProcessId>
<ParentProcessIndex>144</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795781110701520</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>dumpcap.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\dumpcap.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\dumpcap.exe&quot; -n -i \Device\NPF_{8742EB38-E176-4D94-AB83-DB4440CD90E6} -y EN10MB -Z 12892</CommandLine>
<CompanyName>The Wireshark developer community</CompanyName>
<Version>2.6.2</Version>
<Description>Dumpcap</Description>
<modulelist>
<module>
<Timestamp>131795781112729961</Timestamp>
<BaseAddress>0xe30000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\libwinpthread-1.dll</Path>
<Version>1, 0, 0, 0</Version>
<Company>MingW-W64 Project. All rights reserved.</Company>
<Description>POSIX WinThreads for Windows</Description>
</module>
<module>
<Timestamp>131795781112668516</Timestamp>
<BaseAddress>0x61cc0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Wireshark\libintl-8.dll</Path>
<Version>0.18.1</Version>
<Company>Free Software Foundation</Company>
<Description>LGPLed libintl for Windows NT/2000/XP/Vista/7 and Windows 95/98/ME</Description>
</module>
<module>
<Timestamp>131795781112689838</Timestamp>
<BaseAddress>0x646c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libgpg-error6-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112636826</Timestamp>
<BaseAddress>0x64840000</BaseAddress>
<Size>1220608</Size>
<Path>C:\Program Files\Wireshark\libgnutls-30.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112629190</Timestamp>
<BaseAddress>0x653c0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\libgcrypt-20.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112737406</Timestamp>
<BaseAddress>0x65f00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Program Files\Wireshark\libtasn1-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112705672</Timestamp>
<BaseAddress>0x66f00000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Wireshark\libhogweed-4-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112573973</Timestamp>
<BaseAddress>0x685c0000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Program Files\Wireshark\libglib-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GLib</Description>
</module>
<module>
<Timestamp>131795781112722622</Timestamp>
<BaseAddress>0x68ec0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\Wireshark\libp11-kit-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112715396</Timestamp>
<BaseAddress>0x69c80000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\libnettle-6-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112698255</Timestamp>
<BaseAddress>0x6acc0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files\Wireshark\libgmp-10.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112775160</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\libffi-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112582576</Timestamp>
<BaseAddress>0x6dd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\Wireshark\libgmodule-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GModule</Description>
</module>
<module>
<Timestamp>131795781112962306</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\wpcap.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008)</Description>
</module>
<module>
<Timestamp>131795781112975613</Timestamp>
<BaseAddress>0x2203d070000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795781110777700</Timestamp>
<BaseAddress>0x7ff79b530000</BaseAddress>
<Size>438272</Size>
<Path>C:\Program Files\Wireshark\dumpcap.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community</Company>
<Description>Dumpcap</Description>
</module>
<module>
<Timestamp>131795781112745027</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\zlib1.dll</Path>
<Version>1.2.11</Version>
<Company></Company>
<Description>zlib data compression library</Description>
</module>
<module>
<Timestamp>131795781112991873</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795781112551689</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libwsutil.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark utility library</Description>
</module>
<module>
<Timestamp>131795781112616429</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781113081556</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795781113068402</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795781112593287</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wsock32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795781112764136</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795781112680590</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795781112901553</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795781112603842</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795781112889933</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795781112922216</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795781112873689</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795781112851456</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795781112862535</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795781112564185</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795781112558680</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795781112565891</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795781112638400</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795781112561378</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781112543433</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781112557787</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795781112563121</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795781112564994</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795781112555945</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795781111306780</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781112637496</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795781112554892</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795781112553795</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795781112541505</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795781113056743</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795781112539956</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795781111305815</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781112560555</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781112552568</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795781112797169</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795781112562317</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795781112556862</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795781112538759</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795781112574716</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795781112559630</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795781112540782</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795781110778043</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>155</ProcessIndex>
<ProcessId>10656</ProcessId>
<ParentProcessId>10368</ParentProcessId>
<ParentProcessIndex>154</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795781111864203</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Conhost.exe</ProcessName>
<ImagePath>C:\Windows\System32\Conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795781111913743</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795781111943590</Timestamp>
<BaseAddress>0x7ffac16b0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795781112487631</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795781111973094</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795781112447250</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795781112288506</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795781112268292</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795781112265698</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795781112269042</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795781111955891</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781111952093</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781111953761</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795781111957462</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795781111974737</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795781112264787</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795781111919763</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781111959779</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781112263740</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795781112262565</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795781111959111</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795781111952833</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795781111927637</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795781111918688</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781112429009</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795781111954501</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781111958338</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795781111956778</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795781111951234</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795781112266518</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795781112267424</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795781111973936</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795781111913976</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>156</ProcessIndex>
<ProcessId>6544</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795781375514663</CreateTime>
<FinishTime>131795781448145922</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>backgroundTaskHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\backgroundTaskHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\backgroundTaskHost.exe&quot; -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Background Task Host</Description>
<modulelist>
<module>
<Timestamp>131795781375956049</Timestamp>
<BaseAddress>0x7ff6c9470000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\backgroundTaskHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Task Host</Description>
</module>
<module>
<Timestamp>131795781420231974</Timestamp>
<BaseAddress>0x7ffaade60000</BaseAddress>
<Size>2936832</Size>
<Path>C:\Windows\System32\CertEnroll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент регистрации служб сертификатов Active Directory Microsoft®</Description>
</module>
<module>
<Timestamp>131795781391802474</Timestamp>
<BaseAddress>0x7ffaafa00000</BaseAddress>
<Size>2260992</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentManagementSDK.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781378586098</Timestamp>
<BaseAddress>0x7ffab0280000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentDeliveryManager.Background.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781424848611</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795781409116652</Timestamp>
<BaseAddress>0x7ffab8f60000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\CryptoWinRT.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto WinRT Library</Description>
</module>
<module>
<Timestamp>131795781404777029</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795781414822130</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795781421244159</Timestamp>
<BaseAddress>0x7ffababf0000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\certca.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ЦС служб сертификации Microsoft® Active Directory</Description>
</module>
<module>
<Timestamp>131795781413672423</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795781408056391</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795781411322544</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795781391285668</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795781380106961</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795781379627609</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795781404355812</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795781419249846</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795781409496119</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795781413547947</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795781402547126</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795781418873067</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795781378876674</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795781407871528</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795781418862170</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795781376949774</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795781412867320</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795781415411030</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795781389967180</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795781379015368</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795781389477287</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795781415721817</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795781377895075</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795781414207784</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795781414325447</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795781376698975</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795781421254868</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\dsparse.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795781376636667</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795781379055882</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795781378177060</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795781378820936</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\slc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795781379867493</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795781415710619</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795781415160649</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795781379785667</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795781376161721</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795781381497463</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795781400360112</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795781377417467</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795781377574222</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795781379044936</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795781376090036</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795781378865985</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795781414518147</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795781414918402</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795781414341341</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795781417360246</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795781418995689</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795781418966047</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795781414219564</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795781415370787</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795781414781184</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795781415128865</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795781418985585</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795781410039902</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795781409485316</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795781409428276</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795781378809349</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795781376142422</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795781376066481</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795781400337277</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795781376677325</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795781411377418</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795781376323409</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781375973357</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781375975249</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795781376321707</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795781418968465</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795781376165705</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795781400336014</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795781375963238</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781411376468</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795781379140199</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781379139376</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795781375974304</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795781415167464</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795781375971439</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795781375962346</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781421399809</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\Wldap32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795781376322544</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781414140404</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795781376336876</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795781376320735</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795781375972581</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795781378796627</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795781400338549</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795781376091355</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795781375956384</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>157</ProcessIndex>
<ProcessId>9472</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795783695799872</CreateTime>
<FinishTime>131795783788685275</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>UpdateAssistant.exe</ProcessName>
<ImagePath>C:\Windows\UpdateAssistant\UpdateAssistant.exe</ImagePath>
<CommandLine>C:\Windows\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:NHV18:{}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.10057 (rs1_release_d_bugfix(cxesa).180619-1208)</Version>
<Description>UpdateAssistant</Description>
<modulelist>
<module>
<Timestamp>131795783701823215</Timestamp>
<BaseAddress>0x7ff744b10000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\UpdateAssistant\UpdateAssistant.exe</Path>
<Version>10.0.14393.10057 (rs1_release_d_bugfix(cxesa).180619-1208)</Version>
<Company>Microsoft Corporation</Company>
<Description>UpdateAssistant</Description>
</module>
<module>
<Timestamp>131795783720310913</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\atl.dll</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795783720359248</Timestamp>
<BaseAddress>0x7ffac1f10000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\dmcmnutils.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmcmnutils</Description>
</module>
<module>
<Timestamp>131795783760269052</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795783760342879</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795783760357383</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795783720338663</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795783761961676</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795783720030471</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795783761784250</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795783777273664</Timestamp>
<BaseAddress>0x7ffac7ce0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\usoapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Session Orchestrator API</Description>
</module>
<module>
<Timestamp>131795783761383926</Timestamp>
<BaseAddress>0x7ffac7d60000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\updatepolicy.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Policy Reader</Description>
</module>
<module>
<Timestamp>131795783763101028</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795783763248350</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795783761671518</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795783737786694</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795783766477330</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795783720042775</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795783761869001</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795783761841221</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795783760278190</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795783720349343</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795783720009570</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795783720008778</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795783720011055</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795783720003516</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795783719999191</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795783719994518</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795783719996692</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795783720000610</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795783720010268</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795783720007866</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795783712541416</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795783720002840</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795783720002028</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795783720006957</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795783720006098</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795783720001386</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795783719993581</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795783761869802</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795783719991841</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795783760254773</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795783712540499</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795783719998327</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795783720005143</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795783737806683</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795783719999962</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795783719995892</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795783719990891</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795783719995202</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795783720004300</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795783719992966</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795783701823597</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>158</ProcessIndex>
<ProcessId>4400</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795783695800058</CreateTime>
<FinishTime>131795783701748183</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>UpdateAssistant.exe</ProcessName>
<ImagePath>C:\Windows\UpdateAssistant\UpdateAssistant.exe</ImagePath>
<CommandLine>C:\Windows\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:NHV18:{} /AllUsersRun</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.10057 (rs1_release_d_bugfix(cxesa).180619-1208)</Version>
<Description>UpdateAssistant</Description>
<modulelist>
<module>
<Timestamp>131795783701546865</Timestamp>
<BaseAddress>0x7ff744b10000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\UpdateAssistant\UpdateAssistant.exe</Path>
<Version>10.0.14393.10057 (rs1_release_d_bugfix(cxesa).180619-1208)</Version>
<Company>Microsoft Corporation</Company>
<Description>UpdateAssistant</Description>
</module>
<module>
<Timestamp>131795783701547131</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>159</ProcessIndex>
<ProcessId>2452</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795783701691029</CreateTime>
<FinishTime>131795783717790135</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>XblGameSaveTask.exe</ProcessName>
<ImagePath>C:\Windows\System32\XblGameSaveTask.exe</ImagePath>
<CommandLine>C:\Windows\System32\XblGameSaveTask.exe standby</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>XblGameSave Standby Task</Description>
<modulelist>
<module>
<Timestamp>131795783701826465</Timestamp>
<BaseAddress>0x7ff6747e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\XblGameSaveTask.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>XblGameSave Standby Task</Description>
</module>
<module>
<Timestamp>131795783701832150</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795783717422437</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795783717421060</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795783701831338</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795783701826697</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>160</ProcessIndex>
<ProcessId>10668</ProcessId>
<ParentProcessId>2452</ParentProcessId>
<ParentProcessIndex>159</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795783705682467</CreateTime>
<FinishTime>131795783717901381</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>Conhost.exe</ProcessName>
<ImagePath>C:\Windows\System32\Conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795783706097259</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795783706222546</Timestamp>
<BaseAddress>0x7ffac16b0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795783706357733</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795783706615060</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795783706546680</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795783706615836</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795783706267565</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795783706263617</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795783706265432</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795783706269166</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795783706373982</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795783706545807</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795783706108909</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795783706271225</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795783706544765</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795783706543671</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795783706270591</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795783706264354</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795783706116930</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795783706108105</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795783706266792</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795783706269879</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795783706268466</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795783706262861</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795783706547450</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795783706548303</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795783706358550</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795783706097494</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>161</ProcessIndex>
<ProcessId>12760</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795784261891634</CreateTime>
<FinishTime>131795784271656909</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>sedlauncher.exe</ProcessName>
<ImagePath>C:\Program Files\rempl\sedlauncher.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\rempl\sedlauncher.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Description>sedlauncher</Description>
<modulelist>
<module>
<Timestamp>131795784261910410</Timestamp>
<BaseAddress>0x7ff783d60000</BaseAddress>
<Size>258048</Size>
<Path>C:\Program Files\rempl\sedlauncher.exe</Path>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>sedlauncher</Description>
</module>
<module>
<Timestamp>131795784266568695</Timestamp>
<BaseAddress>0x7ffababf0000</BaseAddress>
<Size>798720</Size>
<Path>C:\Program Files\rempl\sedplugins.dll</Path>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>sedplugins</Description>
</module>
<module>
<Timestamp>131795784263491741</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795784267124264</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\atl.dll</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795784266591025</Timestamp>
<BaseAddress>0x7ffac1f10000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\dmcmnutils.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmcmnutils</Description>
</module>
<module>
<Timestamp>131795784263208636</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795784271303424</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795784266880876</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795784267082706</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795784263187575</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795784271119858</Timestamp>
<BaseAddress>0x7ffac7d60000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\updatepolicy.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Policy Reader</Description>
</module>
<module>
<Timestamp>131795784266910659</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795784266580949</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\StorageUsage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795784267114052</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795784267210331</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795784266900084</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795784266394986</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795784265589698</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795784267071668</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795784266870398</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795784263198294</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795784265655565</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795784265600251</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795784263160864</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795784263156364</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795784263162254</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795784263158628</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795784263145141</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795784263148820</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795784263160132</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795784263162953</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795784263161512</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795784263155580</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795784262871886</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795784263151247</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795784266570310</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795784263154696</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795784263153793</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795784266569642</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795784263147124</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795784263150360</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795784262869977</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795784263163848</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795784263157946</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795784266571388</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795784263159487</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795784263148014</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795784265715387</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795784263149679</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795784263157165</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795784263146448</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795784261910701</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>1</ProcessIndex>
<ProcessId>11372</ProcessId>
<ParentProcessId>10560</ParentProcessId>
<ParentProcessIndex>2</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770632346846</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon64.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Temp\Procmon64.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Temp\Procmon64.exe&quot;  /originalpath &quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot;</CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>2</ProcessIndex>
<ProcessId>10560</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770594566098</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon.exe</ProcessName>
<ImagePath>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot; </CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x1000000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x62530000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\RICHED20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cd0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72520000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\Riched32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wrapper Dll for Richedit 1.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>3</ProcessIndex>
<ProcessId>4048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765778109600457</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchIndexer.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchIndexer.exe</ImagePath>
<CommandLine>C:\Windows\system32\SearchIndexer.exe /Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Индексатор службы Microsoft Windows Search</Description>
<modulelist>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ff63db40000</BaseAddress>
<Size>929792</Size>
<Path>C:\Windows\system32\SearchIndexer.exe</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индексатор службы Microsoft Windows Search</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\MSSRCH.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabd990000</BaseAddress>
<Size>720896</Size>
<Path>C:\Windows\system32\ElsLad.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ELS Language Detection</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\Msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>4</ProcessIndex>
<ProcessId>580</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776275984299</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>services.exe</ProcessName>
<ImagePath>C:\Windows\system32\services.exe</ImagePath>
<CommandLine>C:\Windows\system32\services.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Приложение служб и контроллеров</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>6</ProcessIndex>
<ProcessId>664</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776282506625</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k DcomLaunch</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc6a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\SebBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; SEB Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc7e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\SmartCardBackgroundPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartCardBackgroundPolicy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8c0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\CbtBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; CBT Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8d0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\ACPBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; ACP Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc900000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BackgroundMediaPolicy.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Background Media Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\RmClient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca740000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\DAB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL брокера активности компьютера</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacabd0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\OnDemandBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OnDemandBrokerClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacae70000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\systemeventsbrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер системных событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacafc0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy RM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb010000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SYSTEM32\psmserviceexthost.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager PSM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb390000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\psmsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process State Manager (PSM) Service</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb4f0000</BaseAddress>
<Size>794624</Size>
<Path>c:\windows\system32\bisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба инфраструктуры фоновых задач</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb720000</BaseAddress>
<Size>344064</Size>
<Path>c:\windows\system32\mintdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>c:\windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb820000</BaseAddress>
<Size>712704</Size>
<Path>C:\Windows\SYSTEM32\tdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8d0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\umpoext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения службы пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8f0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\umpo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb940000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\umpnpmgr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский режим службы самонастройки (Plug-and-Play)</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>7</ProcessIndex>
<ProcessId>884</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776292813936</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9230000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\bluetoothapis.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Usermode Api host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9580000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\BthRadioMedia.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab95a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WlanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wlan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaba920000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\rmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Radio Manager API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabae80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\NfcRadioMedia.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NFC Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabb8a0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\XboxGipRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Xbox GIP Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc0e0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\WwanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wwan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac78c0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\shacct.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Classes</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7f80000</BaseAddress>
<Size>208896</Size>
<Path>c:\windows\system32\wscsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8490000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\dhcpcore6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8c90000</BaseAddress>
<Size>385024</Size>
<Path>c:\windows\system32\dhcpcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>c:\windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac9c30000</BaseAddress>
<Size>1732608</Size>
<Path>c:\windows\system32\wevtsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба протоколирования событий</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca2a0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\timebrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер событий времени</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca330000</BaseAddress>
<Size>36864</Size>
<Path>c:\windows\system32\nrpsrv.DLL</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Name Resolution Proxy (NRP) RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4d0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lmhsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб транспорта TCPIP NetBios</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>8</ProcessIndex>
<ProcessId>0</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:00000000</AuthenticationId>
<CreateTime>131765775874898587</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>4294967295</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity></Integrity>
<Owner></Owner>
<ProcessName>Idle</ProcessName>
<ImagePath>Idle</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>9</ProcessIndex>
<ProcessId>4</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775907178738</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>System</ProcessName>
<ImagePath>System</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b6e00000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\System32\win32kfull.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Win32k Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7190000</BaseAddress>
<Size>1576960</Size>
<Path>C:\Windows\System32\win32kbase.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Базовый драйвер ядра Win32k</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7320000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\TSDDD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Framebuffer Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7330000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\cdd.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Canonical Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b74a0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\win32k.sys</Path>
<Version>10.0.14393.594 (rs1_release_inmarket.161213-1754)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Multi-User Win32 Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80278934000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\kd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Kernel Debugger</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80279678000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92e00000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\ksecdd.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ee0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\cmimcext.sys</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Configuration Manager Initial Configuration Extension Host Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ef0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\ntosext.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTOS extension host driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92fa0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\drivers\cng.sys</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Cryptography, Next Generation</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93040000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\system32\drivers\Wdf01000.sys</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения платформы драйвера режима ядра</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93120000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\drivers\WDFLDR.SYS</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Mode Driver Framework Loader</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93140000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\Drivers\acpiex.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPIEx Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93170000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\Drivers\WppRecorder.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WPP Trace Recorder</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93180000</BaseAddress>
<Size>733184</Size>
<Path>C:\Windows\System32\drivers\ACPI.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPI драйвер для NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93240000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\WMILIB.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMILIB WMI support library Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93260000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\intelpep.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Power Engine Plugin</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93280000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\drivers\WindowsTrustedRT.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932a0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Service Proxy Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\pcw.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Performance Counters for Windows Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932d0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\msisadrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ISA Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932e0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\isapnp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер шины PNP ISA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932f0000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\drivers\pci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Plug and Play PCI-перечислитель</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93350000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\vdrvroot.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Drive Root Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93370000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\drivers\pdc.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Power Dependency Coordinator Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933a0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\CEA.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation Kernel Mode Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\partmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Partition driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\nvraid.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) RAID Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93420000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\CLASSPNP.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI Class System Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93490000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\vmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Дочерний драйвер шины виртуальной машины Microsoft Hyper-V</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d934c0000</BaseAddress>
<Size>1212416</Size>
<Path>C:\Windows\System32\drivers\NDIS.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS (Network Driver Interface Specification)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d935f0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\drivers\NETIO.SYS</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network I/O Subsystem</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93670000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\hvsocket.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Hyper-V Socket Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\vmbkmcl.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V VMBus KMCL</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\winhv.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Hypervisor Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\pciide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Generic PCI IDE Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936e0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\PCIIDEX.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PCI IDE Bus Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93700000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\drivers\spaceport.sys</Path>
<Version>10.0.14393.1914 (rs1_release_inmarket.171117-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Spaces Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937a0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\intelide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel PCI IDE Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937b0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\volmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937d0000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\drivers\volmgrx.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер расширения диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93830000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\drivers\mountmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер точек подключения</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93850000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\nvstor.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) Sata Performance Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\drivers\storport.sys</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Storage Port Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93910000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\atapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI IDE Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93920000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\System32\drivers\ataport.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93960000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\storahci.sys</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS AHCI Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93990000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\stornvme.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft NVM Express Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\drivers\EhStorClass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enhanced Storage Class driver for IEEE 1667 devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\fileinfo.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FileInfo Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939f0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\Drivers\Wof.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр оверлея Windows</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93a80000</BaseAddress>
<Size>2297856</Size>
<Path>C:\Windows\System32\Drivers\NTFS.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер файловой системы NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\storvsc.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage VSC Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cd0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\Drivers\Fs_Rec.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>File System Recognizer Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93d10000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\System32\drivers\USBPORT.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта USB 1.1 и 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93db0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\mcupdate_GenuineIntel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Microcode Update Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93e50000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\System32\drivers\CLFS.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Common Log File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ec0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\tm.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Transaction Manager Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ef0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\PSHED.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер аппаратных ошибок, специфичных для платформы</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f10000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\BOOTVID.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>VGA Boot Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f20000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\FLTMGR.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер фильтров файловых систем Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\drivers\msrpc.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Remote Procedure Call Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94000000</BaseAddress>
<Size>430080</Size>
<Path>C:\Windows\System32\drivers\fwpkclnt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FWP/IPsec Kernel-Mode API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94070000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\wfplwfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WFP NDIS 6.30 Lightweight Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d940b0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DRIVERS\fvevol.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BitLocker Drive Encryption Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94160000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\volume.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94170000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\System32\drivers\volsnap.sys</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume Shadow Copy driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d941e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\scmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Class Memory Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\drivers\rdyboost.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ReadyBoost Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94250000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\Drivers\mup.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер поставщика множественных UNC</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94280000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\drivers\iorate.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>I/O rate control Filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942a0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\disk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PnP Disk Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942e0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\crashdmp.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crash Dump Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d943c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\drivers\cdrom.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI CD-ROM Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94400000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\drivers\filecrypt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows sandboxing and encryption filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94420000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\tbs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Export driver for kernel mode TPM API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94430000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Null.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NULL Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94440000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Beep.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BEEP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94450000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\BasicDisplay.sys</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94470000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\watchdog.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Watchdog Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94490000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\System32\drivers\dxgkrnl.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Kernel</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\BasicRender.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Render Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\Npfs.SYS</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPFS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94700000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\DRIVERS\tdx.sys</Path>
<Version>10.0.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDI Translation Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94740000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\DRIVERS\netbt.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>MBT Transport driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94790000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\drivers\afd.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер дополнительных функций для Winsock</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94830000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\vwififlt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual WiFi Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94850000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\pacer.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Планировщик пакетов QoS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\drivers\netbios.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetBIOS interface driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d948a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\rdbss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер подсистемы буферизации перенаправленного диска</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94920000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\drivers\csc.sys</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Client Side Caching Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\nsiproxy.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\npsvctrig.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Named pipe service triggers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\gpuenergydrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GPU Energy Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a00000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Drivers\dfsc.sys</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DFS Namespace Client Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a50000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\DRIVERS\ahcache.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Compatibility Cache</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a90000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-Transport Composite Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\kdnic.sys</Path>
<Version>6.01.00.0000 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Kernel Debugger Network Miniport</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ac0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\drivers\umbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User-Mode Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ae0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\i8042prt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта i8042</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b10000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\drivers\kbdclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса клавиатуры</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b30000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\mouclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса мыши</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b80000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\HDAudBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ba0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\drivers\portcls.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Port Class (Class Driver for Port/Miniport Devices)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c10000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\drmk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trusted Audio Drivers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c40000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\drivers\ks.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel CSA Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cb0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\usbohci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OHCI USB Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\CmBatt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Control Method Battery Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cd0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\BATTC.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Class Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ce0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\intelppm.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Processor Device Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d10000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\NdisVirtualBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечислитель виртуальных сетевых адаптеров (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d20000</BaseAddress>
<Size>2588672</Size>
<Path>C:\Windows\System32\drivers\tcpip.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fa0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\swenum.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Plug and Play Software Device Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fb0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\rdpbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft RDP Bus Device driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95200000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\DRIVERS\udfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UDF File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95280000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\Drivers\dump_diskdump.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d952c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\Drivers\dump_storahci.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95310000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\Drivers\dump_dumpfve.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95330000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\system32\drivers\HTTP.sys</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Стек протокола HTTP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95450000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\drivers\WudfPf.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - User-mode Driver Framework Platform Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95470000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\DRIVERS\bowser.sys</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Lan Manager Datagram Receiver Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d954a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT SMB Minirdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95520000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\mpsdrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Protection Service Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95540000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb20.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB 2.0 Redirector</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95580000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\DRIVERS\srvnet.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Network driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d955d0000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\System32\DRIVERS\srv2.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер сервера SMB 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95690000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb10.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB Downlevel SubRdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d956e0000</BaseAddress>
<Size>573440</Size>
<Path>C:\Windows\System32\DRIVERS\srv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95770000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\tcpipreg.sys</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>TCP/IP Registry Compatibility Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95860000</BaseAddress>
<Size>684032</Size>
<Path>C:\Windows\System32\drivers\dxgmms2.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics MMS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95910000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\luafv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра виртуализации файлов LUA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95960000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\storqosflt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр качества обслуживания хранилища</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95980000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\registry.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Registry Containment Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959a0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\drivers\lltdio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Mapper I/O Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959c0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\drivers\mslldp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер протокола Microsoft LLDP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\rspndr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Responder Driver for NDIS 6</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95ae0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\USBD.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Universal Serial Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95af0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\DRIVERS\HdAudio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Function Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95b60000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\ksthunk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Streaming WOW Thunk Service</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95bc0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\HIDPARSE.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hid Parsing Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97020000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\Drivers\360AntiHacker64.sys</Path>
<Version>1.0.0.1149</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络防黑模块</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97060000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\DRIVERS\360AvFlt.sys</Path>
<Version>1.1.0.1056</Version>
<Company>360.cn</Company>
<Description>360杀毒 文件监控驱动</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97080000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\DRIVERS\BAPIDRV64.sys</Path>
<Version>2.0.0.1221</Version>
<Company>360.cn</Company>
<Description>BAPIDRV</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d970c0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\drivers\360netmon.sys</Path>
<Version>2.1.11.5195</Version>
<Company>360.cn</Company>
<Description>360netmon</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97120000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\system32\DRIVERS\360Box64.sys</Path>
<Version>2.1.0.1253</Version>
<Company>360.cn</Company>
<Description>360Box64</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97180000</BaseAddress>
<Size>811008</Size>
<Path>C:\Windows\system32\DRIVERS\360FsFlt.sys</Path>
<Version>6.9.1.1751</Version>
<Company>360.cn</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97330000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\hidusb.sys</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>USB Miniport Driver for Input Devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97350000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\HIDCLASS.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека классов HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97380000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\mouhid.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра мыши HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97390000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\rassstp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS SSTP Miniport Call Manager</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973b0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\DRIVERS\NDProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\drivers\AgileVpn.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер вызовов минипорта RAS Agile VPN</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97420000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\drivers\rasl2tp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS L2TP mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97460000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\raspptp.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Peer-to-Peer Tunneling Protocol</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974a0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\raspppoe.sys</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS PPPoE mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\DRIVERS\ndistapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS 3.0 connection wrapper driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974d0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\drivers\ndiswan.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS PPP Framing Driver (Strong Encryption)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97510000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\DRIVERS\wanarp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS Remote Access and Routing ARP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97550000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\E1G6032E.sys</Path>
<Version>8.4.13.0 built by: WinDDK</Version>
<Company>Intel Corporation</Company>
<Description>Intel(R) PRO/1000 Adapter NDIS 6 deserialized driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97580000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\tunnel.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер интерфейса туннеля (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97600000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\Drivers\PROCMON24.SYS</Path>
<Version>3.10</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor Driver</Description>
</module>
<module>
<Timestamp>131795780236159256</Timestamp>
<BaseAddress>0xfffff80d97620000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\npf.sys</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>npf.sys (NT5/6 AMD64) Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97a60000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\system32\drivers\peauth.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Protected Environment Authentication and Authorization Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b30000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\Ndu.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Network Data Usage Monitoring Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b60000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\drivers\mmcss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMCSS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97bb0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\condrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Driver</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>10</ProcessIndex>
<ProcessId>320</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775908989732</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>smss.exe</ProcessName>
<ImagePath>C:\Windows\System32\smss.exe</ImagePath>
<CommandLine>\SystemRoot\System32\smss.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер сеанса  Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>11</ProcessIndex>
<ProcessId>3108</ProcessId>
<ParentProcessId>3092</ParentProcessId>
<ParentProcessIndex>12</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777624392598</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Explorer.EXE</ProcessName>
<ImagePath>C:\Windows\Explorer.EXE</ImagePath>
<CommandLine>C:\Windows\Explorer.EXE</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x31b0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5db0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Program Files\Uninstall Tool\utshellext.dll</Path>
<Version>1.1.0.15</Version>
<Company>CrystalIDEA Software</Company>
<Description>Uninstall Tool Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x81a0000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\MICROS~1\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x8cb0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5bf70000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_08e394a1a83e212f\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\Notepad++\NppShell_06.dll</Path>
<Version>0.1</Version>
<Company></Company>
<Description>ShellHandler for Notepad++ (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\Explorer.EXE</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2093056</Size>
<Path>C:\Windows\system32\wpdshext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки для переносных устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab350000</BaseAddress>
<Size>1683456</Size>
<Path>C:\Windows\System32\comsvcs.dll</Path>
<Version>2001.12.10941.16384 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Services</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab4f0000</BaseAddress>
<Size>1400832</Size>
<Path>C:\Windows\system32\connect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Мастера подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab650000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\system32\rasgcw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Страницы мастера RAS</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\System32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\system32\ieframe.DLL</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0df0000</BaseAddress>
<Size>1626112</Size>
<Path>C:\Windows\SYSTEM32\d3d9.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 9 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0f80000</BaseAddress>
<Size>1777664</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoViewer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Просмотр фотографий Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab27c0000</BaseAddress>
<Size>516096</Size>
<Path>C:\Windows\System32\imapi2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>IMAPI версии 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2840000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\bthprops.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложение панели управления Bluetooth</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2880000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\cscobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Внутрипроцессный COM-объект используемый клиентами CSC API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab29a0000</BaseAddress>
<Size>1912832</Size>
<Path>C:\Windows\System32\pnidui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Значок сетевой системы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2b80000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\system32\SettingMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Change Monitor</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2bc0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\PortableDeviceTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device (Parameter) Types Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab34f0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\System32\Actioncenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5120000</BaseAddress>
<Size>1691648</Size>
<Path>C:\Windows\system32\BatMeter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Meter Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\MsftEdit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7e40000</BaseAddress>
<Size>3420160</Size>
<Path>C:\Windows\System32\SyncCenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр синхронизации Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\system32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\system32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab99b0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\dxp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки компонента Device Stage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9ba0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\SYSTEM32\searchfolder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SearchFolder</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabac60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\EhStorAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Enhanced Storage API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae20000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msiltcfg.dll</Path>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer Configuration API Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaea0000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\system32\SHDOCVW.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\SYSTEM32\settingsynccore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SYSTEM32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786030517308</Timestamp>
<BaseAddress>0x7ffabb910000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\container.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Containers</Description>
</module>
<module>
<Timestamp>131795786030225106</Timestamp>
<BaseAddress>0x7ffabb970000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\daxexec.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>daxexec</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795786377372706</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786377355113</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786377364261</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SYSTEM32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795786376748307</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd3c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\InputSwitch.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переключатель ввода Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd670000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\framedynos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI SDK Provider Framework</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd6c0000</BaseAddress>
<Size>1306624</Size>
<Path>C:\Windows\System32\werconcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PRS CPL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd800000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\NPSMDesktopProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Библиотека DLL локального поставщика рабочего стола NPSM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabda60000</BaseAddress>
<Size>1241088</Size>
<Path>C:\Windows\System32\wscui.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdeb0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\wpdshserviceobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device Shell Service Object</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabded0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\stobject.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Объект службы оболочки Systray</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe470000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\wscinterop.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Health Center WSC Interop</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe580000</BaseAddress>
<Size>831488</Size>
<Path>C:\Program Files (x86)\360\Total Security\MenuEx64.dll</Path>
<Version>9, 6, 0, 1001</Version>
<Company></Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe650000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\system32\zipfldr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сжатые ZIP-папки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9a0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\Syncreg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Synchronization Framework Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\system32\NetworkExplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0b0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\playtomenu.dll</Path>
<Version>12.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека меню функции &quot;Передать на устройство&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\System32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf590000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\syncui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Портфель Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795786456426767</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfba0000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\WSCAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\MICROS~1\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b40000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\dlnashext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLNA Namespace DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\srchadmin.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры индексирования</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0f60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SYSTEM32\CHARTV.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Chart View</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1cc0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.Sockets.PushEnabledApplication DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac27a0000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.111.0603.0006\amd64\FileSyncShell64.dll</Path>
<Version>18.111.0603.0006</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795786030406949</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fltLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac32e0000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\twext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Свойства: Предыдущие версии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3350000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\OLEACCHOOKS.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Event Hooks Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\dsreg.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5140000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\AboveLockAppHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AboveLockAppHost</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5190000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\NotificationController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5570000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\system32\twinui.pcshell.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Twinui.PCShell</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac55d0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\windows.immersiveshell.serviceprovider.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.ImmersiveShell.ServiceProvider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\system32\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5c70000</BaseAddress>
<Size>65536</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoBase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Base Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6650000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\npsm.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPSM</Description>
</module>
<module>
<Timestamp>131795780903771340</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac78f0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\hgcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Панель управления домашней группы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795782572474169</Timestamp>
<BaseAddress>0x7ffac7ce0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\ploptin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Prelaunch OptIn</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d40000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\SYNCENG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Briefcase Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d90000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\SYSTEM32\SndVolSSO.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Громкость SCA </Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7f50000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\acppage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека расширений для вкладки &quot;Совместимость&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\SYSTEM32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795778062352400</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\ploptin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Prelaunch OptIn</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ea0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\hcproviders.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщики компонента &quot;Центр безопасности и обслуживания&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca190000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\WorkFoldersShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки рабочих папок (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795780604813666</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac80000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SYSTEM32\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>13</ProcessIndex>
<ProcessId>404</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776186257169</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>15</ProcessIndex>
<ProcessId>468</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776223665667</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>17</ProcessIndex>
<ProcessId>484</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226419105</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>wininit.exe</ProcessName>
<ImagePath>C:\Windows\system32\wininit.exe</ImagePath>
<CommandLine>wininit.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Автозагрузка приложений Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>18</ProcessIndex>
<ProcessId>520</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226825613</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>winlogon.exe</ProcessName>
<ImagePath>C:\Windows\system32\winlogon.exe</ImagePath>
<CommandLine>winlogon.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Программа входа в систему Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ff7b5570000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\winlogon.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа входа в систему Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaee0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\dwminit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMInit</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacafa0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\UXINIT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows User Experience Session Initialization Dll</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>19</ProcessIndex>
<ProcessId>588</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776277547408</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>lsass.exe</ProcessName>
<ImagePath>C:\Windows\system32\lsass.exe</ImagePath>
<CommandLine>C:\Windows\system32\lsass.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Description>Local Security Authority Process</Description>
<modulelist>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x222e3610000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\msprivs.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переводы привилегий Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ff6b2d20000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\lsass.exe</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Security Authority Process</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffab9170000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\vaultsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба диспетчера учетных данных</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf170000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\hmkd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows HMAC Key Derivation API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf190000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\ngcpopkeysrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Passport Proof-of-possession Key Service</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\keyiso.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба изоляции ключей CNG</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SYSTEM32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf270000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SecureTimeAggregator.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Secure Time Aggregator</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb9b0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\scecli.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент редактора конфигураций безопасности</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\SspiSrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA SSPI RPC interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\dpapisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DPAPI Server</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbad0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\efslsaext.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA extension for EFS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbb70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wdigest.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Digest Access</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc00000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\MicrosoftAccountCloudAP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MicrosoftAccount Cloud AP Plugin</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc50000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\cloudAP.DLL</Path>
<Version>10.0.14393.1358 (rs1_release.170602-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cloud AP Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbcb0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\system32\pku2u.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pku2u Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd00000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\tspkg.DLL</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Web Service Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe30000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\gmsaclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;gmsaclient.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe60000</BaseAddress>
<Size>843776</Size>
<Path>C:\Windows\system32\netlogon.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека службы Net Logon</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc030000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\KerbClientShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kerberos Client Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc180000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\negoexts.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NegoExtender Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\JOINUTIL.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\netprovfw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Provisioning Service Framework DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc260000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\SYSTEM32\samsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сервера диспетчера учетных записей</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc380000</BaseAddress>
<Size>1527808</Size>
<Path>C:\Windows\system32\lsasrv.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера LSA</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>20</ProcessIndex>
<ProcessId>704</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776284978539</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k RPCSS</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8250000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\wshhyperv.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V Winsock2 Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6a0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\RpcRtRemote.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote RPC Extension</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\rpcepmap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сопоставитель конечных точек RPC
</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>21</ProcessIndex>
<ProcessId>808</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0000c8d4</AuthenticationId>
<CreateTime>131765776288401882</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>Window Manager\DWM-1</Owner>
<ProcessName>dwm.exe</ProcessName>
<ImagePath>C:\Windows\system32\dwm.exe</ImagePath>
<CommandLine>&quot;dwm.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер окон рабочего стола</Description>
<modulelist>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ff683990000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\dwm.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\system32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7b70000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\System32\Windows.Gaming.Input.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Gaming Input API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\avrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9a30000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SYSTEM32\ism32k.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca110000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\dwmghost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMGhost</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca8d0000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\system32\dwmcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека ядра Microsoft DWM</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacac90000</BaseAddress>
<Size>856064</Size>
<Path>C:\Windows\SYSTEM32\udwm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\dwmredir.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компонент перенаправления диспетчера окон рабочего стола Microsoft</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>22</ProcessIndex>
<ProcessId>904</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776293087855</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x259b0640000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\SFC.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab830000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\netman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>c:\windows\system32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>c:\windows\system32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab1260000</BaseAddress>
<Size>10350592</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll</Path>
<Version>4.7.2117.0 built by: NET47REL1LAST</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Common Language Runtime - WorkStation</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>c:\windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795778252487651</Timestamp>
<BaseAddress>0x7ffabc160000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\System32\aeinv.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Inventory Component</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778007496118</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabfa00000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\SYSTEM32\MSVCR120_CLR0400.dll</Path>
<Version>12.00.52519.0 built by: VSWINSERVICING</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\MSI.DLL</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0fc0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\spp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих точек защиты Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1010000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\system32\MSCOREE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac10f0000</BaseAddress>
<Size>421888</Size>
<Path>c:\windows\system32\storsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы хранения</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1240000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll</Path>
<Version>4.7.2623.0 built by: NET471REL1LAST_C</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795781037721051</Timestamp>
<BaseAddress>0x7ffac1660000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\System32\aeinv.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Inventory Component</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2420000</BaseAddress>
<Size>466944</Size>
<Path>c:\windows\system32\das.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сопоставления устройств</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795778007645121</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac41c0000</BaseAddress>
<Size>139264</Size>
<Path>c:\windows\system32\trkwks.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент отслеживания изменившихся связей</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4650000</BaseAddress>
<Size>516096</Size>
<Path>c:\windows\system32\pcasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба помощника по совместимости программ</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Assembly manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b50000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\dssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы NT для службы совместного доступа к данным</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6120000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\sysmain.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост службы Superfetch</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b10000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\SYSTEM32\WUDFPlatform.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - библиотека платформ пользовательского режима</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b50000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\wudfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation (WDF) - служба среды выполнения платформы драйвера режима пользователя</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9800000</BaseAddress>
<Size>376832</Size>
<Path>c:\windows\system32\audioendpointbuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство построения конечных точек Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9de0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\portabledeviceconnectapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Portable Device Connection API Components</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SYSTEM32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca2d0000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\ncbservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Посредник подключений к сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>c:\windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca710000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\pcadm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Diagnostic Module</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\system32\SXS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>c:\windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>23</ProcessIndex>
<ProcessId>96</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776304995849</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2510000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\energyprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2580000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\ncuprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Connectivity Statistics Provider for System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2b90000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\nduprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик сетевой статистики для службы отслеживания использования ресурсов системы</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bb0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\appsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bd0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\eeprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy Estimator SRUM provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2c20000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\wfapigp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall GPO Helper dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2d70000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\wpnsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SRUM provider for WPN</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3310000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\srumsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3730000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\pnpts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PlugPlay Troubleshooter</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3bd0000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\ncdautosetup.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы автоматической настройки сетевых устройств</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac41f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\adhapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD harvest sites and subnets API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4500000</BaseAddress>
<Size>200704</Size>
<Path>c:\windows\system32\dps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба политики диагностики WDI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4cd0000</BaseAddress>
<Size>933888</Size>
<Path>c:\windows\system32\mpssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба защиты (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6740000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\dtsh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API состояния общего доступа и обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac74b0000</BaseAddress>
<Size>827392</Size>
<Path>c:\windows\system32\bfe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба базовой фильтрации</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\coremessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\system32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\CFGMGR32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>24</ProcessIndex>
<ProcessId>348</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776305446235</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k netsvcs</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaa0aa0000</BaseAddress>
<Size>2138112</Size>
<Path>c:\windows\system32\wlidsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба учетных записей Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0750000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\system32\rascustom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль настраиваемых протоколов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab07b0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\vpnike.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>VPNIKE Protocol Engine - Test dll</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab09b0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\system32\rasppp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access PPP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0a00000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\rastapi.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access TAPI Compliance Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab3440000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\rasmans.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер подключений удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4c50000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\eappprxy.dll</Path>
<Version>10.0.14393.187 (rs1_release_inmarket.160906-1818)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft EAPHost Peer Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab9a90000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\dmEnrollEngine.DLL</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enroll Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabc210000</BaseAddress>
<Size>2355200</Size>
<Path>c:\windows\system32\wuaueng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Агент Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabdf60000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\raschap.dll</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>Удаленные доступ через PPP CHAP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4a0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\appinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о приложении</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabed80000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\system32\wbem\wbemess.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee10000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee30000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\system32\wbem\wmiprvsd.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795786151289779</Timestamp>
<BaseAddress>0x7ffabf030000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf090000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>c:\windows\system32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfda0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\wbem\ncprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Non-COM WMI Event Provision APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0000000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wbem\repdrvfs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Repository Driver</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\shacctprofile.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Profile Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795783766785197</Timestamp>
<BaseAddress>0x7ffac13e0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\usocore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обновление ядра оркестратора сеанса</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1530000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SYSTEM32\dpx.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft(R) Delta Package Expander</Description>
</module>
<module>
<Timestamp>131795783773591339</Timestamp>
<BaseAddress>0x7ffac1660000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\System32\updatehandlers.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Session Orchestrator Update Handlers</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1900000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\appxapplicabilityblob.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Appx Applicability Blob DLL</Description>
</module>
<module>
<Timestamp>131795783942703101</Timestamp>
<BaseAddress>0x7ffac1940000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1970000</BaseAddress>
<Size>1073152</Size>
<Path>c:\windows\system32\qmgr.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фоновая интеллектуальная служба передачи</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1c30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\DMProcessXMLFiltered.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmprocessxmlfiltered</Description>
</module>
<module>
<Timestamp>131795779661934902</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1cf0000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\SYSTEM32\wuuhext.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update Agent plugin for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1df0000</BaseAddress>
<Size>61440</Size>
<Path>c:\windows\system32\NCI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CoInstaller: NET</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e20000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f10000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\DMCmnUtils.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmcmnutils</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f50000</BaseAddress>
<Size>471040</Size>
<Path>C:\Windows\system32\wbem\esscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20f0000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\CLUSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API кластера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2210000</BaseAddress>
<Size>1351680</Size>
<Path>C:\Windows\system32\wbem\wbemcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инструментарий управления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2370000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\adhsvc.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD Harvest Sites and Subnets Service</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2390000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\httpprxm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager</Description>
</module>
<module>
<Timestamp>131795775850813653</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac24a0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\system32\RESUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служебной программы ресурсов кластера (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795784861928280</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2640000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\wmidcom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2670000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\miutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура управления</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac26f0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\sscoreext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Core DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2720000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SYSTEM32\WPTaskScheduler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WP Task Scheduler DLL</Description>
</module>
<module>
<Timestamp>131795784861934949</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2770000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\SSCORE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основная DLL-библиотека службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2940000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CSystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Classic System Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>c:\windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a40000</BaseAddress>
<Size>974848</Size>
<Path>c:\windows\system32\iphlpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Эта служба предоставляет автоматическое подключение IPv6 в сети IPv4.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c60000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\WDSCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Panther Engine Module</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\system32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3740000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3b40000</BaseAddress>
<Size>245760</Size>
<Path>c:\windows\system32\wbem\wmisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3fa0000</BaseAddress>
<Size>331776</Size>
<Path>c:\windows\system32\srvsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) ресурсов для службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4160000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\wpnservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба системы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4480000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\taskcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оснастка обратной совместимости диспетчера задач</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4540000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\ProximityServicePAL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service PAL</Description>
</module>
<module>
<Timestamp>131795775380234927</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4cc0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ProximityCommonPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Common PAL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4dc0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\ProximityCommon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Универсальная реализация близкого взаимодействия</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4ee0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\ProximityService.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service Implementation</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5ef0000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\System32\MbaeApiPublic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Mobile Broadband Account API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786151642053</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7700000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\CredentialMigrationHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Migration Handler</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\sqmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SQM Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795783776936389</Timestamp>
<BaseAddress>0x7ffac7ce0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\usoapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Session Orchestrator API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d60000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\UpdatePolicy.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Policy Reader</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e90000</BaseAddress>
<Size>749568</Size>
<Path>c:\windows\system32\FVEAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows BitLocker Drive Encryption API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac82d0000</BaseAddress>
<Size>643072</Size>
<Path>c:\windows\system32\shsvcs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8590000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\LocationWinPalMisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Location Platform Abstraction Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac85c0000</BaseAddress>
<Size>1810432</Size>
<Path>c:\windows\system32\LocationFramework.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа географического положения Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8780000</BaseAddress>
<Size>274432</Size>
<Path>c:\windows\system32\UBPM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL единого диспетчера фоновых процессов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8b60000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\schedsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба планировщика заданий</Description>
</module>
<module>
<Timestamp>131795783774133461</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac91c0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\profsvcext.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvcExt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92a0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\sens.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба уведомления о системных событиях (SENS)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\themeservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы темы оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9420000</BaseAddress>
<Size>380928</Size>
<Path>c:\windows\system32\profsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvc</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9a70000</BaseAddress>
<Size>1257472</Size>
<Path>c:\windows\system32\gpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca700000</BaseAddress>
<Size>32768</Size>
<Path>c:\windows\system32\DABAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Desktop Activity Broker API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca720000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\bitsigd.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service IGD Support</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacab70000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба географического положения</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac40000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\seclogon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL службы вторичного входа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac50000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\bitsperf.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Perfmon Counter Access</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\MSWSOCK.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>25</ProcessIndex>
<ProcessId>372</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776305463443</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>c:\windows\system32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab91f0000</BaseAddress>
<Size>233472</Size>
<Path>c:\windows\system32\sstpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обеспечивает возможность использования SSTP для подключения к удаленным компьютерам с помощью VPN.</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795780812578370</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabc610000</BaseAddress>
<Size>540672</Size>
<Path>c:\windows\system32\w32time.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба времени Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabef00000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\cdpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба CDP Майкрософт (R)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05e0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\sbservicetrigger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Socket Broker Service Trigger</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795780812550384</Timestamp>
<BaseAddress>0x7ffac3290000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\fthsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль диагностики отказоустойчивой кучи Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4130000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\fdphost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба размещения поставщиков функций обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4200000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\perftrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Performance PerfTrack</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5b80000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\AuthBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API WinRT для веб-проверки подлинности</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66e0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\fdssdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery SSDP Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6960000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\fdwsd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery WS Discovery Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac76d0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\vmictimeprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Machine Integration Component Time Sync Provider Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7a10000</BaseAddress>
<Size>544768</Size>
<Path>c:\windows\system32\netprofmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер списка сетей</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7f70000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\licensemanagersvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManagerSvc</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90a0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\nsisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RPC-сервер интерфейса сохранения сети</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac91f0000</BaseAddress>
<Size>172032</Size>
<Path>c:\windows\system32\FontProvider.dll</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Font Provider Library</Description>
</module>
<module>
<Timestamp>131795780812573070</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9860000</BaseAddress>
<Size>1896448</Size>
<Path>c:\windows\system32\fntcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэша шрифтов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>c:\windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795780812567382</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>26</ProcessIndex>
<ProcessId>360</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311216195</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffabaad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\deviceaccess.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Broker And Policy COM Server</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac7e70000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\coreaudiopolicymanagerext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;coreaudiopolicymanagerext.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac87d0000</BaseAddress>
<Size>237568</Size>
<Path>c:\windows\system32\AUDIOSRVPOLICYMANAGER.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Audio Service Policy Manager</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac90d0000</BaseAddress>
<Size>978944</Size>
<Path>c:\windows\system32\audiosrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\POWRPROF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>27</ProcessIndex>
<ProcessId>1040</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311708649</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8820000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SYSTEM32\cmintegrator.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>cmintegrator.dll</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8c50000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wcmcsp.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Service Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8fe0000</BaseAddress>
<Size>737280</Size>
<Path>c:\windows\system32\wcmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы диспетчера подключений Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>28</ProcessIndex>
<ProcessId>1068</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776312395030</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\CRYPTNET.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\cryptcatsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Catalog Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65f0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\crypttpmeksvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic TPM Endorsement Key Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6680000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\cryptsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6f00000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\wkssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы рабочей станции</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79e0000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\netjoin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL присоединения к домену</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\WlanApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7c00000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\ssdpapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8260000</BaseAddress>
<Size>425984</Size>
<Path>c:\windows\system32\ncsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индикатор работоспособности сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8370000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\nlasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о подключенных сетях 2</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8410000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dnsext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DNS extension DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SYSTEM32\Fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8830000</BaseAddress>
<Size>290816</Size>
<Path>c:\windows\system32\dnsrslvr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэширующего сопоставителя DNS</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\JoinUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>29</ProcessIndex>
<ProcessId>1248</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776322176070</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>spoolsv.exe</ProcessName>
<ImagePath>C:\Windows\System32\spoolsv.exe</ImagePath>
<CommandLine>C:\Windows\System32\spoolsv.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер очереди печати</Description>
<modulelist>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ff639680000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\spoolsv.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер очереди печати</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffab8a60000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaba980000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\jscript.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabb7d0000</BaseAddress>
<Size>851968</Size>
<Path>C:\Windows\System32\win32spl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик печати с исполнением на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\prntvpt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Ticket Services Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd70000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_53d78f68bc1697cc\Amd64\PrintConfig.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc0c0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPFILEQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPFILEQ</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc590000</BaseAddress>
<Size>118784</Size>
<Path>C:\Program Files\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc5b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\amsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Anti-Malware Scan Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd040000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdPnp.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pnp Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd060000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\WSDMon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер порта принтера WSD</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd100000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\usbmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Standard Dynamic Printing Port Monitor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd160000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\wsnmp32.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft WinSNMP v2.0 Manager API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd2a0000</BaseAddress>
<Size>1159168</Size>
<Path>C:\Windows\System32\localspl.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека локального диспетчера очереди</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabde60000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\System32\tcpmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека монитора портов TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe3f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\spool\PRTPROCS\x64\winprint.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Print Processor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe6c0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\PrintIsolationProxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Sandbox COM Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe8a0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\snmpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SNMP Utility Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe980000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\SPOOLSS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Spooler SubSystem DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f00000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\FXSMON.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft  Fax Print Monitor</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac4e90000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\wshirda.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Sockets Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac7e00000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\inetpp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Internet Print Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>30</ProcessIndex>
<ProcessId>1512</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776336551242</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffabe9f0000</BaseAddress>
<Size>258048</Size>
<Path>c:\windows\system32\ssdpsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы SSDP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69b0000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\fdrespub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба публикации ресурсов обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>c:\windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>31</ProcessIndex>
<ProcessId>1556</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776339471770</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k utcsvc</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x272f9bf0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf140000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\CourtesyEngine.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Feedback Courtesy Engine DLL Server</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfde0000</BaseAddress>
<Size>143360</Size>
<Path>c:\windows\system32\CRYPTXML.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API-интерфейс XML DigSig</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\Netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\DSREG.DLL</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac5fd0000</BaseAddress>
<Size>1056768</Size>
<Path>c:\windows\system32\WindowsPerformanceRecorderControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Performance Recorder Control Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>c:\windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6210000</BaseAddress>
<Size>2007040</Size>
<Path>c:\windows\system32\diagtrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диагностическое отслеживание Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786489787144</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795786490911252</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>32</ProcessIndex>
<ProcessId>1636</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776343009549</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k appmodel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>c:\windows\system32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3c10000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\tileobjserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер моделей данных плиток</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>c:\windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>c:\windows\system32\windows.staterepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795780599947775</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795780600943570</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>33</ProcessIndex>
<ProcessId>1744</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776348255325</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>MemCompression</ProcessName>
<ImagePath>MemCompression</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>34</ProcessIndex>
<ProcessId>2100</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776438403561</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffabff90000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\ipsecsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows IPsec SPD Server DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac1e00000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\FwRemoteSvr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall Remote APIs Server</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>35</ProcessIndex>
<ProcessId>2648</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777555980720</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>sihost.exe</ProcessName>
<ImagePath>C:\Windows\system32\sihost.exe</ImagePath>
<CommandLine>sihost.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Shell Infrastructure Host</Description>
<modulelist>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ff7bbae0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\sihost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Infrastructure Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb910000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\container.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Containers</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb970000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\daxexec.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>daxexec</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc450000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\system32\ShareHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShareHost</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc800000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\windowmanagement.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Window Management</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc850000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\AppointmentActivation.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL for AppointmentActivation</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc8b0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\NotificationPlatformComponent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationPlatformComponent</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc9a0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\activationmanager.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Activation Manager</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabca10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\ClipboardServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Modern Clipboard</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcde0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Windows\System32\modernexecserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Modern Execution</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcf10000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\desktopshellext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DesktopHost Extensions</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\system32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>36</ProcessIndex>
<ProcessId>840</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777563791648</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k UnistackSvcGroup</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf6a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\PhoneUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Phone utilities</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf700000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\System32\PIMSTORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>POOM</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab05d0000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\AccountAccessor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync data model to access accounts</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab0630000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\SyncController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SyncController for managing sync of mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb20000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\CEMAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CEMAPI</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcd80000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\cdpusersvc.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP User Components</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabd630000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\MCCSEngineShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Utilies shared among OneSync engines</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabdde0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\SYNCUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabed20000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\aphostservice.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>c:\windows\system32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4100000</BaseAddress>
<Size>151552</Size>
<Path>c:\windows\system32\NetworkHelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac97b0000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\InprocLogger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>In-proc Private Event Trace Logger</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca1d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\UserDataTypeHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Type Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca270000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\UserDataLanguageUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Language-related helper functions for user data</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca520000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\APHostClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service RPC Client </Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacabf0000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\MCCSPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform abstraction layer dll for MCCS</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacac20000</BaseAddress>
<Size>86016</Size>
<Path>c:\windows\system32\UserDataPlatformHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>37</ProcessIndex>
<ProcessId>528</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777565618284</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\system32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb440000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\system32\MTFServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;MTFServer.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb510000</BaseAddress>
<Size>2854912</Size>
<Path>C:\Windows\system32\InputService.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Text InputService Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8c0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\InputLocaleManager.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;InputLocaleManager.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8f0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\EditBufferTestHook.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;EditBufferTestHook.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb9f0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\system32\MSUTB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) сервера MSUTB</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabba70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\MsCtfMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MsCtfMonitor DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabbc20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\PlaySndSrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба PlaySound</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\system32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac7d10000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\KBDUS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>United States Keyboard Layout</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab10000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\WordBreakers.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;WordBreakers.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>38</ProcessIndex>
<ProcessId>3632</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777941176116</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>RuntimeBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\RuntimeBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\RuntimeBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Runtime Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7a45f0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\RuntimeBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Runtime Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\System32\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795780843802542</Timestamp>
<BaseAddress>0x7ffaad3f0000</BaseAddress>
<Size>1826816</Size>
<Path>C:\Windows\System32\Wpc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека параметров родительского контроля</Description>
</module>
<module>
<Timestamp>131795786292112107</Timestamp>
<BaseAddress>0x7ffab08d0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\LockAppBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL брокера приложения &quot;Блокировка&quot; Windows</Description>
</module>
<module>
<Timestamp>131795786164057245</Timestamp>
<BaseAddress>0x7ffab0b10000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\mssvp.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа Vista MSSearch</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\mssrch.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795780489291214</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795786088780638</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786148630640</Timestamp>
<BaseAddress>0x7ffabaad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\deviceaccess.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Broker And Policy COM Server</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795786089047958</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795780613006289</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795780733496994</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795780611542837</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795786306767518</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786143522657</Timestamp>
<BaseAddress>0x7ffabd220000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\Windows.Devices.Enumeration.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Enumeration</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795786165227211</Timestamp>
<BaseAddress>0x7ffabe130000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\mapi32.dll</Path>
<Version>1.0.2536.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенный MAPI 1.0 для Windows NT</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795786089826857</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe880000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\FeClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT File Encryption Client Interfaces</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe8c0000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\system32\windows.cortana.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.Desktop</Description>
</module>
<module>
<Timestamp>131795786151786571</Timestamp>
<BaseAddress>0x7ffabf030000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780443980999</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf9c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\system32\windows.cortana.onecore.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.OneCore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795786445101159</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795779561161209</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786075081206</Timestamp>
<BaseAddress>0x7ffac15d0000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Core.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Model Core API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780447369522</Timestamp>
<BaseAddress>0x7ffac37b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795771234179313</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795780489961900</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795780846908833</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5ca0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\AppExtension.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API AppExtension</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786144114651</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795786145514308</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795786287854312</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786448623381</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7d00000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SYSTEM32\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795780849625720</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786090201282</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\samlib.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795780611842861</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>39</ProcessIndex>
<ProcessId>3164</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778119045372</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ShellExperienceHost.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe&quot; -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Windows Shell Experience Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ff697570000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Experience Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f760000</BaseAddress>
<Size>3796992</Size>
<Path>C:\Windows\System32\MFMediaEngine.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Media Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaabad0000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\mfsrcsnk.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Source and Sink DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaafe70000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\System32\mfcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Core DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab0be0000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\ShellExperiences\NetworkUX.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab9eb0000</BaseAddress>
<Size>2899968</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.ActionCenter.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActionCenter Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaba180000</BaseAddress>
<Size>7880704</Size>
<Path>C:\Windows\ShellExperiences\StartUI.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Start UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SYSTEM32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd420000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\RTMediaFrame.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime MediaFrame DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe410000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\SYSTEM32\globcollationhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GlobCollationHost</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795780594734370</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0080000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\System32\resampledmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Resampler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0110000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\QuickActionsDataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>QuickActionsDataModel</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0160000</BaseAddress>
<Size>491520</Size>
<Path>C:\Windows\ShellExperiences\QuickActions.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac40f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4eb0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5b20000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\CompPkgSup.DLL</Path>
<Version>10.0.14393.969 (rs1_release_inmarket.170315-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Component Package Support DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5e90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\Windows.Media.MediaControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера MediaControl среды выполнения Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>40</ProcessIndex>
<ProcessId>4856</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778391112136</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MSASCuiL.exe</ProcessName>
<ImagePath>C:\Program Files\Windows Defender\MSASCuiL.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Windows Defender\MSASCuiL.exe&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Description>Windows Defender notification icon</Description>
<modulelist>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x23622c70000</BaseAddress>
<Size>733184</Size>
<Path>C:\Program Files\Windows Defender\EppManifest.dll</Path>
<Version>4.10.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль ресурсов настройки пользовательского интерфейса</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ff63bef0000</BaseAddress>
<Size>651264</Size>
<Path>C:\Program Files\Windows Defender\MSASCuiL.exe</Path>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Defender notification icon</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4560000</BaseAddress>
<Size>950272</Size>
<Path>C:\Program Files\Windows Defender\mpclient.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Client Interface</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>41</ProcessIndex>
<ProcessId>4928</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778406250112</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>uTorrent.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe&quot;  /MINIMIZED</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>3.5.4.44498</Version>
<Description>µTorrent</Description>
<modulelist>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>5406720</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</Path>
<Version>3.5.4.44498</Version>
<Company>BitTorrent Inc.</Company>
<Description>µTorrent</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e140000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SysWOW64\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1c0000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\SysWOW64\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6ef20000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70af0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fc0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fd0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fe0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>42</ProcessIndex>
<ProcessId>3608</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778496229053</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ApplicationFrameHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\ApplicationFrameHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\ApplicationFrameHost.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Application Frame Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ff6aa270000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\ApplicationFrameHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Frame Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5240000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\ApplicationFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фрейм приложения</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\system32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795786034558955</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\D3D10Warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>43</ProcessIndex>
<ProcessId>5952</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778883326814</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54150_1240996307 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>44</ProcessIndex>
<ProcessId>5800</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765779120650795</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\esent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>45</ProcessIndex>
<ProcessId>340</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765800389528045</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54870_1839591030 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c50000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\Ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>46</ProcessIndex>
<ProcessId>2736</ProcessId>
<ParentProcessId>3976</ParentProcessId>
<ParentProcessIndex>47</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765800903010156</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Taskmgr.exe</ProcessName>
<ImagePath>C:\Windows\System32\Taskmgr.exe</ImagePath>
<CommandLine>&quot;C:\Windows\System32\Taskmgr.exe&quot; /2 </CommandLine>
<CompanyName>Microsoft® Windows® Operating System</CompanyName>
<Version>1, 0, 0, 1</Version>
<Description>Task Manager</Description>
<modulelist>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ff7c2a70000</BaseAddress>
<Size>1286144</Size>
<Path>C:\Windows\System32\Taskmgr.exe</Path>
<Version>1, 0, 0, 1</Version>
<Company>Microsoft® Windows® Operating System</Company>
<Description>Task Manager</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdfa0000</BaseAddress>
<Size>393216</Size>
<Path>C:\Windows\System32\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\System32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>49</ProcessIndex>
<ProcessId>6724</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803507001117</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHActiveDefense.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe&quot;</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1008</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795778431738530</Timestamp>
<BaseAddress>0x10000</BaseAddress>
<Size>413696</Size>
<Path>C:\ProgramData\Package Cache\{b8e12890-118d-4721-8e54-05d978086712}\VC_redist.x64.exe</Path>
<Version>14.0.24516.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24516</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0xd0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</Path>
<Version>10,0,0,1008</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795778469924367</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Wireshark\WinPcap_4_1_3.exe</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>WinPcap 4.1.3 installer</Description>
</module>
<module>
<Timestamp>131795778203065490</Timestamp>
<BaseAddress>0x840000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files\Wireshark\vcredist_x64.exe</Path>
<Version>14.12.25810.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810</Description>
</module>
<module>
<Timestamp>131795786058722021</Timestamp>
<BaseAddress>0x34c0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\browser_broker.exe</Path>
<Version>11.00.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>Browser_Broker</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x3c80000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795780944214585</Timestamp>
<BaseAddress>0x40a0000</BaseAddress>
<Size>438272</Size>
<Path>C:\Program Files\Wireshark\dumpcap.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community</Company>
<Description>Dumpcap</Description>
</module>
<module>
<Timestamp>131795780231568066</Timestamp>
<BaseAddress>0x4630000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SysWOW64\net1.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Command</Description>
</module>
<module>
<Timestamp>131795778389953959</Timestamp>
<BaseAddress>0xa8e0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786140191230</Timestamp>
<BaseAddress>0xe830000</BaseAddress>
<Size>2416640</Size>
<Path>C:\Windows\System32\smartscreen.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreen</Description>
</module>
<module>
<Timestamp>131795780691287613</Timestamp>
<BaseAddress>0xf730000</BaseAddress>
<Size>8298496</Size>
<Path>C:\Program Files\Wireshark\Wireshark.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark</Description>
</module>
<module>
<Timestamp>131795780222197886</Timestamp>
<BaseAddress>0x10000000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fb90000</BaseAddress>
<Size>2736128</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\deepscan.dll</Path>
<Version>3, 5, 1, 2130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60190000</BaseAddress>
<Size>475136</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360SafeCamera.tpi</Path>
<Version>2, 0, 0, 1031</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60210000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\jcloudscan.dll</Path>
<Version>1, 0, 0, 1012</Version>
<Company>360.cn</Company>
<Description>360安全卫士 移动云查询模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604a0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appdext.dll</Path>
<Version>1, 0, 0, 1483</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604e0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\DrvUtility.dll</Path>
<Version>1, 0, 0, 1081</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60510000</BaseAddress>
<Size>409600</Size>
<Path>C:\Program Files (x86)\360\Total Security\SafeScan.dll</Path>
<Version>1, 0, 0, 1074</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60580000</BaseAddress>
<Size>204800</Size>
<Path>C:\Program Files (x86)\360\Total Security\ScanStub.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x605c0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360gameidentify.dll</Path>
<Version>1, 0, 1, 1050</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏识别模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60640000</BaseAddress>
<Size>430080</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\Netgm.dll</Path>
<Version>9,0,0,1005</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏模式判断模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60a50000</BaseAddress>
<Size>479232</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\DsSysRepair.dll</Path>
<Version>1, 0, 0, 1062</Version>
<Company>QIHU360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security System Repair Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61000000</BaseAddress>
<Size>184320</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\qutmipc.dll</Path>
<Version>7, 3, 0, 1267</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61030000</BaseAddress>
<Size>262144</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg.dll</Path>
<Version>3, 0, 0, 1160</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x610d0000</BaseAddress>
<Size>1097728</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\SomAdvUtils.dll</Path>
<Version>3, 1, 1, 2020</Version>
<Company>360.cn</Company>
<Description>360 Safeguard PC Boost</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61480000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qex\qex.dll</Path>
<Version>4.1.13.3366</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2017 Antivirus</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x616a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SelfProtectAPI2.dll</Path>
<Version>7, 1, 1, 1033</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61700000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360procmon.dll</Path>
<Version>7, 1, 1, 1221</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61780000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\netdefender.dll</Path>
<Version>1, 0, 0, 1129</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x617e0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appd.dll</Path>
<Version>7, 3, 6, 3113</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360HipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61ab0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\fileMgr.dll</Path>
<Version>7, 3, 0, 1963</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x621a0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\yhregd.dll</Path>
<Version>7, 2, 0, 1903</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62280000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\360SoftMgrS.dll</Path>
<Version>2, 1, 6, 1490</Version>
<Company>360.cn</Company>
<Description>360软件管家 服务模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62470000</BaseAddress>
<Size>405504</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll</Path>
<Version>7, 2, 1, 1279</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x624e0000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\360box.dll</Path>
<Version>2, 0, 0, 1043</Version>
<Company>360.cn</Company>
<Description>360隔离沙箱模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\deepscan\DsRes.dll</Path>
<Version>1,0,0,1012</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security Resource</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b70000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\gamemode.tpi</Path>
<Version>9,0,0,1001</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Game Mode Control</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67130000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\devenum.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечисление устройств.</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\fltlib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6c0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6ea80000</BaseAddress>
<Size>860160</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\QVM\360QVM.dll</Path>
<Version>5.0.2.1003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security QVM Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70210000</BaseAddress>
<Size>966656</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEngine.dll</Path>
<Version>1, 0, 0, 2016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70300000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEI.dll</Path>
<Version>1, 0, 0, 2003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>50</ProcessIndex>
<ProcessId>6340</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765803510844292</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>QHSafeTray.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</ImagePath>
<CommandLine>/showtrayicon</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1024</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0xec0000</BaseAddress>
<Size>2351104</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</Path>
<Version>10,0,0,1024</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x68f0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c480000</BaseAddress>
<Size>245760</Size>
<Path>C:\Program Files (x86)\360\Total Security\PDown.dll</Path>
<Version>1, 3, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Security Center Network Module </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5fe30000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll</Path>
<Version>9,6,0,1001</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60020000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360netctrl.dll</Path>
<Version>5, 3, 15, 2232</Version>
<Company>360.cn</Company>
<Description>360 Total Security NetwokrMonCtrl</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60090000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\netmon.tpi</Path>
<Version>5, 1, 1, 3157</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360安全卫士 流量防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60350000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Program Files (x86)\360\Total Security\ToolBox.dll</Path>
<Version>1, 0, 0, 1094</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x606b0000</BaseAddress>
<Size>598016</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe.dll</Path>
<Version>1, 0, 0, 1120</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x609b0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360GuardBase.dll</Path>
<Version>3, 1, 0, 1060</Version>
<Company>360.cn</Company>
<Description>360保镖</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61070000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SomProxy.dll</Path>
<Version>1, 0, 0, 1900</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x611e0000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360connect.tpi</Path>
<Version>9,2,0,1030</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Connect</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x618c0000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files (x86)\360\Total Security\sites.dll</Path>
<Version>11, 1, 0, 1212</Version>
<Company>360.cn</Company>
<Description>360安全卫士</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360hipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\softmgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\Cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62210000</BaseAddress>
<Size>446464</Size>
<Path>C:\Program Files (x86)\360\Total Security\360TSCommon.dll</Path>
<Version>9, 0, 0, 1016</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62960000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\CleanPlusCache.tpi</Path>
<Version>1, 0, 0, 1004</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>CleanPlusCache</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795771279916892</Timestamp>
<BaseAddress>0x68850000</BaseAddress>
<Size>2764800</Size>
<Path>C:\Windows\SysWOW64\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e6e0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e770000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SysWOW64\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71170000</BaseAddress>
<Size>466944</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\CQhCltHttpW.dll</Path>
<Version>1, 4, 0, 1030</Version>
<Company>QIHU 360 SOFTWARE  CO. LIMITED</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>51</ProcessIndex>
<ProcessId>6860</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803555957830</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHWatchdog.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe&quot; /watch</CommandLine>
<CompanyName>QIHU 360 SOFTWARE CO. LIMITED</CompanyName>
<Version>8,2,0,1000</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0xdf0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</Path>
<Version>8,2,0,1000</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>52</ProcessIndex>
<ProcessId>5924</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765805232900810</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>wmiprvse.exe</ProcessName>
<ImagePath>C:\Windows\sysWOW64\wbem\wmiprvse.exe</ImagePath>
<CommandLine>C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Description>WMI Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x950000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\sysWOW64\wbem\wmiprvse.exe</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Provider Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\storagewmi_passthru.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60160000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x604d0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\delegatorprovider.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>54</ProcessIndex>
<ProcessId>4408</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765812380694767</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x17826230000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1140000</BaseAddress>
<Size>1134592</Size>
<Path>C:\Windows\System32\ReAgent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>C:\Windows\System32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\system32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe000000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\system32\WinSATAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Assessment Tool API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf050000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\sdiageng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема выполнения сценариев диагностики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4ae0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sdiagschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запланированная задача сценариев проверки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4b00000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\MemoryDiagnostic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач средства проверки памяти Windows (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac5c80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\TempSignedLicenseExchangeTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TempSignedLicenseExchangeTask Task</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca200000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\ReAgentTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca210000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\RstrtMgr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер перезапуска</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacac00000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\radarrs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>программа устранения нехватки системных ресурсов Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>55</ProcessIndex>
<ProcessId>6944</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131767576301455145</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SkypeHost.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe&quot; -ServerName:SkypeHost.ServerServer</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>12.1815.210.0</Version>
<Description>Microsoft Skype</Description>
<modulelist>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ff7e8670000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaae130000</BaseAddress>
<Size>22437888</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkyWrap.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabe150000</BaseAddress>
<Size>2691072</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\skypert.dll</Path>
<Version>2018.15.01.31</Version>
<Company></Company>
<Description>SkypeRT shared library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1a80000</BaseAddress>
<Size>978944</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7c80000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>56</ProcessIndex>
<ProcessId>1048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131768729449405953</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>sedsvc.exe</ProcessName>
<ImagePath>C:\Program Files\rempl\sedsvc.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\rempl\sedsvc.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Description>sedsvc</Description>
<modulelist>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ff751430000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\rempl\sedsvc.exe</Path>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>sedsvc</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>57</ProcessIndex>
<ProcessId>7744</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081112364684</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; </CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x11330000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60900000</BaseAddress>
<Size>720896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\urlproc.dll</Path>
<Version>2, 9, 5, 1260</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x68b00000</BaseAddress>
<Size>44998656</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ce30000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6dc80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files (x86)\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6df70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\SysWOW64\shdocvw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e070000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e090000</BaseAddress>
<Size>233472</Size>
<Path>C:\Windows\SysWOW64\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e110000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e120000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multimedia Realtime Runtime</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e2a0000</BaseAddress>
<Size>4440064</Size>
<Path>C:\Windows\SysWOW64\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb60000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb70000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ec40000</BaseAddress>
<Size>442368</Size>
<Path>C:\Windows\SysWOW64\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd00000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd20000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe40000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe50000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SysWOW64\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ff90000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\SysWOW64\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ffe0000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\SysWOW64\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70190000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x701a0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\dllyupdate.dll</Path>
<Version>1.2.0.1831</Version>
<Company>Yandex LLC</Company>
<Description>Yandex updater (CU)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b30000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\WINUSB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows USB Driver User Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b60000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x711f0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>58</ProcessIndex>
<ProcessId>5696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081114193232</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe --type=crashpad-handler &quot;--user-data-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler &quot;--database=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data\Crashpad&quot; &quot;--metrics-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; --url=https://crash-reports.browser.yandex.net/submit --annotation=machine_id=c46245ef0fec9d5c44d2fa20241f2070 --annotation=main_process_pid=7744 --annotation=metrics_client_id=520f4dd3247d4cdfb744f32b1130b1bf --annotation=plat=Win32 --annotation=prod=Yandex --annotation=ver=18.6.1.770 --initial-client-data=0x1c4,0x1cc,0x1d0,0x1c0,0x1d4,0x700b800c,0x700b7ffc,0x700b7fe0,0x1c8</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>59</ProcessIndex>
<ProcessId>4664</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081123844756</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=gpu-process --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --service-request-channel-token=CC1AC8FA9C8EFF1EEBC2375FE4F704C6 --mojo-platform-channel-handle=1588 --ignored=&quot; --type=renderer &quot; /prefetch:2</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ecb0000</BaseAddress>
<Size>2228224</Size>
<Path>C:\Windows\SysWOW64\mfh264enc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation H264 Encoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f250000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\SysWOW64\ddraw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectDraw</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f340000</BaseAddress>
<Size>3784704</Size>
<Path>C:\Windows\SysWOW64\D3DCompiler_47.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D HLSL Compiler</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f6e0000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\SysWOW64\msvproc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Video Processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fbe0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\mf.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff20000</BaseAddress>
<Size>118784</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\swiftshader\libegl.dll</Path>
<Version>4.0.0.3</Version>
<Company></Company>
<Description>SwiftShader libEGL 32-bit Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dxva2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Video Acceleration 2.0 DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x705d0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\DCIMAN32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DCI Manager</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>60</ProcessIndex>
<ProcessId>8968</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081206363215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=183F52B8A6577BFD721F95F3A9641348 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=183F52B8A6577BFD721F95F3A9641348 --renderer-client-id=4 --mojo-platform-channel-handle=2640 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>61</ProcessIndex>
<ProcessId>4992</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081244357280</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=7E8A8199C364F4B0114F2A163B757250 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E8A8199C364F4B0114F2A163B757250 --renderer-client-id=10 --mojo-platform-channel-handle=3904 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>63</ProcessIndex>
<ProcessId>9504</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956266598229</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgent.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgent.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgent.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>InstallAgent</Description>
<modulelist>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ff63d380000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\InstallAgent.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffabea60000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\VEStoreEventHandlers.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDL Store Event Handlers</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4ad0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\EAMProgressHandler.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>EAMProgressHandler</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>64</ProcessIndex>
<ProcessId>8768</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956321853179</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgentUserBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgentUserBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgentUserBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>InstallAgentUserBroker</Description>
<modulelist>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x22530450000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ff74f890000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\InstallAgentUserBroker.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgentUserBroker</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>65</ProcessIndex>
<ProcessId>9636</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956424585250</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettingsBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\SystemSettingsBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\SystemSettingsBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>System Settings Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ff6015f0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\SystemSettingsBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Broker</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>66</ProcessIndex>
<ProcessId>10592</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956519902643</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettings.exe</ProcessName>
<ImagePath>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</ImagePath>
<CommandLine>&quot;C:\Windows\ImmersiveControlPanel\SystemSettings.exe&quot; -ServerName:microsoft.windows.immersivecontrolpanel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Параметры</Description>
<modulelist>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x18099ef0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\WMI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI DC and DP functionality</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ff7937a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaabce0000</BaseAddress>
<Size>2535424</Size>
<Path>C:\Windows\System32\NetworkMobileSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System settings network mobile handlers group</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac220000</BaseAddress>
<Size>4952064</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Application</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaadd90000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\NetworkDesktopSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Группа обработчиков системных параметров сетевого рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaaf920000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettingsViewModel.Desktop.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings View Model Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0970000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\credprovhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост инфраструктуры поставщика учетных данных</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0a70000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\System32\fhcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигураций истории файлов</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\SYSTEM32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\SYSTEM32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab91d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\ImmersiveControlPanel\Telemetry.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Telemetry Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcc60000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\System32\MiracastReceiver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API приемника Miracast</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2bf0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\EFSUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>EFS Utility Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\SYSTEM32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\wmiclnt.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca560000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\NcaApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Network Connectivity Assistant API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>67</ProcessIndex>
<ProcessId>10964</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794956837373387</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{BA126F01-2166-11D1-B1D0-00805FC1270E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\system32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>76</ProcessIndex>
<ProcessId>11496</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958406617238</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SearchUI.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe&quot; -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>Search and Cortana application</Description>
<modulelist>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ff79c3c0000</BaseAddress>
<Size>10706944</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Search and Cortana application</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\SYSTEM32\chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\SYSTEM32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4c70000</BaseAddress>
<Size>4874240</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab52c0000</BaseAddress>
<Size>2445312</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5840000</BaseAddress>
<Size>3108864</Size>
<Path>C:\Windows\System32\Speech_OneCore\Common\sapi_onecore.dll</Path>
<Version>5.3.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Speech API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5db0000</BaseAddress>
<Size>9781248</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9d50000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;CortanaApi.ProxyStub.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe770000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabefa0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\Cortana.Persona.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana.Persona</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac10b0000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\PersonaX.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PersonaX</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\SYSTEM32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3bf0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionMgr.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana Action Manager</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bb0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\windows.cortana.pal.desktop.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.PAL.Desktop</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7c50000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\BingConfigurationClient.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bing Configuration Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\SYSTEM32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780654647361</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>79</ProcessIndex>
<ProcessId>5612</ProcessId>
<ParentProcessId>904</ParentProcessId>
<ParentProcessIndex>22</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131794965205293998</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>dashost.exe</ProcessName>
<ImagePath>C:\Windows\system32\dashost.exe</ImagePath>
<CommandLine>dashost.exe {609e1ffd-7b4d-4dbc-a36f725917d81f2d}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Device Association Framework Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ff6559c0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\dashost.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Framework Provider Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabb1a0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\DAFWSD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF WSD Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabc970000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\dafupnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF UPnP Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>80</ProcessIndex>
<ProcessId>9720</ProcessId>
<ParentProcessId>9180</ParentProcessId>
<ParentProcessIndex>81</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794969418818027</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Windows10UpgraderApp.exe</ProcessName>
<ImagePath>C:\Windows10Upgrade\Windows10UpgraderApp.exe</ImagePath>
<CommandLine>&quot;C:\Windows10Upgrade\Windows10UpgraderApp.exe&quot;  /Install /ClientID Win10Upgrade:VNL:NHV18:{} /SkipEULA /PostEosUi</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>1.4.9200.22452</Version>
<Description>Помощник по обновлению Windows 10</Description>
<modulelist>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0xb30000</BaseAddress>
<Size>1875968</Size>
<Path>C:\Windows10Upgrade\Windows10UpgraderApp.exe</Path>
<Version>1.4.9200.22452</Version>
<Company>Microsoft Corporation</Company>
<Description>Помощник по обновлению Windows 10</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d6e0000</BaseAddress>
<Size>634880</Size>
<Path>C:\Windows\SysWOW64\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d780000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\SysWOW64\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d860000</BaseAddress>
<Size>1245184</Size>
<Path>C:\Windows\SysWOW64\MFC42u.dll</Path>
<Version>6.06.8063.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека MFCDLL - розничная версия</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6ded0000</BaseAddress>
<Size>630784</Size>
<Path>C:\Windows\SysWOW64\ODBC32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ODBC Driver Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfc0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfd0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SysWOW64\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e010000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows10Upgrade\Downloader.dll</Path>
<Version>1.4.9200.22452 (win8_ldr.180426-0600)</Version>
<Company>Microsoft Corporation</Company>
<Description>Downloader</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e050000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.DLL</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>82</ProcessIndex>
<ProcessId>8944</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795005508439638</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>fontdrvhost.exe</ProcessName>
<ImagePath>C:\Windows\system32\fontdrvhost.exe</ImagePath>
<CommandLine>&quot;fontdrvhost.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Usermode Font Driver Host</Description>
<modulelist>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ff654db0000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\system32\fontdrvhost.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Usermode Font Driver Host</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>83</ProcessIndex>
<ProcessId>6684</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795006053748558</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Microsoft.Photos.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe&quot; -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ff705e40000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bb10000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bc70000</BaseAddress>
<Size>3158016</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bf80000</BaseAddress>
<Size>2994176</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9c260000</BaseAddress>
<Size>20144128</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9d5a0000</BaseAddress>
<Size>29011968</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9fb20000</BaseAddress>
<Size>7950336</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.3_1.3.24201.0_x64__8wekyb3d8bbwe\SharedLibrary.dll</Path>
<Version></Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Shared Framework</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa03f0000</BaseAddress>
<Size>4546560</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\FaceSdkStoreWrapper.dll</Path>
<Version>16.425.0.0</Version>
<Company>Microsoft Corporation</Company>
<Description>FaceSdkStoreWrapper</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa0850000</BaseAddress>
<Size>2371584</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\MediaEngine.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab270000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\System32\Windows.AccountsControl.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Accounts Control</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\Windows.System.Diagnostics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Diagnostics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f60000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\CryptoWinRT.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto WinRT Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9270000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9b40000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x64__8wekyb3d8bbwe\mrt100_app.dll</Path>
<Version>1.4.24201.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabea30000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\Windows.Energy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Energy Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0fa0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1c70000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCOMP140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C/C++ OpenMP Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2c00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\clrcompression.dll</Path>
<Version>1.0.23123.00 built by: PROJECTKREL</Version>
<Company>Microsoft Corporation</Company>
<Description>ClrCompression</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SYSTEM32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\mrt100.dll</Path>
<Version>1.0.24120.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OleAut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>84</ProcessIndex>
<ProcessId>6208</ProcessId>
<ParentProcessId>12140</ParentProcessId>
<ParentProcessIndex>85</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795181740423780</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>OneDrive.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</ImagePath>
<CommandLine> /updateInstalled /background</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>18.131.0701.0007</Version>
<Description>Microsoft OneDrive</Description>
<modulelist>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x11f0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x55a0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSync.Resources.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\MSHTML.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6bab0000</BaseAddress>
<Size>4472832</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Widgets.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d210000</BaseAddress>
<Size>4993024</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Gui.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\Wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ce0000</BaseAddress>
<Size>1519616</Size>
<Path>C:\Windows\SysWOW64\wpc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека параметров родительского контроля</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70f00000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71200000</BaseAddress>
<Size>708608</Size>
<Path>C:\Windows\SysWOW64\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x712b0000</BaseAddress>
<Size>602112</Size>
<Path>C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71350000</BaseAddress>
<Size>2867200</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Quick.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71630000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x716b0000</BaseAddress>
<Size>1294336</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LIBEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x717f0000</BaseAddress>
<Size>2637824</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Qml.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71a80000</BaseAddress>
<Size>4796416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Core.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71f20000</BaseAddress>
<Size>6033408</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SyncEngine.DLL</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Sync Engine</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72530000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72550000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72810000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72820000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SysWOW64\MicrosoftAccountTokenProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Token Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72850000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\SysWOW64\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728b0000</BaseAddress>
<Size>135168</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncFAL.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDriveFile Sync FAL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\SysWOW64\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72bb0000</BaseAddress>
<Size>1105920</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\platforms\qwindows.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e90000</BaseAddress>
<Size>299008</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SSLEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ee0000</BaseAddress>
<Size>950272</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Network.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72fd0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\loadperf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Загрузка и выгрузка счетчиков производительности</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ff0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\pdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль поддержки данных производительности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73040000</BaseAddress>
<Size>253952</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5WinExtras.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73080000</BaseAddress>
<Size>880640</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ADAL.dll</Path>
<Version>1.0.2110.0526</Version>
<Company>Microsoft</Company>
<Description>ADAL.Native</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73160000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WSOCK32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73170000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SysWOW64\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x731d0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\WnsClientApi.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive WNS Client Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73240000</BaseAddress>
<Size>520192</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LogUploader.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive Sync LogUploader Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x732c0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncViews.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Qt Components</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73400000</BaseAddress>
<Size>159744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\UpdateRingSettings.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Ring Settings</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73430000</BaseAddress>
<Size>1748992</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncSessions.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>P2P Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x735e0000</BaseAddress>
<Size>671744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\RemoteAccess.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73690000</BaseAddress>
<Size>188416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Telemetry.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Telemetry Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ETWLog.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>ETW Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736d0000</BaseAddress>
<Size>3600384</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncClient.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Client</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73af0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LoggingPlatform.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Logging Platform</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73dc0000</BaseAddress>
<Size>1171456</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ucrtbase.dll</Path>
<Version>10.0.17134.12 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73fb0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\MSWSOCK.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74090000</BaseAddress>
<Size>462848</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\MSVCP140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\VCRUNTIME140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74220000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>86</ProcessIndex>
<ProcessId>6140</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795747339404666</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=764E64A4EA650A23B18EB059FF0B4B51 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=764E64A4EA650A23B18EB059FF0B4B51 --renderer-client-id=106 --mojo-platform-channel-handle=6612 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>87</ProcessIndex>
<ProcessId>11432</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755605761168</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=9DD318D38190D474A9A0F5AFD262A449 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=9DD318D38190D474A9A0F5AFD262A449 --renderer-client-id=109 --mojo-platform-channel-handle=4152 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>88</ProcessIndex>
<ProcessId>10384</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755746873891</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=7E669976FFDCEE94D9B90B02CADE1179 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E669976FFDCEE94D9B90B02CADE1179 --renderer-client-id=112 --mojo-platform-channel-handle=5412 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>90</ProcessIndex>
<ProcessId>6936</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795756360200321</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --renderer-client-id=116 --mojo-platform-channel-handle=4024 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>98</ProcessIndex>
<ProcessId>6080</ProcessId>
<ParentProcessId>84</ParentProcessId>
<ParentProcessIndex>97</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795771125310655</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MCLauncher.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe&quot; </CommandLine>
<CompanyName></CompanyName>
<Version>1.0</Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795771127806606</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>2830336</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Version>1.0</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771129292604</Timestamp>
<BaseAddress>0x750000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771335510731</Timestamp>
<BaseAddress>0x11000000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771334241016</Timestamp>
<BaseAddress>0x12000000</BaseAddress>
<Size>360448</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771129285523</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795771129286235</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795771129295328</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795771135408057</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795771129575672</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129398434</Timestamp>
<BaseAddress>0x66680000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771136825814</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795771129423112</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771129349562</Timestamp>
<BaseAddress>0x6b830000</BaseAddress>
<Size>2584576</Size>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795771329638947</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795771329610149</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795771329592759</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795771136045859</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795771131298623</Timestamp>
<BaseAddress>0x6d180000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795771136082794</Timestamp>
<BaseAddress>0x6dca0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Script Runtime</Description>
</module>
<module>
<Timestamp>131795771133718253</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795771129406131</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795771329618480</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795771329601483</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795771336447829</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771135435621</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795771135446667</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771136073867</Timestamp>
<BaseAddress>0x70e90000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Script Host Runtime Library</Description>
</module>
<module>
<Timestamp>131795771135423397</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795771135552456</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795771136181434</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771328759427</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771135541570</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795771347140137</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795771347110306</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795771135314174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771347090516</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795771347075776</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795771328179609</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795771130913562</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795771135359123</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795771129415027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795771130899582</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795771133098293</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795771132990161</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795771131765102</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795771129389543</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795771129317462</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795771129360685</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795771129360034</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771129496759</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795771129358136</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129357408</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795771129365891</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795771129359203</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795771129353720</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771135412052</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795771129350362</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795771129366695</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795771136054082</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795771131750596</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795771129363162</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795771328737550</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795771135228888</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795771129301509</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771129362062</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795771135227735</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795771129363985</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795771129356607</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795771129364960</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795771129354665</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795771129370252</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795771129352041</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795771129367584</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795771129351257</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771129361361</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795771129369244</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129368545</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795771131168008</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795771129352931</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771133704572</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795771129355632</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795771347076821</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795771127807387</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795771127807116</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>104</ProcessIndex>
<ProcessId>12696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777567759490</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=E83DB721798C8A70C76CD26F6F4EE1BC --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=E83DB721798C8A70C76CD26F6F4EE1BC --renderer-client-id=119 --mojo-platform-channel-handle=7052 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777567991690</Timestamp>
<BaseAddress>0xc00000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777567961139</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777569452751</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777567980184</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777567981270</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777567994943</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777570994535</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777570968696</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777570908362</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777570920904</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777570943637</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777570874151</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777570891841</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777568100773</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777570569484</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777570619251</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777570607590</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777570676211</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777570557202</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777570691164</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777570539079</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777569494420</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777570658737</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777569526517</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777569154123</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777570594964</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777570630821</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777570523174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777570582120</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777570646486</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777570953652</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777569213807</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777568156054</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777569481011</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777568142933</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777568179155</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777568043561</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777568042430</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777569239058</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777568075566</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777568073430</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777568086784</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777568041126</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777568081914</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777568046844</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777568038347</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777568088134</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777569468247</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777569466798</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777568077279</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777569469408</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777568024100</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777568039823</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777569470854</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777568036731</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777568054568</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777568078714</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777568050811</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777568084892</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777568089486</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777568083413</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777568044758</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777569464930</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777569463567</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777568116745</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777568080182</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777569457550</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777568052363</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777570632192</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777567961904</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777567961630</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>106</ProcessIndex>
<ProcessId>5556</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777595302537</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=3ADFA2396247AD5E547F61590603D06D --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=3ADFA2396247AD5E547F61590603D06D --renderer-client-id=121 --mojo-platform-channel-handle=6636 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777595490187</Timestamp>
<BaseAddress>0x1020000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595475498</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595491301</Timestamp>
<BaseAddress>0x5550000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777596381097</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595481485</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777595482474</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777595494304</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777597543015</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777597521210</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777597472595</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777597484525</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777597497517</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777597428793</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777597448444</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777595565558</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777597103476</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777597165296</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777597153510</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777597221087</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777597072535</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777597233493</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777597059294</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777596424202</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777597205195</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777596436120</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777596128973</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777597128037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777597177209</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777597044137</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777597116160</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777597192860</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777597506812</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777596148547</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777595627397</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777596410831</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777595610560</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777595638942</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777595529014</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777595527983</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777596182171</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777595541526</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777595540326</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777595551866</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777595526606</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777595547732</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777595531563</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777595524005</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777595553384</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777596396507</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777596394953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777595543299</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777596397607</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777595508927</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595525398</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777596398892</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777595522182</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777595538927</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777595544568</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777595535397</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777595550455</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777595554628</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777595549128</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777595530150</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777596393437</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777596392132</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777595583766</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777595545878</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777596385979</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777595536930</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777597178434</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777595476066</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777595475814</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>111</ProcessIndex>
<ProcessId>9032</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777895284069</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>explorer.exe</ProcessName>
<ImagePath>C:\Windows\explorer.exe</ImagePath>
<CommandLine>C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795777911330291</Timestamp>
<BaseAddress>0x4d80000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795777920515787</Timestamp>
<BaseAddress>0x6530000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\Microsoft Office\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795777903881315</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795777903867506</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795777895813346</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\explorer.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795777906005639</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\duser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795777922060868</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795777918507242</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795777907532495</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\System32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795777910997447</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795777915260331</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795777910978745</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\System32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795778008622616</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795778007235790</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\devrtl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795777909146457</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795777902950088</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\System32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795778007048279</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795777902932644</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795777909802797</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777909791020</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777917395017</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\linkinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795777918158137</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795777966565943</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795777908125051</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795777905900322</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\dui70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795777908270107</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795777922014669</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\System32\networkexplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795778007216762</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795777919764442</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795777915281766</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795777909775471</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795777910387599</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795777905243222</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795777919412503</Timestamp>
<BaseAddress>0x7ffac1710000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\amd64\FileSyncShell64.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795777904716802</Timestamp>
<BaseAddress>0x7ffac18b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg64.dll</Path>
<Version>1, 0, 0, 1140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795777944562485</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795777903915791</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777922001525</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795777903903305</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777909321798</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777909330655</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777906462233</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795777910949757</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795777920555307</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795777906356495</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795777905097743</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\System32\ExplorerFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795777908567233</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795777911007559</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795777914831974</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795777905390625</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777902894862</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795777906986296</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795777906995835</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795777903975733</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795777906257948</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795777919424461</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795777902880674</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777908138610</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795777902921260</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778008641775</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795777907005063</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795777918659102</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777918649579</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777909306748</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795777902905939</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795777906474194</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902941219</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795778008632518</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795777918171528</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795777907014508</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777903933947</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777902985171</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777903008375</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777902974089</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777905657867</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795777902999880</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777902852334</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777902849489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777902853126</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777902855116</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777902843222</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777902836309</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902838974</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777902841617</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777902844144</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777902848566</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777902824318</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777902854301</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777902835470</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902847555</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777902846521</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777902834719</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777916996283</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795777902838016</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777902833378</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777904879129</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777902823359</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777905449820</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795777920556415</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795777902842396</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777903888252</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777903413262</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777902840664</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777902837229</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777903887407</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795777902850328</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777903886124</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777902845086</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777902851375</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777895813598</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>144</ProcessIndex>
<ProcessId>12892</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780695167004</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Wireshark.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\Wireshark.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\Wireshark.exe&quot; </CommandLine>
<CompanyName>The Wireshark developer community, http://www.wireshark.org/</CompanyName>
<Version>2.6.2</Version>
<Description>Wireshark</Description>
<modulelist>
<module>
<Timestamp>131795780706141890</Timestamp>
<BaseAddress>0xbd0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\libwinpthread-1.dll</Path>
<Version>1, 0, 0, 0</Version>
<Company>MingW-W64 Project. All rights reserved.</Company>
<Description>POSIX WinThreads for Windows</Description>
</module>
<module>
<Timestamp>131795780721765742</Timestamp>
<BaseAddress>0xbf0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\k5sprt64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>Kerberos v5 support - internal support code for MIT Kerberos v5 /GSS distribution</Description>
</module>
<module>
<Timestamp>131795780722106261</Timestamp>
<BaseAddress>0xc00000</BaseAddress>
<Size>45056</Size>
<Path>C:\Program Files\Wireshark\comerr64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>COM_ERR - Common Error Handler for MIT Kerberos v5 / GSS distribution</Description>
</module>
<module>
<Timestamp>131795780719731475</Timestamp>
<BaseAddress>0x1c000000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\krb5_64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>Kerberos v5 - MIT GSS / Kerberos v5 distribution</Description>
</module>
<module>
<Timestamp>131795780773060331</Timestamp>
<BaseAddress>0x5af30000</BaseAddress>
<Size>348160</Size>
<Path>C:\Program Files\Wireshark\Qt5Svg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780721210805</Timestamp>
<BaseAddress>0x5af90000</BaseAddress>
<Size>1286144</Size>
<Path>C:\Program Files\Wireshark\libxml2-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780696840198</Timestamp>
<BaseAddress>0x5b0d0000</BaseAddress>
<Size>5865472</Size>
<Path>C:\Program Files\Wireshark\Qt5Core.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780696801039</Timestamp>
<BaseAddress>0x5b670000</BaseAddress>
<Size>5619712</Size>
<Path>C:\Program Files\Wireshark\Qt5Widgets.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780721068755</Timestamp>
<BaseAddress>0x5bcf0000</BaseAddress>
<Size>733184</Size>
<Path>C:\Program Files\Wireshark\libsmi-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720701584</Timestamp>
<BaseAddress>0x5bdb0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Program Files\Wireshark\liblz4.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720048995</Timestamp>
<BaseAddress>0x5bdf0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Program Files\Wireshark\libcares-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780701085625</Timestamp>
<BaseAddress>0x5be10000</BaseAddress>
<Size>122880</Size>
<Path>C:\Program Files\Wireshark\libbcg729.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700086118</Timestamp>
<BaseAddress>0x5be30000</BaseAddress>
<Size>1261568</Size>
<Path>C:\Program Files\Wireshark\Qt5Network.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780701499544</Timestamp>
<BaseAddress>0x61cc0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Wireshark\libintl-8.dll</Path>
<Version>0.18.1</Version>
<Company>Free Software Foundation</Company>
<Description>LGPLed libintl for Windows NT/2000/XP/Vista/7 and Windows 95/98/ME</Description>
</module>
<module>
<Timestamp>131795780704834900</Timestamp>
<BaseAddress>0x646c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libgpg-error6-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780703191110</Timestamp>
<BaseAddress>0x64840000</BaseAddress>
<Size>1220608</Size>
<Path>C:\Program Files\Wireshark\libgnutls-30.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720700188</Timestamp>
<BaseAddress>0x64a00000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\lua52.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780702785552</Timestamp>
<BaseAddress>0x653c0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\libgcrypt-20.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780706408972</Timestamp>
<BaseAddress>0x65f00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Program Files\Wireshark\libtasn1-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705520711</Timestamp>
<BaseAddress>0x66f00000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Wireshark\libhogweed-4-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780696518462</Timestamp>
<BaseAddress>0x685c0000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Program Files\Wireshark\libglib-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GLib</Description>
</module>
<module>
<Timestamp>131795780706610973</Timestamp>
<BaseAddress>0x68ec0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\Wireshark\libp11-kit-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720967901</Timestamp>
<BaseAddress>0x69340000</BaseAddress>
<Size>815104</Size>
<Path>C:\Program Files\Wireshark\libsnappy-1.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705423287</Timestamp>
<BaseAddress>0x69c80000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\libnettle-6-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700701891</Timestamp>
<BaseAddress>0x6a680000</BaseAddress>
<Size>122880</Size>
<Path>C:\Program Files\Wireshark\libsbc-1.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705248323</Timestamp>
<BaseAddress>0x6acc0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files\Wireshark\libgmp-10.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780707311684</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\libffi-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700957949</Timestamp>
<BaseAddress>0x6d7c0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files\Wireshark\libspandsp-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720746780</Timestamp>
<BaseAddress>0x6dc80000</BaseAddress>
<Size>167936</Size>
<Path>C:\Program Files\Wireshark\libnghttp2-14.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780698864675</Timestamp>
<BaseAddress>0x6dd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\Wireshark\libgmodule-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GModule</Description>
</module>
<module>
<Timestamp>131795780759720376</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\wpcap.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008)</Description>
</module>
<module>
<Timestamp>131795780760417804</Timestamp>
<BaseAddress>0x190ac770000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795780695991379</Timestamp>
<BaseAddress>0x7ff7f1130000</BaseAddress>
<Size>8298496</Size>
<Path>C:\Program Files\Wireshark\Wireshark.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark</Description>
</module>
<module>
<Timestamp>131795780718751145</Timestamp>
<BaseAddress>0x7ffaa6f50000</BaseAddress>
<Size>64282624</Size>
<Path>C:\Program Files\Wireshark\libwireshark.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark dissector library</Description>
</module>
<module>
<Timestamp>131795780697272337</Timestamp>
<BaseAddress>0x7ffaaaca0000</BaseAddress>
<Size>6094848</Size>
<Path>C:\Program Files\Wireshark\Qt5Gui.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896758694</Timestamp>
<BaseAddress>0x7ffab1e90000</BaseAddress>
<Size>593920</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimax.dll</Path>
<Version>1.2.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimax dissector</Description>
</module>
<module>
<Timestamp>131795780766458881</Timestamp>
<BaseAddress>0x7ffab1f30000</BaseAddress>
<Size>614400</Size>
<Path>C:\Windows\System32\riched20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795780699399720</Timestamp>
<BaseAddress>0x7ffab2280000</BaseAddress>
<Size>1916928</Size>
<Path>C:\Program Files\Wireshark\WinSparkle.dll</Path>
<Version>0.5.7</Version>
<Company>winsparkle.org</Company>
<Description>WinSparkle updater</Description>
</module>
<module>
<Timestamp>131795780771263589</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795780765326722</Timestamp>
<BaseAddress>0x7ffab9010000</BaseAddress>
<Size>1388544</Size>
<Path>C:\Program Files\Wireshark\platforms\qwindows.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896746168</Timestamp>
<BaseAddress>0x7ffab9b10000</BaseAddress>
<Size>135168</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\unistim.dll</Path>
<Version>0.0.2.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>unistim dissector</Description>
</module>
<module>
<Timestamp>131795780896708383</Timestamp>
<BaseAddress>0x7ffabaef0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\profinet.dll</Path>
<Version>0.2.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>profinet dissector</Description>
</module>
<module>
<Timestamp>131795780773615377</Timestamp>
<BaseAddress>0x7ffabb070000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files\Wireshark\imageformats\qwebp.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780702318544</Timestamp>
<BaseAddress>0x7ffabb0f0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780773096445</Timestamp>
<BaseAddress>0x7ffabb250000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files\Wireshark\imageformats\qtiff.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896696149</Timestamp>
<BaseAddress>0x7ffabc110000</BaseAddress>
<Size>237568</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\opcua.dll</Path>
<Version>1.0.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>opcua dissector</Description>
</module>
<module>
<Timestamp>131795780696290907</Timestamp>
<BaseAddress>0x7ffabc150000</BaseAddress>
<Size>729088</Size>
<Path>C:\Program Files\Wireshark\Qt5Multimedia.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780699299849</Timestamp>
<BaseAddress>0x7ffabcbb0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Program Files\Wireshark\libwiretap.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark capture file library</Description>
</module>
<module>
<Timestamp>131795780702235327</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795780699512168</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795780773039075</Timestamp>
<BaseAddress>0x7ffabe940000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\imageformats\qjpeg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896684027</Timestamp>
<BaseAddress>0x7ffabeb80000</BaseAddress>
<Size>163840</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\mate.dll</Path>
<Version>1.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>mate dissector</Description>
</module>
<module>
<Timestamp>131795780767100288</Timestamp>
<BaseAddress>0x7ffabebb0000</BaseAddress>
<Size>233472</Size>
<Path>C:\Windows\System32\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795780967804060</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795780703722010</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780896660120</Timestamp>
<BaseAddress>0x7ffabf990000</BaseAddress>
<Size>135168</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\gryphon.dll</Path>
<Version>0.0.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>gryphon dissector</Description>
</module>
<module>
<Timestamp>131795781117544658</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\NapiNSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795781117680972</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795780896781202</Timestamp>
<BaseAddress>0x7ffabff40000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimaxmacphy.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimaxmacphy dissector</Description>
</module>
<module>
<Timestamp>131795780975772674</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795781117813782</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795780967709675</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780896602379</Timestamp>
<BaseAddress>0x7ffac0b10000</BaseAddress>
<Size>180224</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\ethercat.dll</Path>
<Version>0.1.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>ethercat dissector</Description>
</module>
<module>
<Timestamp>131795780696305369</Timestamp>
<BaseAddress>0x7ffac12f0000</BaseAddress>
<Size>585728</Size>
<Path>C:\Program Files\Wireshark\Qt5WinExtras.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780696268510</Timestamp>
<BaseAddress>0x7ffac1380000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files\Wireshark\Qt5PrintSupport.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896769846</Timestamp>
<BaseAddress>0x7ffac1640000</BaseAddress>
<Size>81920</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimaxasncp.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimaxasncp dissector</Description>
</module>
<module>
<Timestamp>131795780703633136</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\zlib1.dll</Path>
<Version>1.2.11</Version>
<Company></Company>
<Description>zlib data compression library</Description>
</module>
<module>
<Timestamp>131795780968289847</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795780896672499</Timestamp>
<BaseAddress>0x7ffac21f0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\irda.dll</Path>
<Version>0.0.6.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>irda dissector</Description>
</module>
<module>
<Timestamp>131795780943468609</Timestamp>
<BaseAddress>0x7ffac2950000</BaseAddress>
<Size>32768</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\codecs\l16mono.dll</Path>
<Version>0.1.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>l16mono dissector</Description>
</module>
<module>
<Timestamp>131795780696778265</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780698025500</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libwsutil.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark utility library</Description>
</module>
<module>
<Timestamp>131795780964290332</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780896734845</Timestamp>
<BaseAddress>0x7ffac3730000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\transum.dll</Path>
<Version>2.0.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>transum dissector</Description>
</module>
<module>
<Timestamp>131795780962958391</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780891504201</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795780896719593</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\stats_tree.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>stats_tree dissector</Description>
</module>
<module>
<Timestamp>131795780893701095</Timestamp>
<BaseAddress>0x7ffac4c50000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\wiretap\usbdump.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>usbdump dissector</Description>
</module>
<module>
<Timestamp>131795780891269455</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795780965552062</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795780963571749</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795780963646684</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795780773109195</Timestamp>
<BaseAddress>0x7ffac6aa0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qwbmp.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773083338</Timestamp>
<BaseAddress>0x7ffac6ab0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qtga.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780700311672</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780700270884</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780773051219</Timestamp>
<BaseAddress>0x7ffac7710000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qsvg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773027062</Timestamp>
<BaseAddress>0x7ffac7c70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\imageformats\qico.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773014999</Timestamp>
<BaseAddress>0x7ffac7cc0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files\Wireshark\imageformats\qicns.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773002354</Timestamp>
<BaseAddress>0x7ffac7e80000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\imageformats\qgif.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780968266724</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795780968255503</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795780966275544</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795780892525330</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795780963686201</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795780892534590</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795781117718740</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795780698877286</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wsock32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795780891204535</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795780696645603</Timestamp>
<BaseAddress>0x7ffaca540000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\libwscodecs.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark codecs library</Description>
</module>
<module>
<Timestamp>131795780700298298</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780892543743</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795780766486586</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795780704258643</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795780702045466</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795780946467813</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795780696789076</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780891516231</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795780892568770</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795780892552823</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795780966945740</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795780735395573</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795780967734879</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795780699490686</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780703368899</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795780963669913</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795780735383654</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780725077080</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780735352973</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780735341669</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780963187802</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780703358385</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780696324267</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780696320774</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780696326027</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780700094061</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780696281753</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780696314418</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780696011047</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780967736295</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795780696325096</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780696319762</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780696000095</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780700093105</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780700405929</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780696318427</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780719380090</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795780696316518</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780700405056</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780696313332</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780703813608</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795780696317482</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780891250440</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780695999112</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780892432004</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795780696011842</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780696829366</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780722304611</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780696010125</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780696013618</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795780696312465</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780696321680</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780696311589</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780696323259</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780696315318</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780695991736</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>154</ProcessIndex>
<ProcessId>10368</ProcessId>
<ParentProcessId>12892</ParentProcessId>
<ParentProcessIndex>144</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795781110701520</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>dumpcap.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\dumpcap.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\dumpcap.exe&quot; -n -i \Device\NPF_{8742EB38-E176-4D94-AB83-DB4440CD90E6} -y EN10MB -Z 12892</CommandLine>
<CompanyName>The Wireshark developer community</CompanyName>
<Version>2.6.2</Version>
<Description>Dumpcap</Description>
<modulelist>
<module>
<Timestamp>131795781112729961</Timestamp>
<BaseAddress>0xe30000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\libwinpthread-1.dll</Path>
<Version>1, 0, 0, 0</Version>
<Company>MingW-W64 Project. All rights reserved.</Company>
<Description>POSIX WinThreads for Windows</Description>
</module>
<module>
<Timestamp>131795781112668516</Timestamp>
<BaseAddress>0x61cc0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Wireshark\libintl-8.dll</Path>
<Version>0.18.1</Version>
<Company>Free Software Foundation</Company>
<Description>LGPLed libintl for Windows NT/2000/XP/Vista/7 and Windows 95/98/ME</Description>
</module>
<module>
<Timestamp>131795781112689838</Timestamp>
<BaseAddress>0x646c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libgpg-error6-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112636826</Timestamp>
<BaseAddress>0x64840000</BaseAddress>
<Size>1220608</Size>
<Path>C:\Program Files\Wireshark\libgnutls-30.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112629190</Timestamp>
<BaseAddress>0x653c0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\libgcrypt-20.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112737406</Timestamp>
<BaseAddress>0x65f00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Program Files\Wireshark\libtasn1-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112705672</Timestamp>
<BaseAddress>0x66f00000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Wireshark\libhogweed-4-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112573973</Timestamp>
<BaseAddress>0x685c0000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Program Files\Wireshark\libglib-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GLib</Description>
</module>
<module>
<Timestamp>131795781112722622</Timestamp>
<BaseAddress>0x68ec0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\Wireshark\libp11-kit-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112715396</Timestamp>
<BaseAddress>0x69c80000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\libnettle-6-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112698255</Timestamp>
<BaseAddress>0x6acc0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files\Wireshark\libgmp-10.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112775160</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\libffi-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112582576</Timestamp>
<BaseAddress>0x6dd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\Wireshark\libgmodule-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GModule</Description>
</module>
<module>
<Timestamp>131795781112962306</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\wpcap.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008)</Description>
</module>
<module>
<Timestamp>131795781112975613</Timestamp>
<BaseAddress>0x2203d070000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795781110777700</Timestamp>
<BaseAddress>0x7ff79b530000</BaseAddress>
<Size>438272</Size>
<Path>C:\Program Files\Wireshark\dumpcap.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community</Company>
<Description>Dumpcap</Description>
</module>
<module>
<Timestamp>131795781112745027</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\zlib1.dll</Path>
<Version>1.2.11</Version>
<Company></Company>
<Description>zlib data compression library</Description>
</module>
<module>
<Timestamp>131795781112991873</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795781112551689</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libwsutil.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark utility library</Description>
</module>
<module>
<Timestamp>131795781112616429</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781113081556</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795781113068402</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795781112593287</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wsock32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795781112764136</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795781112680590</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795781112901553</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795781112603842</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795781112889933</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795781112922216</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795781112873689</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795781112851456</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795781112862535</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795781112564185</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795781112558680</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795781112565891</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795781112638400</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795781112561378</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781112543433</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781112557787</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795781112563121</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795781112564994</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795781112555945</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795781111306780</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781112637496</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795781112554892</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795781112553795</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795781112541505</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795781113056743</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795781112539956</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795781111305815</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781112560555</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781112552568</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795781112797169</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795781112562317</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795781112556862</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795781112538759</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795781112574716</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795781112559630</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795781112540782</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795781110778043</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>155</ProcessIndex>
<ProcessId>10656</ProcessId>
<ParentProcessId>10368</ParentProcessId>
<ParentProcessIndex>154</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795781111864203</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Conhost.exe</ProcessName>
<ImagePath>C:\Windows\System32\Conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795781111913743</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795781111943590</Timestamp>
<BaseAddress>0x7ffac16b0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795781112487631</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795781111973094</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795781112447250</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795781112288506</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795781112268292</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795781112265698</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795781112269042</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795781111955891</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781111952093</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781111953761</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795781111957462</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795781111974737</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795781112264787</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795781111919763</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781111959779</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781112263740</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795781112262565</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795781111959111</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795781111952833</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795781111927637</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795781111918688</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781112429009</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795781111954501</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781111958338</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795781111956778</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795781111951234</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795781112266518</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795781112267424</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795781111973936</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795781111913976</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>162</ProcessIndex>
<ProcessId>4760</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786042098193</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MicrosoftEdge.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe&quot; -ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Microsoft Edge</Description>
<modulelist>
<module>
<Timestamp>131795786042630177</Timestamp>
<BaseAddress>0x7ff782940000</BaseAddress>
<Size>7663616</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786057154585</Timestamp>
<BaseAddress>0x7ffaad380000</BaseAddress>
<Size>5730304</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\eView.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge View</Description>
</module>
<module>
<Timestamp>131795786054805787</Timestamp>
<BaseAddress>0x7ffaad900000</BaseAddress>
<Size>4730880</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\eModel.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Model</Description>
</module>
<module>
<Timestamp>131795786066907553</Timestamp>
<BaseAddress>0x7ffab0430000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\System32\ieapfltr.dll</Path>
<Version>11.00.14393.2189</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SmartScreen Filter</Description>
</module>
<module>
<Timestamp>131795786128228596</Timestamp>
<BaseAddress>0x7ffab1df0000</BaseAddress>
<Size>602112</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\eData.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Data Store API Module</Description>
</module>
<module>
<Timestamp>131795786065479748</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\System32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795786063895095</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795786054266392</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795786230757616</Timestamp>
<BaseAddress>0x7ffab8fd0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\MicrosoftAccountTokenProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Token Provider</Description>
</module>
<module>
<Timestamp>131795786063975264</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786144818989</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795786059649322</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795786067415829</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786288759665</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786288473868</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795786288676720</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795786065177710</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795786066322832</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795786072876141</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795786088399099</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795786065841979</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795786055069007</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786147341523</Timestamp>
<BaseAddress>0x7ffabd220000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\Windows.Devices.Enumeration.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Enumeration</Description>
</module>
<module>
<Timestamp>131795786063327247</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795786125346246</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795786068479711</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\System32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795786065629245</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795786100800557</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795786057138366</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795786088259759</Timestamp>
<BaseAddress>0x7ffabf090000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform Diagnostics and Usage Settings DLL</Description>
</module>
<module>
<Timestamp>131795786241271463</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786064506043</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786066155936</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795786063962359</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795786069984086</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795786241104861</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786059637885</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\System32\Windows.UI.Core.TextInput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795786053932620</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795786241083669</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786056074983</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786100125856</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786075280874</Timestamp>
<BaseAddress>0x7ffac15d0000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Core.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Model Core API</Description>
</module>
<module>
<Timestamp>131795786070406699</Timestamp>
<BaseAddress>0x7ffac1600000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\mdmregistration.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>MDM Registration DLL</Description>
</module>
<module>
<Timestamp>131795786062579941</Timestamp>
<BaseAddress>0x7ffac1940000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Windows.System.Profile.RetailInfo.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Profile.RetailInfo Runtime DLL</Description>
</module>
<module>
<Timestamp>131795786070419915</Timestamp>
<BaseAddress>0x7ffac1f10000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\dmcmnutils.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmcmnutils</Description>
</module>
<module>
<Timestamp>131795786068039488</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795786089075107</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786065677921</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795786065270981</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786128841302</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\esent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795786054294330</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786063368609</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786202359997</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795786200068117</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795786055042484</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\eShims.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Compatibility Shims</Description>
</module>
<module>
<Timestamp>131795786089712128</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795786059830786</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795786150797625</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\System32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795786453454285</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\System32\UIAutomationCore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795786067621067</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786092263039</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786147367807</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795786065223183</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786147382918</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795786065248448</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786055777229</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795786453657664</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795786057001398</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795786057773467</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795786060164250</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786068353332</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795786070260699</Timestamp>
<BaseAddress>0x7ffac79e0000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\System32\netjoin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL присоединения к домену</Description>
</module>
<module>
<Timestamp>131795786066493970</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795786056922456</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\System32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795786092912724</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786060129754</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795786065322940</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786056749751</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795786070245572</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786054670572</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786056291342</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\System32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795786068265491</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795786082912516</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795786063291141</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786054280400</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786056308035</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786054309397</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795786060143604</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795786053885709</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795786056099190</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786063385911</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786054634364</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786064476035</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795786056663398</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795786070433601</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\devobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795786054821679</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786064343854</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795786056649628</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795786240387843</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786241189729</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786241130378</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786065234326</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786070099854</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786070392550</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786055055520</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786065299260</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786067045090</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786061034021</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786070369175</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\joinutil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795786070463748</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786070448934</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786064523489</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786054651608</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786054249334</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786054809092</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786054683095</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786057003667</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795786053916113</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786053913423</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786053914306</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786053917903</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786241132060</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786054295713</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786054808089</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786053867639</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786057002708</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786053934160</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786054810350</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786072535568</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786053933393</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786070371970</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795786053910705</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786065324109</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786053908868</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786053866675</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786058760529</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795786053915276</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786065183195</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786053988560</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786053916977</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786053912669</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786053907976</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786053911866</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786054806876</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786053909990</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786042630465</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>163</ProcessIndex>
<ProcessId>11628</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786060723216</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser_broker.exe</ProcessName>
<ImagePath>C:\Windows\system32\browser_broker.exe</ImagePath>
<CommandLine>C:\Windows\system32\browser_broker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.1613 (rs1_release_d.170807-1806)</Version>
<Description>Browser_Broker</Description>
<modulelist>
<module>
<Timestamp>131795786060746750</Timestamp>
<BaseAddress>0x7ff7b0a20000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\browser_broker.exe</Path>
<Version>11.00.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>Browser_Broker</Description>
</module>
<module>
<Timestamp>131795786168836722</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786168862865</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786168827250</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\System32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786282574098</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786062630515</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786377997340</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786062639680</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786379114346</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786377416821</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786174396342</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786063237345</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786062620047</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786062594364</Timestamp>
<BaseAddress>0x7ffac37b0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\browserbroker.dll</Path>
<Version>11.00.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>BrowserBroker</Description>
</module>
<module>
<Timestamp>131795786062611592</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786373086635</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786062648299</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786374469208</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786169923245</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786169944900</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786375051635</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786170132533</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786168854180</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786372529204</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786060981181</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786373096703</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786062656563</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786376235194</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786377463635</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786062672588</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786169932479</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786372992934</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786282563295</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786170115721</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786168845591</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786377475058</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786377435415</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786377426421</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786065020552</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786168896935</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786060963845</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786065028759</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786065029803</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786062602748</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795786060771823</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786060765038</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786060766797</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786060769366</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786377447217</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786062597872</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786065027623</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786060754491</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786062601823</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786062599820</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786174124589</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786174123329</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786062599041</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786060765825</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786170133242</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786060762708</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786062743817</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786060753543</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786060770964</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786169882199</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786060799279</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786060768413</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786060764068</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786062600875</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786063238473</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786062621206</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786060767532</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786060746988</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>164</ProcessIndex>
<ProcessId>9260</ProcessId>
<ParentProcessId>3632</ParentProcessId>
<ParentProcessIndex>38</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786076559956</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>microsoftedgecp.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe&quot; SCODEF:4760 CREDAT:140545 /prefetch:2</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Microsoft Edge Content Process</Description>
<modulelist>
<module>
<Timestamp>131795786082343149</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786082139934</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786076857473</Timestamp>
<BaseAddress>0x7ff6405a0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content Process</Description>
</module>
<module>
<Timestamp>131795786340825586</Timestamp>
<BaseAddress>0x7ffaa65e0000</BaseAddress>
<Size>4526080</Size>
<Path>C:\Windows\System32\D3DCompiler_47.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D HLSL Compiler</Description>
</module>
<module>
<Timestamp>131795786083247759</Timestamp>
<BaseAddress>0x7ffaafb30000</BaseAddress>
<Size>3379200</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\EdgeContent.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content</Description>
</module>
<module>
<Timestamp>131795786086088180</Timestamp>
<BaseAddress>0x7ffab0430000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\System32\ieapfltr.dll</Path>
<Version>11.00.14393.2189</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SmartScreen Filter</Description>
</module>
<module>
<Timestamp>131795786159084433</Timestamp>
<BaseAddress>0x7ffab0d50000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795786202624192</Timestamp>
<BaseAddress>0x7ffab2230000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\elshyph.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ELS Hyphenation Service</Description>
</module>
<module>
<Timestamp>131795786084579233</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786084609324</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786084567131</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\System32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786088444599</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795786084123182</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786160557742</Timestamp>
<BaseAddress>0x7ffababa0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\icm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Color Management Module (CMM)</Description>
</module>
<module>
<Timestamp>131795786082878183</Timestamp>
<BaseAddress>0x7ffababf0000</BaseAddress>
<Size>806912</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe64.dll</Path>
<Version>1, 0, 0, 1150</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786390382274</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795786086580284</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786085595890</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795786083370196</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786137282976</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795786244144116</Timestamp>
<BaseAddress>0x7ffabe110000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\imgutil.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE plugin image decoder support DLL</Description>
</module>
<module>
<Timestamp>131795786154004846</Timestamp>
<BaseAddress>0x7ffabe530000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\WindowsCodecsExt.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Extended Library</Description>
</module>
<module>
<Timestamp>131795786089791507</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\System32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795786155347443</Timestamp>
<BaseAddress>0x7ffabe830000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\smartscreenps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreenPS</Description>
</module>
<module>
<Timestamp>131795786389154702</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795786114772856</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786296880485</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795786085297567</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786112051091</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786107069509</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786241015463</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786083065977</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>126976</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N64.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795786100196624</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786271419198</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795786086130048</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795786082410441</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786087301397</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795786082393485</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786086032569</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786321446812</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795786282318342</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795786082097229</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786085965984</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786083356981</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\eShims.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Compatibility Shims</Description>
</module>
<module>
<Timestamp>131795786210171775</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786104739299</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786085635138</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786085676901</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786089609753</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795786087107447</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795786088421856</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795786092153446</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795786100849928</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786089750406</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795786088584854</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\System32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795786270943858</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795786270495097</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795786104726596</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786086442135</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795786085717720</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786086457038</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795786082439684</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786084597848</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786184150347</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795786141307846</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795786240298598</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786092224838</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786086057183</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786089629599</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795786086481184</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795786082048569</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795786084078182</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786086008568</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786083279286</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786088520571</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795786083257346</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786086544984</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795786105438151</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786098058671</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786098091830</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786085647065</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786093150053</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786082425895</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786083270628</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786085695835</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786084588700</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786098076226</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786112038692</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786112026610</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786085316210</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786082453168</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786082355351</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786082352777</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786082356404</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786082346599</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786082076458</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786082077405</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786082344914</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786082078287</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786082074829</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786082351486</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786082030503</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786082079752</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786082360385</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786082350101</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786082348521</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786082359321</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786082073607</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786085718659</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786082071659</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786082029525</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786086063062</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795786082345765</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786082362660</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786082465073</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786082343975</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786082075682</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786082361662</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795786082070778</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786082357670</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786082354079</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786082072862</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786076857714</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>165</ProcessIndex>
<ProcessId>9716</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786078382267</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>backgroundTaskHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\backgroundTaskHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\backgroundTaskHost.exe&quot; -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Background Task Host</Description>
<modulelist>
<module>
<Timestamp>131795786078418454</Timestamp>
<BaseAddress>0x7ff6c9470000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\backgroundTaskHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Task Host</Description>
</module>
<module>
<Timestamp>131795786443106818</Timestamp>
<BaseAddress>0x7ffaa63b0000</BaseAddress>
<Size>2260992</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentManagementSDK.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795786178014437</Timestamp>
<BaseAddress>0x7ffaadde0000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentDeliveryManager.Background.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795786446836026</Timestamp>
<BaseAddress>0x7ffab8f60000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\CryptoWinRT.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto WinRT Library</Description>
</module>
<module>
<Timestamp>131795786452519637</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786442096938</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795786184454951</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795786411124347</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795786447511170</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795786446350687</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795786178082701</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795786448549221</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795786087899215</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786439664619</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786178119779</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786438702275</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795786138262787</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795786087656774</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795786087636053</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795786178883132</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795786138319065</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786178060788</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\slc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795786424168262</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795786085105196</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786444935300</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786135208275</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786135908983</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786178148521</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786078586397</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786178071668</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795786448305262</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786447500168</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786447396943</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786178048432</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786085085167</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786078572417</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786444912775</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786087643960</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786087150180</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786078435842</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786078437510</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786087148614</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786085110036</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786444911600</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786078425607</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786178085269</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786178083562</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786078436568</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786078433692</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786078424455</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786087149421</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786087182640</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786087147697</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786078435030</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786178015977</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786444913925</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786078587414</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786078418747</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>166</ProcessIndex>
<ProcessId>10548</ProcessId>
<ParentProcessId>3632</ParentProcessId>
<ParentProcessIndex>38</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786089162133</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>microsoftedgecp.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe&quot; SCODEF:4760 CREDAT:140546 /prefetch:2</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Microsoft Edge Content Process</Description>
<modulelist>
<module>
<Timestamp>131795786091222895</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786090902666</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786089403507</Timestamp>
<BaseAddress>0x7ff6405a0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content Process</Description>
</module>
<module>
<Timestamp>131795786093276149</Timestamp>
<BaseAddress>0x7ffaafb30000</BaseAddress>
<Size>3379200</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\EdgeContent.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content</Description>
</module>
<module>
<Timestamp>131795786097059549</Timestamp>
<BaseAddress>0x7ffab0430000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\System32\ieapfltr.dll</Path>
<Version>11.00.14393.2189</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SmartScreen Filter</Description>
</module>
<module>
<Timestamp>131795786095385025</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786095414401</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786095372148</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\System32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786098894292</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795786095060723</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786092008108</Timestamp>
<BaseAddress>0x7ffababf0000</BaseAddress>
<Size>806912</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe64.dll</Path>
<Version>1, 0, 0, 1150</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786097852913</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786095928005</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795786093350863</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786137298934</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795786099499942</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\System32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795786155511100</Timestamp>
<BaseAddress>0x7ffabe830000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\smartscreenps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreenPS</Description>
</module>
<module>
<Timestamp>131795786175106783</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795786126783504</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786095697218</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786126703773</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786126666772</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786092840839</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>126976</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N64.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795786122446702</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786097238400</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795786091280736</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786098823307</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795786091266496</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786097003528</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786168735686</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795786090797141</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786096821309</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786093337459</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\eShims.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Compatibility Shims</Description>
</module>
<module>
<Timestamp>131795786149406998</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786124866847</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786096204385</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786096235413</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786099433900</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795786098769154</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795786098876641</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795786099938691</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795786126416006</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786099479132</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795786098957527</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\System32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795786124773333</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786097660874</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795786096795570</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786097688469</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795786091312218</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786095403206</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786220221983</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795786176564935</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795786196210087</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786100083353</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786097022036</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786099453250</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795786097703788</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795786090732326</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795786094154074</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786096836522</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786093314951</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786098913536</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795786093292052</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786097717992</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795786125771324</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786118519493</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786118553070</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786096216041</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786109730985</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786091297207</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786093305950</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786096756389</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786095394201</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786118538156</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786126691616</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786126679897</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786095715320</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786091326041</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786091234983</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786091232285</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786091236180</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786091226209</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786090775583</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786090776791</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786091224549</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786090777738</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786090758361</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786091230916</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786090715101</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786090779459</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786091239738</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786091229511</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786091227932</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786091238674</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786226607039</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795786090757247</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786096796493</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786090755355</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786090714140</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786097027569</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795786091225372</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786091241982</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786091337871</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786091223732</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786090759164</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786091241004</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795786090754460</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786091237308</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786091233709</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786090756519</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786089403873</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>167</ProcessIndex>
<ProcessId>8360</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786145545826</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>smartscreen.exe</ProcessName>
<ImagePath>C:\Windows\System32\smartscreen.exe</ImagePath>
<CommandLine>C:\Windows\System32\smartscreen.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>SmartScreen</Description>
<modulelist>
<module>
<Timestamp>131795786149935538</Timestamp>
<BaseAddress>0x7ff75abc0000</BaseAddress>
<Size>2416640</Size>
<Path>C:\Windows\System32\smartscreen.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreen</Description>
</module>
<module>
<Timestamp>131795786314242815</Timestamp>
<BaseAddress>0x7ffaa6a40000</BaseAddress>
<Size>2936832</Size>
<Path>C:\Windows\System32\CertEnroll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент регистрации служб сертификатов Active Directory Microsoft®</Description>
</module>
<module>
<Timestamp>131795786321983797</Timestamp>
<BaseAddress>0x7ffab0360000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\certca.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ЦС служб сертификации Microsoft® Active Directory</Description>
</module>
<module>
<Timestamp>131795786150398418</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786338506430</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786156130630</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795786162891895</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795786155325960</Timestamp>
<BaseAddress>0x7ffabe830000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\smartscreenps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreenPS</Description>
</module>
<module>
<Timestamp>131795786290626130</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795786303817642</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786292777426</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786308881957</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786291185460</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795786303729142</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786295084336</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786150377395</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\System32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795786150443503</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786295137905</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786293100161</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786293113418</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786317286245</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\dsparse.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795786296541369</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786294026752</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786150415925</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786150432150</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786162900766</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786290836325</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\samlib.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795786293555790</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795786293160744</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795786340507243</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795786297745460</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786155834219</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786303757002</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786167890086</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786167870284</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786150424134</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786294009833</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786150385959</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786155846861</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786303746521</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786303737722</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786292790345</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786150407736</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786149962132</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786149968291</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786149971001</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786149965440</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786149952992</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786149956475</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786149963670</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786149971757</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786149957278</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786149967388</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786149943620</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786149960523</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786149952242</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786155995189</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786157141835</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786149955480</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786167871961</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786149957990</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786154314206</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786149942691</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786322132523</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\Wldap32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795786149964615</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786149966457</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786151032932</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786149962916</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786149954350</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786149969125</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786149970065</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786149959703</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786149935879</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>168</ProcessIndex>
<ProcessId>10424</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786165392877</CreateTime>
<FinishTime>131795786220626599</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{DC4537C3-CA73-4AC7-9E1D-B2CE27C3A7A6}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795786165580408</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795786167836628</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795786167391676</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786166847881</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786166883283</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786166311839</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786166314864</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786166867627</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786166302973</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786168206836</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786168205896</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786166313892</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786166848937</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786166854863</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786166302020</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786166868439</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786166896006</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786166866807</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786166313074</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786167022152</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786165580657</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>169</ProcessIndex>
<ProcessId>10296</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795786226372453</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k wsappx</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795786226400516</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795786230130846</Timestamp>
<BaseAddress>0x7ffaa6d10000</BaseAddress>
<Size>2297856</Size>
<Path>C:\Windows\System32\AppXDeploymentServer.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера развертывания AppX</Description>
</module>
<module>
<Timestamp>131795786231602983</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795786230153246</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fltLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795786230145294</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795786231588260</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795786230170844</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786230189651</Timestamp>
<BaseAddress>0x7ffacb720000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\mintdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795786230158474</Timestamp>
<BaseAddress>0x7ffacb820000</BaseAddress>
<Size>712704</Size>
<Path>C:\Windows\System32\tdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795786231611090</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795786230164145</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786231594114</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786229616871</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786230136201</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786230137819</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795786229625340</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786229594723</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786229603946</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786229623786</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786231611929</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786230132115</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786229584668</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786230136994</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786230134090</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786230133328</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786229593263</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786229617635</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786229583632</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786229624570</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786229622783</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786229602893</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786230135123</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786229592437</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786226400757</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>170</ProcessIndex>
<ProcessId>10876</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786251236056</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SearchProtocolHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchProtocolHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchProtocolHost.exe&quot; Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-3477790013-1571897634-1299942168-1000288_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-3477790013-1571897634-1299942168-1000288 1 -2147483646 &quot;Software\Microsoft\Windows Search&quot; &quot;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)&quot; &quot;C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc&quot; &quot;DownLevelDaemon&quot;  &quot;1&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Protocol Host</Description>
<modulelist>
<module>
<Timestamp>131795786251269067</Timestamp>
<BaseAddress>0x7ff77c170000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\SearchProtocolHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Protocol Host</Description>
</module>
<module>
<Timestamp>131795786252378762</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\System32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795786311861720</Timestamp>
<BaseAddress>0x7ffab7d50000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\mssph.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик протоколов поиска Microsoft</Description>
</module>
<module>
<Timestamp>131795786298907649</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795786252887437</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795786252245401</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786252238173</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786252246194</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786252240990</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786252230091</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786252232823</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786252244559</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786252236231</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786252237203</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786252218352</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786252229401</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786252228473</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786252231867</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786252227168</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786255090404</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786252217360</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786252240184</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786252464763</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786252243819</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786252231033</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786252234383</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786258307185</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786252239270</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786252235203</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786251269513</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>171</ProcessIndex>
<ProcessId>12864</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795786259819446</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchFilterHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchFilterHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchFilterHost.exe&quot; 0 708 712 720 8192 716 </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Filter Host</Description>
<modulelist>
<module>
<Timestamp>131795786260175133</Timestamp>
<BaseAddress>0x7ff6a9f90000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\SearchFilterHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Filter Host</Description>
</module>
<module>
<Timestamp>131795786261457443</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\System32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795786263344012</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795786261520949</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786261484334</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786261436442</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786261439345</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786261482480</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786263346910</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786261425296</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786261435749</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786261434971</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786261438373</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786261433616</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786262531245</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786261424318</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786261483472</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786261480909</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786261481696</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786261437569</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786261440235</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786261442074</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786260175449</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>172</ProcessIndex>
<ProcessId>11924</ProcessId>
<ParentProcessId>3632</ParentProcessId>
<ParentProcessIndex>38</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786260517979</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>microsoftedgecp.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe&quot; SCODEF:4760 CREDAT:271620 /prefetch:2</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Microsoft Edge Content Process</Description>
<modulelist>
<module>
<Timestamp>131795786262397181</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786262167704</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786260845950</Timestamp>
<BaseAddress>0x7ff6405a0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content Process</Description>
</module>
<module>
<Timestamp>131795786266817230</Timestamp>
<BaseAddress>0x7ffaafb30000</BaseAddress>
<Size>3379200</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\EdgeContent.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content</Description>
</module>
<module>
<Timestamp>131795786273171730</Timestamp>
<BaseAddress>0x7ffab0430000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\System32\ieapfltr.dll</Path>
<Version>11.00.14393.2189</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SmartScreen Filter</Description>
</module>
<module>
<Timestamp>131795786270806162</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786270839051</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786270772483</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\System32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786275446565</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795786270072489</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786265786335</Timestamp>
<BaseAddress>0x7ffababf0000</BaseAddress>
<Size>806912</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe64.dll</Path>
<Version>1, 0, 0, 1150</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786274051995</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786272010707</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795786268295906</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786276659367</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\System32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795786270998807</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786266702928</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>126976</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N64.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795786281591660</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786273587652</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795786263279818</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786274502821</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795786262999598</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786273075968</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786262124801</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786273039671</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786267816488</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\eShims.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Compatibility Shims</Description>
</module>
<module>
<Timestamp>131795786272372041</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786272398710</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786276370397</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795786274296386</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795786275429221</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795786277431755</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795786281870494</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786276415541</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795786275500652</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\System32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795786273929786</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795786272872598</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786273944650</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795786264741964</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786270826076</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786277530830</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786273013365</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786276389583</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795786273968562</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795786261792794</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795786269891965</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786273053460</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786267733064</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786275464402</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795786267710124</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786273983354</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795786272383802</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786264728389</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786267723907</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786272853268</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786270815412</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786271801017</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786264754931</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786262716363</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786262713703</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786262717336</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786262708096</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786262103806</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786262104662</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786262706569</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786262105460</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786262102390</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786262712493</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786261162555</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786262106757</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786262720644</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786262711177</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786262709636</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786262719660</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786262101329</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786272873296</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786262099282</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786261161608</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786273020851</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795786262707345</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786263695399</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786264820388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786262705735</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786262103125</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786262721852</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795786262098445</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786262718386</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786262715028</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786262100531</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786260846246</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>173</ProcessIndex>
<ProcessId>6512</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786279544797</CreateTime>
<FinishTime>131795786332953778</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{DC4537C3-CA73-4AC7-9E1D-B2CE27C3A7A6}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795786279756626</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795786282280809</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795786281646883</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786279816706</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786279836723</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786279791427</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786279794572</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786279835169</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786279765038</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786282282419</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786282281668</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786279793499</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786279817501</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786279823410</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786279763827</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786279835983</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786279850030</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786279834412</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786279792641</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786280521004</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786279756867</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>174</ProcessIndex>
<ProcessId>10416</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786340684007</CreateTime>
<FinishTime>131795786440769208</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>OpenWith.exe</ProcessName>
<ImagePath>C:\Windows\system32\OpenWith.exe</ImagePath>
<CommandLine>C:\Windows\system32\OpenWith.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Выбор приложения</Description>
<modulelist>
<module>
<Timestamp>131795786340697046</Timestamp>
<BaseAddress>0x7ff7cf030000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\OpenWith.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Выбор приложения</Description>
</module>
<module>
<Timestamp>131795786364855084</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\System32\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795786385190978</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\duser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795786371582484</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786386435101</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795786363702843</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795786387741545</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795786375033549</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795786385172975</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\dui70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795786398185782</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\System32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795786371609311</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786358721789</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786364045243</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786365588891</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786365601478</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786372856393</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786365574958</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786393561736</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795786393544445</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795786376167966</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795786396849688</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795786384903236</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\System32\UIAutomationCore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795786395129075</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795786370388547</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786387700172</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795786356469026</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795786394999236</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795786386597129</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\System32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795786386570997</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795786365622133</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786363734173</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786386542039</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795786371593148</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786386485594</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786363723229</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786386649285</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795786390586753</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795786357409673</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786391843038</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786363713890</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786391819591</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795786386607690</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795786386581048</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795786365612937</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786384914246</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786371527014</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786398123334</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795786363743640</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786356442224</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786356438658</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786356443027</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786356431668</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786356434184</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786356426149</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786356430100</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786356437639</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786356416679</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786359375904</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786356436375</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786356435328</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786359374713</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786356433167</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786356429346</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786357514231</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786356415696</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786386382735</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795786356426961</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786356480704</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786356425185</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786356430923</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786356439506</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786358091907</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786356441268</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786356440265</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786340697298</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>175</ProcessIndex>
<ProcessId>5516</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786458574348</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\SysWOW64\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\SysWOW64\DllHost.exe /Processid:{53362C32-A296-4F2D-A2F8-FD984D08340B}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795786458625739</Timestamp>
<BaseAddress>0x1c0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795786458812497</Timestamp>
<BaseAddress>0x28a0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786458802018</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795786458803135</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795786459187647</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795786464828747</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786471755242</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795786467292564</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795786465884399</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786465896468</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786465871513</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786475201135</Timestamp>
<BaseAddress>0x72510000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\oleacchooks.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Event Hooks Library</Description>
</module>
<module>
<Timestamp>131795786464811068</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786465908090</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786465859315</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786460206704</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786460205088</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786464695607</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786460203002</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786461511851</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786460204080</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786464171982</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786465839162</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795786461513544</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786465833280</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786461526166</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786465840162</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786465830817</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786460190404</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786460954334</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786465573379</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786465829008</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786465832041</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786465577964</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786464044290</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786465834482</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786464043149</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786460952558</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786465838059</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786465836920</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786465835671</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786464045523</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786465579325</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786458626282</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795786458626030</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>176</ProcessIndex>
<ProcessId>10132</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786476963161</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\SysWOW64\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\SysWOW64\DllHost.exe /Processid:{60A90A2F-858D-42AF-8929-82BE9D99E8A1}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795786477001176</Timestamp>
<BaseAddress>0x1c0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795786478398121</Timestamp>
<BaseAddress>0x2d30000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786478389241</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795786478390127</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795786478400908</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795786480674311</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786482887456</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795786483144498</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795786480744805</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786480755984</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786480732611</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786479600862</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786480770108</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786480721105</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786482897187</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786478425807</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786478424070</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786479420252</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786478422103</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786478445339</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786478423111</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786479406688</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786480701271</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795786478446378</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786480695805</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786478454213</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786480702108</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786480693547</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786478411433</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786478427541</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786480678971</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786480692449</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786480694624</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786480682946</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786479404153</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786480696852</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786479403125</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786478426691</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786480700210</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786480699254</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786480697952</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786479405386</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786480690377</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786477001678</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795786477001417</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>177</ProcessIndex>
<ProcessId>4460</ProcessId>
<ParentProcessId>360</ParentProcessId>
<ParentProcessIndex>26</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131795786483672847</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>AUDIODG.EXE</ProcessName>
<ImagePath>C:\Windows\system32\AUDIODG.EXE</ImagePath>
<CommandLine>C:\Windows\system32\AUDIODG.EXE 0x3c8</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Изоляция графов аудиоустройств Windows </Description>
<modulelist>
<module>
<Timestamp>131795786483737234</Timestamp>
<BaseAddress>0x7ff644450000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\System32\audiodg.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Изоляция графов аудиоустройств Windows </Description>
</module>
<module>
<Timestamp>131795786489991459</Timestamp>
<BaseAddress>0x7ffaa61f0000</BaseAddress>
<Size>1802240</Size>
<Path>C:\Windows\System32\WMALFXGFXDSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SysFx DSP</Description>
</module>
<module>
<Timestamp>131795786491203172</Timestamp>
<BaseAddress>0x7ffab02d0000</BaseAddress>
<Size>552960</Size>
<Path>C:\Windows\System32\AudioEng.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Audio Engine</Description>
</module>
<module>
<Timestamp>131795786493632244</Timestamp>
<BaseAddress>0x7ffab2210000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\System32\AUDIOKSE.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Audio Ks Endpoint</Description>
</module>
<module>
<Timestamp>131795786489315184</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\AudioSes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795786491212877</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\avrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795786489374175</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786486995361</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795786487023199</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786487012555</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\devobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795786487110854</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786489316223</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786487130406</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786487013350</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786487027890</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786487128514</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786487028876</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786486974715</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786487025610</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786487014184</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786487024061</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786486996225</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786486983209</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786487161583</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786486973739</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786487129567</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786487127680</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786487026948</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786486997505</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786483737473</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>1</ProcessIndex>
<ProcessId>11372</ProcessId>
<ParentProcessId>10560</ParentProcessId>
<ParentProcessIndex>2</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770632346846</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon64.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Temp\Procmon64.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Temp\Procmon64.exe&quot;  /originalpath &quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot;</CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>2</ProcessIndex>
<ProcessId>10560</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770594566098</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon.exe</ProcessName>
<ImagePath>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot; </CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x1000000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x62530000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\RICHED20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cd0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72520000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\Riched32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wrapper Dll for Richedit 1.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>3</ProcessIndex>
<ProcessId>4048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765778109600457</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchIndexer.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchIndexer.exe</ImagePath>
<CommandLine>C:\Windows\system32\SearchIndexer.exe /Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Индексатор службы Microsoft Windows Search</Description>
<modulelist>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ff63db40000</BaseAddress>
<Size>929792</Size>
<Path>C:\Windows\system32\SearchIndexer.exe</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индексатор службы Microsoft Windows Search</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\MSSRCH.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabd990000</BaseAddress>
<Size>720896</Size>
<Path>C:\Windows\system32\ElsLad.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ELS Language Detection</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\Msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>4</ProcessIndex>
<ProcessId>580</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776275984299</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>services.exe</ProcessName>
<ImagePath>C:\Windows\system32\services.exe</ImagePath>
<CommandLine>C:\Windows\system32\services.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Приложение служб и контроллеров</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>6</ProcessIndex>
<ProcessId>664</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776282506625</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k DcomLaunch</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc6a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\SebBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; SEB Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc7e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\SmartCardBackgroundPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartCardBackgroundPolicy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8c0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\CbtBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; CBT Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8d0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\ACPBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; ACP Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc900000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BackgroundMediaPolicy.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Background Media Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\RmClient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca740000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\DAB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL брокера активности компьютера</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacabd0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\OnDemandBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OnDemandBrokerClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacae70000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\systemeventsbrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер системных событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacafc0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy RM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb010000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SYSTEM32\psmserviceexthost.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager PSM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb390000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\psmsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process State Manager (PSM) Service</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb4f0000</BaseAddress>
<Size>794624</Size>
<Path>c:\windows\system32\bisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба инфраструктуры фоновых задач</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb720000</BaseAddress>
<Size>344064</Size>
<Path>c:\windows\system32\mintdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>c:\windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb820000</BaseAddress>
<Size>712704</Size>
<Path>C:\Windows\SYSTEM32\tdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8d0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\umpoext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения службы пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8f0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\umpo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb940000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\umpnpmgr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский режим службы самонастройки (Plug-and-Play)</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>7</ProcessIndex>
<ProcessId>884</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776292813936</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9230000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\bluetoothapis.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Usermode Api host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9580000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\BthRadioMedia.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab95a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WlanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wlan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaba920000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\rmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Radio Manager API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabae80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\NfcRadioMedia.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NFC Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabb8a0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\XboxGipRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Xbox GIP Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc0e0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\WwanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wwan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac78c0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\shacct.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Classes</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7f80000</BaseAddress>
<Size>208896</Size>
<Path>c:\windows\system32\wscsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8490000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\dhcpcore6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8c90000</BaseAddress>
<Size>385024</Size>
<Path>c:\windows\system32\dhcpcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>c:\windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac9c30000</BaseAddress>
<Size>1732608</Size>
<Path>c:\windows\system32\wevtsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба протоколирования событий</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca2a0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\timebrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер событий времени</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca330000</BaseAddress>
<Size>36864</Size>
<Path>c:\windows\system32\nrpsrv.DLL</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Name Resolution Proxy (NRP) RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4d0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lmhsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб транспорта TCPIP NetBios</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>8</ProcessIndex>
<ProcessId>0</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:00000000</AuthenticationId>
<CreateTime>131765775874898587</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>4294967295</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity></Integrity>
<Owner></Owner>
<ProcessName>Idle</ProcessName>
<ImagePath>Idle</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>9</ProcessIndex>
<ProcessId>4</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775907178738</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>System</ProcessName>
<ImagePath>System</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b6e00000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\System32\win32kfull.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Win32k Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7190000</BaseAddress>
<Size>1576960</Size>
<Path>C:\Windows\System32\win32kbase.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Базовый драйвер ядра Win32k</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7320000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\TSDDD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Framebuffer Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7330000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\cdd.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Canonical Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b74a0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\win32k.sys</Path>
<Version>10.0.14393.594 (rs1_release_inmarket.161213-1754)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Multi-User Win32 Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80278934000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\kd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Kernel Debugger</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80279678000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92e00000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\ksecdd.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ee0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\cmimcext.sys</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Configuration Manager Initial Configuration Extension Host Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ef0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\ntosext.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTOS extension host driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92fa0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\drivers\cng.sys</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Cryptography, Next Generation</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93040000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\system32\drivers\Wdf01000.sys</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения платформы драйвера режима ядра</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93120000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\drivers\WDFLDR.SYS</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Mode Driver Framework Loader</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93140000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\Drivers\acpiex.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPIEx Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93170000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\Drivers\WppRecorder.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WPP Trace Recorder</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93180000</BaseAddress>
<Size>733184</Size>
<Path>C:\Windows\System32\drivers\ACPI.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPI драйвер для NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93240000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\WMILIB.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMILIB WMI support library Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93260000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\intelpep.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Power Engine Plugin</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93280000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\drivers\WindowsTrustedRT.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932a0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Service Proxy Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\pcw.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Performance Counters for Windows Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932d0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\msisadrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ISA Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932e0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\isapnp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер шины PNP ISA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932f0000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\drivers\pci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Plug and Play PCI-перечислитель</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93350000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\vdrvroot.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Drive Root Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93370000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\drivers\pdc.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Power Dependency Coordinator Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933a0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\CEA.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation Kernel Mode Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\partmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Partition driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\nvraid.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) RAID Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93420000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\CLASSPNP.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI Class System Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93490000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\vmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Дочерний драйвер шины виртуальной машины Microsoft Hyper-V</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d934c0000</BaseAddress>
<Size>1212416</Size>
<Path>C:\Windows\System32\drivers\NDIS.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS (Network Driver Interface Specification)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d935f0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\drivers\NETIO.SYS</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network I/O Subsystem</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93670000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\hvsocket.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Hyper-V Socket Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\vmbkmcl.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V VMBus KMCL</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\winhv.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Hypervisor Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\pciide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Generic PCI IDE Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936e0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\PCIIDEX.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PCI IDE Bus Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93700000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\drivers\spaceport.sys</Path>
<Version>10.0.14393.1914 (rs1_release_inmarket.171117-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Spaces Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937a0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\intelide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel PCI IDE Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937b0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\volmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937d0000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\drivers\volmgrx.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер расширения диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93830000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\drivers\mountmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер точек подключения</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93850000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\nvstor.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) Sata Performance Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\drivers\storport.sys</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Storage Port Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93910000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\atapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI IDE Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93920000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\System32\drivers\ataport.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93960000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\storahci.sys</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS AHCI Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93990000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\stornvme.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft NVM Express Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\drivers\EhStorClass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enhanced Storage Class driver for IEEE 1667 devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\fileinfo.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FileInfo Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939f0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\Drivers\Wof.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр оверлея Windows</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93a80000</BaseAddress>
<Size>2297856</Size>
<Path>C:\Windows\System32\Drivers\NTFS.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер файловой системы NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\storvsc.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage VSC Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cd0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\Drivers\Fs_Rec.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>File System Recognizer Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93d10000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\System32\drivers\USBPORT.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта USB 1.1 и 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93db0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\mcupdate_GenuineIntel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Microcode Update Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93e50000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\System32\drivers\CLFS.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Common Log File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ec0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\tm.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Transaction Manager Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ef0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\PSHED.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер аппаратных ошибок, специфичных для платформы</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f10000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\BOOTVID.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>VGA Boot Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f20000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\FLTMGR.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер фильтров файловых систем Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\drivers\msrpc.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Remote Procedure Call Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94000000</BaseAddress>
<Size>430080</Size>
<Path>C:\Windows\System32\drivers\fwpkclnt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FWP/IPsec Kernel-Mode API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94070000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\wfplwfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WFP NDIS 6.30 Lightweight Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d940b0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DRIVERS\fvevol.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BitLocker Drive Encryption Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94160000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\volume.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94170000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\System32\drivers\volsnap.sys</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume Shadow Copy driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d941e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\scmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Class Memory Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\drivers\rdyboost.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ReadyBoost Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94250000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\Drivers\mup.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер поставщика множественных UNC</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94280000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\drivers\iorate.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>I/O rate control Filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942a0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\disk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PnP Disk Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942e0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\crashdmp.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crash Dump Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d943c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\drivers\cdrom.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI CD-ROM Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94400000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\drivers\filecrypt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows sandboxing and encryption filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94420000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\tbs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Export driver for kernel mode TPM API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94430000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Null.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NULL Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94440000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Beep.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BEEP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94450000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\BasicDisplay.sys</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94470000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\watchdog.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Watchdog Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94490000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\System32\drivers\dxgkrnl.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Kernel</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\BasicRender.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Render Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\Npfs.SYS</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPFS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94700000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\DRIVERS\tdx.sys</Path>
<Version>10.0.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDI Translation Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94740000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\DRIVERS\netbt.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>MBT Transport driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94790000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\drivers\afd.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер дополнительных функций для Winsock</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94830000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\vwififlt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual WiFi Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94850000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\pacer.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Планировщик пакетов QoS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\drivers\netbios.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetBIOS interface driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d948a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\rdbss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер подсистемы буферизации перенаправленного диска</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94920000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\drivers\csc.sys</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Client Side Caching Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\nsiproxy.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\npsvctrig.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Named pipe service triggers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\gpuenergydrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GPU Energy Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a00000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Drivers\dfsc.sys</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DFS Namespace Client Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a50000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\DRIVERS\ahcache.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Compatibility Cache</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a90000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-Transport Composite Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\kdnic.sys</Path>
<Version>6.01.00.0000 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Kernel Debugger Network Miniport</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ac0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\drivers\umbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User-Mode Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ae0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\i8042prt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта i8042</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b10000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\drivers\kbdclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса клавиатуры</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b30000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\mouclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса мыши</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b80000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\HDAudBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ba0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\drivers\portcls.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Port Class (Class Driver for Port/Miniport Devices)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c10000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\drmk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trusted Audio Drivers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c40000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\drivers\ks.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel CSA Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cb0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\usbohci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OHCI USB Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\CmBatt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Control Method Battery Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cd0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\BATTC.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Class Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ce0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\intelppm.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Processor Device Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d10000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\NdisVirtualBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечислитель виртуальных сетевых адаптеров (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d20000</BaseAddress>
<Size>2588672</Size>
<Path>C:\Windows\System32\drivers\tcpip.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fa0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\swenum.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Plug and Play Software Device Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fb0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\rdpbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft RDP Bus Device driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95200000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\DRIVERS\udfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UDF File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95280000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\Drivers\dump_diskdump.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d952c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\Drivers\dump_storahci.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95310000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\Drivers\dump_dumpfve.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95330000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\system32\drivers\HTTP.sys</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Стек протокола HTTP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95450000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\drivers\WudfPf.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - User-mode Driver Framework Platform Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95470000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\DRIVERS\bowser.sys</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Lan Manager Datagram Receiver Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d954a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT SMB Minirdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95520000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\mpsdrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Protection Service Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95540000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb20.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB 2.0 Redirector</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95580000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\DRIVERS\srvnet.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Network driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d955d0000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\System32\DRIVERS\srv2.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер сервера SMB 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95690000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb10.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB Downlevel SubRdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d956e0000</BaseAddress>
<Size>573440</Size>
<Path>C:\Windows\System32\DRIVERS\srv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95770000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\tcpipreg.sys</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>TCP/IP Registry Compatibility Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95860000</BaseAddress>
<Size>684032</Size>
<Path>C:\Windows\System32\drivers\dxgmms2.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics MMS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95910000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\luafv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра виртуализации файлов LUA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95960000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\storqosflt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр качества обслуживания хранилища</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95980000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\registry.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Registry Containment Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959a0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\drivers\lltdio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Mapper I/O Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959c0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\drivers\mslldp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер протокола Microsoft LLDP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\rspndr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Responder Driver for NDIS 6</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95ae0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\USBD.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Universal Serial Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95af0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\DRIVERS\HdAudio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Function Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95b60000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\ksthunk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Streaming WOW Thunk Service</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95bc0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\HIDPARSE.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hid Parsing Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97020000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\Drivers\360AntiHacker64.sys</Path>
<Version>1.0.0.1149</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络防黑模块</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97060000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\DRIVERS\360AvFlt.sys</Path>
<Version>1.1.0.1056</Version>
<Company>360.cn</Company>
<Description>360杀毒 文件监控驱动</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97080000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\DRIVERS\BAPIDRV64.sys</Path>
<Version>2.0.0.1221</Version>
<Company>360.cn</Company>
<Description>BAPIDRV</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d970c0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\drivers\360netmon.sys</Path>
<Version>2.1.11.5195</Version>
<Company>360.cn</Company>
<Description>360netmon</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97120000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\system32\DRIVERS\360Box64.sys</Path>
<Version>2.1.0.1253</Version>
<Company>360.cn</Company>
<Description>360Box64</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97180000</BaseAddress>
<Size>811008</Size>
<Path>C:\Windows\system32\DRIVERS\360FsFlt.sys</Path>
<Version>6.9.1.1751</Version>
<Company>360.cn</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97330000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\hidusb.sys</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>USB Miniport Driver for Input Devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97350000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\HIDCLASS.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека классов HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97380000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\mouhid.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра мыши HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97390000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\rassstp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS SSTP Miniport Call Manager</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973b0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\DRIVERS\NDProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\drivers\AgileVpn.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер вызовов минипорта RAS Agile VPN</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97420000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\drivers\rasl2tp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS L2TP mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97460000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\raspptp.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Peer-to-Peer Tunneling Protocol</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974a0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\raspppoe.sys</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS PPPoE mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\DRIVERS\ndistapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS 3.0 connection wrapper driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974d0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\drivers\ndiswan.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS PPP Framing Driver (Strong Encryption)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97510000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\DRIVERS\wanarp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS Remote Access and Routing ARP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97550000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\E1G6032E.sys</Path>
<Version>8.4.13.0 built by: WinDDK</Version>
<Company>Intel Corporation</Company>
<Description>Intel(R) PRO/1000 Adapter NDIS 6 deserialized driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97580000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\tunnel.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер интерфейса туннеля (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97600000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\Drivers\PROCMON24.SYS</Path>
<Version>3.10</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor Driver</Description>
</module>
<module>
<Timestamp>131795780236159256</Timestamp>
<BaseAddress>0xfffff80d97620000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\npf.sys</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>npf.sys (NT5/6 AMD64) Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97a60000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\system32\drivers\peauth.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Protected Environment Authentication and Authorization Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b30000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\Ndu.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Network Data Usage Monitoring Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b60000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\drivers\mmcss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMCSS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97bb0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\condrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Driver</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>10</ProcessIndex>
<ProcessId>320</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775908989732</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>smss.exe</ProcessName>
<ImagePath>C:\Windows\System32\smss.exe</ImagePath>
<CommandLine>\SystemRoot\System32\smss.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер сеанса  Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>11</ProcessIndex>
<ProcessId>3108</ProcessId>
<ParentProcessId>3092</ParentProcessId>
<ParentProcessIndex>12</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777624392598</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Explorer.EXE</ProcessName>
<ImagePath>C:\Windows\Explorer.EXE</ImagePath>
<CommandLine>C:\Windows\Explorer.EXE</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x31b0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5db0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Program Files\Uninstall Tool\utshellext.dll</Path>
<Version>1.1.0.15</Version>
<Company>CrystalIDEA Software</Company>
<Description>Uninstall Tool Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x81a0000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\MICROS~1\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x8cb0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5bf70000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_08e394a1a83e212f\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\Notepad++\NppShell_06.dll</Path>
<Version>0.1</Version>
<Company></Company>
<Description>ShellHandler for Notepad++ (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\Explorer.EXE</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2093056</Size>
<Path>C:\Windows\system32\wpdshext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки для переносных устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab350000</BaseAddress>
<Size>1683456</Size>
<Path>C:\Windows\System32\comsvcs.dll</Path>
<Version>2001.12.10941.16384 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Services</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab4f0000</BaseAddress>
<Size>1400832</Size>
<Path>C:\Windows\system32\connect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Мастера подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab650000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\system32\rasgcw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Страницы мастера RAS</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\System32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\system32\ieframe.DLL</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0df0000</BaseAddress>
<Size>1626112</Size>
<Path>C:\Windows\SYSTEM32\d3d9.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 9 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0f80000</BaseAddress>
<Size>1777664</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoViewer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Просмотр фотографий Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab27c0000</BaseAddress>
<Size>516096</Size>
<Path>C:\Windows\System32\imapi2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>IMAPI версии 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2840000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\bthprops.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложение панели управления Bluetooth</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2880000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\cscobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Внутрипроцессный COM-объект используемый клиентами CSC API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab29a0000</BaseAddress>
<Size>1912832</Size>
<Path>C:\Windows\System32\pnidui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Значок сетевой системы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2b80000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\system32\SettingMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Change Monitor</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2bc0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\PortableDeviceTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device (Parameter) Types Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab34f0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\System32\Actioncenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5120000</BaseAddress>
<Size>1691648</Size>
<Path>C:\Windows\system32\BatMeter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Meter Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\MsftEdit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7e40000</BaseAddress>
<Size>3420160</Size>
<Path>C:\Windows\System32\SyncCenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр синхронизации Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\system32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\system32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab99b0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\dxp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки компонента Device Stage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9ba0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\SYSTEM32\searchfolder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SearchFolder</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabac60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\EhStorAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Enhanced Storage API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae20000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msiltcfg.dll</Path>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer Configuration API Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaea0000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\system32\SHDOCVW.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\SYSTEM32\settingsynccore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SYSTEM32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786030517308</Timestamp>
<BaseAddress>0x7ffabb910000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\container.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Containers</Description>
</module>
<module>
<Timestamp>131795786030225106</Timestamp>
<BaseAddress>0x7ffabb970000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\daxexec.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>daxexec</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795786377372706</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786377355113</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786377364261</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SYSTEM32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795786376748307</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd3c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\InputSwitch.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переключатель ввода Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd670000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\framedynos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI SDK Provider Framework</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd6c0000</BaseAddress>
<Size>1306624</Size>
<Path>C:\Windows\System32\werconcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PRS CPL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd800000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\NPSMDesktopProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Библиотека DLL локального поставщика рабочего стола NPSM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabda60000</BaseAddress>
<Size>1241088</Size>
<Path>C:\Windows\System32\wscui.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdeb0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\wpdshserviceobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device Shell Service Object</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabded0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\stobject.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Объект службы оболочки Systray</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe470000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\wscinterop.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Health Center WSC Interop</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe580000</BaseAddress>
<Size>831488</Size>
<Path>C:\Program Files (x86)\360\Total Security\MenuEx64.dll</Path>
<Version>9, 6, 0, 1001</Version>
<Company></Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe650000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\system32\zipfldr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сжатые ZIP-папки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9a0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\Syncreg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Synchronization Framework Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\system32\NetworkExplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0b0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\playtomenu.dll</Path>
<Version>12.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека меню функции &quot;Передать на устройство&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\System32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf590000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\syncui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Портфель Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795786456426767</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfba0000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\WSCAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\MICROS~1\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b40000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\dlnashext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLNA Namespace DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\srchadmin.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры индексирования</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0f60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SYSTEM32\CHARTV.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Chart View</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1cc0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.Sockets.PushEnabledApplication DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac27a0000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.111.0603.0006\amd64\FileSyncShell64.dll</Path>
<Version>18.111.0603.0006</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795786030406949</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fltLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac32e0000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\twext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Свойства: Предыдущие версии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3350000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\OLEACCHOOKS.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Event Hooks Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\dsreg.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5140000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\AboveLockAppHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AboveLockAppHost</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5190000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\NotificationController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5570000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\system32\twinui.pcshell.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Twinui.PCShell</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac55d0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\windows.immersiveshell.serviceprovider.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.ImmersiveShell.ServiceProvider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\system32\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5c70000</BaseAddress>
<Size>65536</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoBase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Base Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6650000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\npsm.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPSM</Description>
</module>
<module>
<Timestamp>131795780903771340</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac78f0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\hgcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Панель управления домашней группы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795782572474169</Timestamp>
<BaseAddress>0x7ffac7ce0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\ploptin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Prelaunch OptIn</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d40000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\SYNCENG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Briefcase Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d90000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\SYSTEM32\SndVolSSO.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Громкость SCA </Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7f50000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\acppage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека расширений для вкладки &quot;Совместимость&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\SYSTEM32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795778062352400</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\ploptin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Prelaunch OptIn</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ea0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\hcproviders.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщики компонента &quot;Центр безопасности и обслуживания&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca190000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\WorkFoldersShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки рабочих папок (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795780604813666</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac80000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SYSTEM32\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>13</ProcessIndex>
<ProcessId>404</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776186257169</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>15</ProcessIndex>
<ProcessId>468</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776223665667</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>17</ProcessIndex>
<ProcessId>484</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226419105</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>wininit.exe</ProcessName>
<ImagePath>C:\Windows\system32\wininit.exe</ImagePath>
<CommandLine>wininit.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Автозагрузка приложений Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>18</ProcessIndex>
<ProcessId>520</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226825613</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>winlogon.exe</ProcessName>
<ImagePath>C:\Windows\system32\winlogon.exe</ImagePath>
<CommandLine>winlogon.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Программа входа в систему Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ff7b5570000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\winlogon.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа входа в систему Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaee0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\dwminit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMInit</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacafa0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\UXINIT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows User Experience Session Initialization Dll</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>19</ProcessIndex>
<ProcessId>588</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776277547408</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>lsass.exe</ProcessName>
<ImagePath>C:\Windows\system32\lsass.exe</ImagePath>
<CommandLine>C:\Windows\system32\lsass.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Description>Local Security Authority Process</Description>
<modulelist>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x222e3610000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\msprivs.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переводы привилегий Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ff6b2d20000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\lsass.exe</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Security Authority Process</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffab9170000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\vaultsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба диспетчера учетных данных</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf170000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\hmkd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows HMAC Key Derivation API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf190000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\ngcpopkeysrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Passport Proof-of-possession Key Service</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\keyiso.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба изоляции ключей CNG</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SYSTEM32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf270000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SecureTimeAggregator.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Secure Time Aggregator</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb9b0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\scecli.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент редактора конфигураций безопасности</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\SspiSrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA SSPI RPC interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\dpapisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DPAPI Server</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbad0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\efslsaext.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA extension for EFS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbb70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wdigest.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Digest Access</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc00000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\MicrosoftAccountCloudAP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MicrosoftAccount Cloud AP Plugin</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc50000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\cloudAP.DLL</Path>
<Version>10.0.14393.1358 (rs1_release.170602-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cloud AP Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbcb0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\system32\pku2u.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pku2u Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd00000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\tspkg.DLL</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Web Service Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe30000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\gmsaclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;gmsaclient.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe60000</BaseAddress>
<Size>843776</Size>
<Path>C:\Windows\system32\netlogon.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека службы Net Logon</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc030000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\KerbClientShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kerberos Client Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc180000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\negoexts.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NegoExtender Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\JOINUTIL.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\netprovfw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Provisioning Service Framework DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc260000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\SYSTEM32\samsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сервера диспетчера учетных записей</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc380000</BaseAddress>
<Size>1527808</Size>
<Path>C:\Windows\system32\lsasrv.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера LSA</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>20</ProcessIndex>
<ProcessId>704</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776284978539</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k RPCSS</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8250000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\wshhyperv.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V Winsock2 Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6a0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\RpcRtRemote.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote RPC Extension</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\rpcepmap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сопоставитель конечных точек RPC
</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>21</ProcessIndex>
<ProcessId>808</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0000c8d4</AuthenticationId>
<CreateTime>131765776288401882</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>Window Manager\DWM-1</Owner>
<ProcessName>dwm.exe</ProcessName>
<ImagePath>C:\Windows\system32\dwm.exe</ImagePath>
<CommandLine>&quot;dwm.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер окон рабочего стола</Description>
<modulelist>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ff683990000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\dwm.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\system32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7b70000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\System32\Windows.Gaming.Input.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Gaming Input API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\avrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9a30000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SYSTEM32\ism32k.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca110000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\dwmghost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMGhost</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca8d0000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\system32\dwmcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека ядра Microsoft DWM</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacac90000</BaseAddress>
<Size>856064</Size>
<Path>C:\Windows\SYSTEM32\udwm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\dwmredir.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компонент перенаправления диспетчера окон рабочего стола Microsoft</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>22</ProcessIndex>
<ProcessId>904</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776293087855</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x259b0640000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\SFC.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab830000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\netman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>c:\windows\system32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>c:\windows\system32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab1260000</BaseAddress>
<Size>10350592</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll</Path>
<Version>4.7.2117.0 built by: NET47REL1LAST</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Common Language Runtime - WorkStation</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>c:\windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795778252487651</Timestamp>
<BaseAddress>0x7ffabc160000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\System32\aeinv.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Inventory Component</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778007496118</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabfa00000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\SYSTEM32\MSVCR120_CLR0400.dll</Path>
<Version>12.00.52519.0 built by: VSWINSERVICING</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\MSI.DLL</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0fc0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\spp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих точек защиты Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1010000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\system32\MSCOREE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac10f0000</BaseAddress>
<Size>421888</Size>
<Path>c:\windows\system32\storsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы хранения</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1240000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll</Path>
<Version>4.7.2623.0 built by: NET471REL1LAST_C</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795781037721051</Timestamp>
<BaseAddress>0x7ffac1660000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\System32\aeinv.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Inventory Component</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2420000</BaseAddress>
<Size>466944</Size>
<Path>c:\windows\system32\das.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сопоставления устройств</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795778007645121</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac41c0000</BaseAddress>
<Size>139264</Size>
<Path>c:\windows\system32\trkwks.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент отслеживания изменившихся связей</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4650000</BaseAddress>
<Size>516096</Size>
<Path>c:\windows\system32\pcasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба помощника по совместимости программ</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Assembly manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b50000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\dssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы NT для службы совместного доступа к данным</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6120000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\sysmain.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост службы Superfetch</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b10000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\SYSTEM32\WUDFPlatform.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - библиотека платформ пользовательского режима</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b50000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\wudfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation (WDF) - служба среды выполнения платформы драйвера режима пользователя</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9800000</BaseAddress>
<Size>376832</Size>
<Path>c:\windows\system32\audioendpointbuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство построения конечных точек Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9de0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\portabledeviceconnectapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Portable Device Connection API Components</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SYSTEM32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca2d0000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\ncbservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Посредник подключений к сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>c:\windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca710000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\pcadm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Diagnostic Module</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\system32\SXS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>c:\windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>23</ProcessIndex>
<ProcessId>96</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776304995849</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2510000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\energyprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2580000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\ncuprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Connectivity Statistics Provider for System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2b90000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\nduprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик сетевой статистики для службы отслеживания использования ресурсов системы</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bb0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\appsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bd0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\eeprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy Estimator SRUM provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2c20000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\wfapigp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall GPO Helper dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2d70000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\wpnsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SRUM provider for WPN</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3310000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\srumsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3730000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\pnpts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PlugPlay Troubleshooter</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3bd0000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\ncdautosetup.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы автоматической настройки сетевых устройств</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac41f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\adhapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD harvest sites and subnets API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4500000</BaseAddress>
<Size>200704</Size>
<Path>c:\windows\system32\dps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба политики диагностики WDI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4cd0000</BaseAddress>
<Size>933888</Size>
<Path>c:\windows\system32\mpssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба защиты (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6740000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\dtsh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API состояния общего доступа и обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac74b0000</BaseAddress>
<Size>827392</Size>
<Path>c:\windows\system32\bfe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба базовой фильтрации</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\coremessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\system32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\CFGMGR32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>24</ProcessIndex>
<ProcessId>348</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776305446235</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k netsvcs</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaa0aa0000</BaseAddress>
<Size>2138112</Size>
<Path>c:\windows\system32\wlidsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба учетных записей Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0750000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\system32\rascustom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль настраиваемых протоколов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab07b0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\vpnike.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>VPNIKE Protocol Engine - Test dll</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab09b0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\system32\rasppp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access PPP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0a00000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\rastapi.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access TAPI Compliance Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795786944300478</Timestamp>
<BaseAddress>0x7ffab3410000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab3440000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\rasmans.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер подключений удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4c50000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\eappprxy.dll</Path>
<Version>10.0.14393.187 (rs1_release_inmarket.160906-1818)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft EAPHost Peer Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab9a90000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\dmEnrollEngine.DLL</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enroll Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabc210000</BaseAddress>
<Size>2355200</Size>
<Path>c:\windows\system32\wuaueng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Агент Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabdf60000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\raschap.dll</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>Удаленные доступ через PPP CHAP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4a0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\appinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о приложении</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabed80000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\system32\wbem\wbemess.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee10000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee30000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\system32\wbem\wmiprvsd.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795786151289779</Timestamp>
<BaseAddress>0x7ffabf030000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf090000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>c:\windows\system32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfda0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\wbem\ncprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Non-COM WMI Event Provision APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0000000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wbem\repdrvfs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Repository Driver</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\shacctprofile.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Profile Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795783766785197</Timestamp>
<BaseAddress>0x7ffac13e0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\usocore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обновление ядра оркестратора сеанса</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1530000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SYSTEM32\dpx.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft(R) Delta Package Expander</Description>
</module>
<module>
<Timestamp>131795788214269808</Timestamp>
<BaseAddress>0x7ffac15d0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795783773591339</Timestamp>
<BaseAddress>0x7ffac1660000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\System32\updatehandlers.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Session Orchestrator Update Handlers</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1900000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\appxapplicabilityblob.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Appx Applicability Blob DLL</Description>
</module>
<module>
<Timestamp>131795783942703101</Timestamp>
<BaseAddress>0x7ffac1940000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1970000</BaseAddress>
<Size>1073152</Size>
<Path>c:\windows\system32\qmgr.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фоновая интеллектуальная служба передачи</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1c30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\DMProcessXMLFiltered.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmprocessxmlfiltered</Description>
</module>
<module>
<Timestamp>131795779661934902</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1cf0000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\SYSTEM32\wuuhext.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update Agent plugin for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1df0000</BaseAddress>
<Size>61440</Size>
<Path>c:\windows\system32\NCI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CoInstaller: NET</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e20000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f10000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\DMCmnUtils.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmcmnutils</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f50000</BaseAddress>
<Size>471040</Size>
<Path>C:\Windows\system32\wbem\esscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20f0000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\CLUSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API кластера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2210000</BaseAddress>
<Size>1351680</Size>
<Path>C:\Windows\system32\wbem\wbemcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инструментарий управления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2370000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\adhsvc.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD Harvest Sites and Subnets Service</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2390000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\httpprxm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager</Description>
</module>
<module>
<Timestamp>131795775850813653</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac24a0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\system32\RESUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служебной программы ресурсов кластера (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795784861928280</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2640000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\wmidcom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2670000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\miutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура управления</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac26f0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\sscoreext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Core DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2720000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SYSTEM32\WPTaskScheduler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WP Task Scheduler DLL</Description>
</module>
<module>
<Timestamp>131795784861934949</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2770000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\SSCORE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основная DLL-библиотека службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2940000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CSystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Classic System Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>c:\windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a40000</BaseAddress>
<Size>974848</Size>
<Path>c:\windows\system32\iphlpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Эта служба предоставляет автоматическое подключение IPv6 в сети IPv4.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c60000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\WDSCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Panther Engine Module</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\system32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3740000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3b40000</BaseAddress>
<Size>245760</Size>
<Path>c:\windows\system32\wbem\wmisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3fa0000</BaseAddress>
<Size>331776</Size>
<Path>c:\windows\system32\srvsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) ресурсов для службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4160000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\wpnservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба системы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4480000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\taskcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оснастка обратной совместимости диспетчера задач</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4540000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\ProximityServicePAL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service PAL</Description>
</module>
<module>
<Timestamp>131795775380234927</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4cc0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ProximityCommonPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Common PAL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4dc0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\ProximityCommon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Универсальная реализация близкого взаимодействия</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4ee0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\ProximityService.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service Implementation</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5ef0000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\System32\MbaeApiPublic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Mobile Broadband Account API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786151642053</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7700000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\CredentialMigrationHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Migration Handler</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\sqmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SQM Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795783776936389</Timestamp>
<BaseAddress>0x7ffac7ce0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\usoapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Session Orchestrator API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d60000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\UpdatePolicy.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Policy Reader</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e90000</BaseAddress>
<Size>749568</Size>
<Path>c:\windows\system32\FVEAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows BitLocker Drive Encryption API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac82d0000</BaseAddress>
<Size>643072</Size>
<Path>c:\windows\system32\shsvcs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8590000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\LocationWinPalMisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Location Platform Abstraction Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac85c0000</BaseAddress>
<Size>1810432</Size>
<Path>c:\windows\system32\LocationFramework.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа географического положения Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8780000</BaseAddress>
<Size>274432</Size>
<Path>c:\windows\system32\UBPM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL единого диспетчера фоновых процессов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8b60000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\schedsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба планировщика заданий</Description>
</module>
<module>
<Timestamp>131795783774133461</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac91c0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\profsvcext.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvcExt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92a0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\sens.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба уведомления о системных событиях (SENS)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\themeservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы темы оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9420000</BaseAddress>
<Size>380928</Size>
<Path>c:\windows\system32\profsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvc</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9a70000</BaseAddress>
<Size>1257472</Size>
<Path>c:\windows\system32\gpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca700000</BaseAddress>
<Size>32768</Size>
<Path>c:\windows\system32\DABAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Desktop Activity Broker API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca720000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\bitsigd.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service IGD Support</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacab70000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба географического положения</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac40000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\seclogon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL службы вторичного входа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac50000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\bitsperf.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Perfmon Counter Access</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\MSWSOCK.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>25</ProcessIndex>
<ProcessId>372</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776305463443</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>c:\windows\system32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab91f0000</BaseAddress>
<Size>233472</Size>
<Path>c:\windows\system32\sstpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обеспечивает возможность использования SSTP для подключения к удаленным компьютерам с помощью VPN.</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795780812578370</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabc610000</BaseAddress>
<Size>540672</Size>
<Path>c:\windows\system32\w32time.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба времени Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabef00000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\cdpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба CDP Майкрософт (R)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05e0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\sbservicetrigger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Socket Broker Service Trigger</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795780812550384</Timestamp>
<BaseAddress>0x7ffac3290000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\fthsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль диагностики отказоустойчивой кучи Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4130000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\fdphost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба размещения поставщиков функций обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4200000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\perftrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Performance PerfTrack</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5b80000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\AuthBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API WinRT для веб-проверки подлинности</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66e0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\fdssdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery SSDP Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6960000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\fdwsd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery WS Discovery Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac76d0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\vmictimeprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Machine Integration Component Time Sync Provider Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7a10000</BaseAddress>
<Size>544768</Size>
<Path>c:\windows\system32\netprofmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер списка сетей</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7f70000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\licensemanagersvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManagerSvc</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90a0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\nsisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RPC-сервер интерфейса сохранения сети</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac91f0000</BaseAddress>
<Size>172032</Size>
<Path>c:\windows\system32\FontProvider.dll</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Font Provider Library</Description>
</module>
<module>
<Timestamp>131795780812573070</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9860000</BaseAddress>
<Size>1896448</Size>
<Path>c:\windows\system32\fntcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэша шрифтов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>c:\windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795780812567382</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>26</ProcessIndex>
<ProcessId>360</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311216195</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffabaad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\deviceaccess.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Broker And Policy COM Server</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac7e70000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\coreaudiopolicymanagerext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;coreaudiopolicymanagerext.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac87d0000</BaseAddress>
<Size>237568</Size>
<Path>c:\windows\system32\AUDIOSRVPOLICYMANAGER.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Audio Service Policy Manager</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac90d0000</BaseAddress>
<Size>978944</Size>
<Path>c:\windows\system32\audiosrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\POWRPROF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>27</ProcessIndex>
<ProcessId>1040</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311708649</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8820000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SYSTEM32\cmintegrator.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>cmintegrator.dll</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8c50000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wcmcsp.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Service Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8fe0000</BaseAddress>
<Size>737280</Size>
<Path>c:\windows\system32\wcmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы диспетчера подключений Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>28</ProcessIndex>
<ProcessId>1068</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776312395030</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\CRYPTNET.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\cryptcatsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Catalog Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65f0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\crypttpmeksvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic TPM Endorsement Key Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6680000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\cryptsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6f00000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\wkssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы рабочей станции</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79e0000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\netjoin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL присоединения к домену</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\WlanApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7c00000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\ssdpapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8260000</BaseAddress>
<Size>425984</Size>
<Path>c:\windows\system32\ncsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индикатор работоспособности сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8370000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\nlasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о подключенных сетях 2</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8410000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dnsext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DNS extension DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SYSTEM32\Fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8830000</BaseAddress>
<Size>290816</Size>
<Path>c:\windows\system32\dnsrslvr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэширующего сопоставителя DNS</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\JoinUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>29</ProcessIndex>
<ProcessId>1248</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776322176070</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>spoolsv.exe</ProcessName>
<ImagePath>C:\Windows\System32\spoolsv.exe</ImagePath>
<CommandLine>C:\Windows\System32\spoolsv.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер очереди печати</Description>
<modulelist>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ff639680000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\spoolsv.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер очереди печати</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffab8a60000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaba980000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\jscript.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabb7d0000</BaseAddress>
<Size>851968</Size>
<Path>C:\Windows\System32\win32spl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик печати с исполнением на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\prntvpt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Ticket Services Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd70000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_53d78f68bc1697cc\Amd64\PrintConfig.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc0c0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPFILEQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPFILEQ</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc590000</BaseAddress>
<Size>118784</Size>
<Path>C:\Program Files\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc5b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\amsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Anti-Malware Scan Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd040000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdPnp.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pnp Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd060000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\WSDMon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер порта принтера WSD</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd100000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\usbmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Standard Dynamic Printing Port Monitor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd160000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\wsnmp32.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft WinSNMP v2.0 Manager API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd2a0000</BaseAddress>
<Size>1159168</Size>
<Path>C:\Windows\System32\localspl.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека локального диспетчера очереди</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabde60000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\System32\tcpmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека монитора портов TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe3f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\spool\PRTPROCS\x64\winprint.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Print Processor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe6c0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\PrintIsolationProxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Sandbox COM Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe8a0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\snmpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SNMP Utility Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe980000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\SPOOLSS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Spooler SubSystem DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f00000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\FXSMON.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft  Fax Print Monitor</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac4e90000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\wshirda.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Sockets Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac7e00000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\inetpp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Internet Print Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>30</ProcessIndex>
<ProcessId>1512</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776336551242</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffabe9f0000</BaseAddress>
<Size>258048</Size>
<Path>c:\windows\system32\ssdpsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы SSDP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69b0000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\fdrespub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба публикации ресурсов обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>c:\windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>31</ProcessIndex>
<ProcessId>1556</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776339471770</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k utcsvc</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x272f9bf0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf140000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\CourtesyEngine.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Feedback Courtesy Engine DLL Server</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfde0000</BaseAddress>
<Size>143360</Size>
<Path>c:\windows\system32\CRYPTXML.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API-интерфейс XML DigSig</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\Netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\DSREG.DLL</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac5fd0000</BaseAddress>
<Size>1056768</Size>
<Path>c:\windows\system32\WindowsPerformanceRecorderControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Performance Recorder Control Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>c:\windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6210000</BaseAddress>
<Size>2007040</Size>
<Path>c:\windows\system32\diagtrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диагностическое отслеживание Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786489787144</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795786490911252</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>32</ProcessIndex>
<ProcessId>1636</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776343009549</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k appmodel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>c:\windows\system32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3c10000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\tileobjserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер моделей данных плиток</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>c:\windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>c:\windows\system32\windows.staterepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795780599947775</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795780600943570</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>33</ProcessIndex>
<ProcessId>1744</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776348255325</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>MemCompression</ProcessName>
<ImagePath>MemCompression</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>34</ProcessIndex>
<ProcessId>2100</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776438403561</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffabff90000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\ipsecsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows IPsec SPD Server DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac1e00000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\FwRemoteSvr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall Remote APIs Server</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>35</ProcessIndex>
<ProcessId>2648</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777555980720</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>sihost.exe</ProcessName>
<ImagePath>C:\Windows\system32\sihost.exe</ImagePath>
<CommandLine>sihost.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Shell Infrastructure Host</Description>
<modulelist>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ff7bbae0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\sihost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Infrastructure Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb910000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\container.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Containers</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb970000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\daxexec.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>daxexec</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc450000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\system32\ShareHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShareHost</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc800000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\windowmanagement.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Window Management</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc850000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\AppointmentActivation.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL for AppointmentActivation</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc8b0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\NotificationPlatformComponent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationPlatformComponent</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc9a0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\activationmanager.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Activation Manager</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabca10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\ClipboardServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Modern Clipboard</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcde0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Windows\System32\modernexecserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Modern Execution</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcf10000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\desktopshellext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DesktopHost Extensions</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\system32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>36</ProcessIndex>
<ProcessId>840</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777563791648</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k UnistackSvcGroup</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf6a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\PhoneUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Phone utilities</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf700000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\System32\PIMSTORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>POOM</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab05d0000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\AccountAccessor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync data model to access accounts</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab0630000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\SyncController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SyncController for managing sync of mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb20000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\CEMAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CEMAPI</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcd80000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\cdpusersvc.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP User Components</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabd630000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\MCCSEngineShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Utilies shared among OneSync engines</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabdde0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\SYNCUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabed20000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\aphostservice.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>c:\windows\system32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4100000</BaseAddress>
<Size>151552</Size>
<Path>c:\windows\system32\NetworkHelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac97b0000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\InprocLogger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>In-proc Private Event Trace Logger</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca1d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\UserDataTypeHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Type Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca270000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\UserDataLanguageUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Language-related helper functions for user data</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca520000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\APHostClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service RPC Client </Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacabf0000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\MCCSPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform abstraction layer dll for MCCS</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacac20000</BaseAddress>
<Size>86016</Size>
<Path>c:\windows\system32\UserDataPlatformHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>37</ProcessIndex>
<ProcessId>528</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777565618284</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\system32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb440000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\system32\MTFServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;MTFServer.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb510000</BaseAddress>
<Size>2854912</Size>
<Path>C:\Windows\system32\InputService.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Text InputService Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8c0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\InputLocaleManager.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;InputLocaleManager.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8f0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\EditBufferTestHook.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;EditBufferTestHook.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb9f0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\system32\MSUTB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) сервера MSUTB</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabba70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\MsCtfMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MsCtfMonitor DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabbc20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\PlaySndSrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба PlaySound</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\system32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac7d10000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\KBDUS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>United States Keyboard Layout</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab10000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\WordBreakers.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;WordBreakers.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>38</ProcessIndex>
<ProcessId>3632</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777941176116</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>RuntimeBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\RuntimeBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\RuntimeBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Runtime Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7a45f0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\RuntimeBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Runtime Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\System32\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795780843802542</Timestamp>
<BaseAddress>0x7ffaad3f0000</BaseAddress>
<Size>1826816</Size>
<Path>C:\Windows\System32\Wpc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека параметров родительского контроля</Description>
</module>
<module>
<Timestamp>131795786292112107</Timestamp>
<BaseAddress>0x7ffab08d0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\LockAppBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL брокера приложения &quot;Блокировка&quot; Windows</Description>
</module>
<module>
<Timestamp>131795786164057245</Timestamp>
<BaseAddress>0x7ffab0b10000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\mssvp.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа Vista MSSearch</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\mssrch.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795780489291214</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795786088780638</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786148630640</Timestamp>
<BaseAddress>0x7ffabaad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\deviceaccess.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Broker And Policy COM Server</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795786089047958</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795780613006289</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795780733496994</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795780611542837</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795786306767518</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786143522657</Timestamp>
<BaseAddress>0x7ffabd220000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\Windows.Devices.Enumeration.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Enumeration</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795786165227211</Timestamp>
<BaseAddress>0x7ffabe130000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\mapi32.dll</Path>
<Version>1.0.2536.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенный MAPI 1.0 для Windows NT</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795786089826857</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe880000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\FeClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT File Encryption Client Interfaces</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe8c0000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\system32\windows.cortana.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.Desktop</Description>
</module>
<module>
<Timestamp>131795786151786571</Timestamp>
<BaseAddress>0x7ffabf030000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780443980999</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf9c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\system32\windows.cortana.onecore.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.OneCore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795786445101159</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795779561161209</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786075081206</Timestamp>
<BaseAddress>0x7ffac15d0000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Core.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Model Core API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780447369522</Timestamp>
<BaseAddress>0x7ffac37b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795771234179313</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795780489961900</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795780846908833</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5ca0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\AppExtension.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API AppExtension</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786144114651</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795786145514308</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795786287854312</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786448623381</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7d00000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SYSTEM32\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795780849625720</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786090201282</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\samlib.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795780611842861</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>39</ProcessIndex>
<ProcessId>3164</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778119045372</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ShellExperienceHost.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe&quot; -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Windows Shell Experience Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ff697570000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Experience Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f760000</BaseAddress>
<Size>3796992</Size>
<Path>C:\Windows\System32\MFMediaEngine.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Media Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaabad0000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\mfsrcsnk.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Source and Sink DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaafe70000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\System32\mfcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Core DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab0be0000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\ShellExperiences\NetworkUX.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab9eb0000</BaseAddress>
<Size>2899968</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.ActionCenter.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActionCenter Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaba180000</BaseAddress>
<Size>7880704</Size>
<Path>C:\Windows\ShellExperiences\StartUI.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Start UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SYSTEM32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd420000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\RTMediaFrame.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime MediaFrame DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe410000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\SYSTEM32\globcollationhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GlobCollationHost</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795780594734370</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0080000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\System32\resampledmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Resampler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0110000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\QuickActionsDataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>QuickActionsDataModel</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0160000</BaseAddress>
<Size>491520</Size>
<Path>C:\Windows\ShellExperiences\QuickActions.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac40f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4eb0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5b20000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\CompPkgSup.DLL</Path>
<Version>10.0.14393.969 (rs1_release_inmarket.170315-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Component Package Support DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5e90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\Windows.Media.MediaControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера MediaControl среды выполнения Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>40</ProcessIndex>
<ProcessId>4856</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778391112136</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MSASCuiL.exe</ProcessName>
<ImagePath>C:\Program Files\Windows Defender\MSASCuiL.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Windows Defender\MSASCuiL.exe&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Description>Windows Defender notification icon</Description>
<modulelist>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x23622c70000</BaseAddress>
<Size>733184</Size>
<Path>C:\Program Files\Windows Defender\EppManifest.dll</Path>
<Version>4.10.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль ресурсов настройки пользовательского интерфейса</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ff63bef0000</BaseAddress>
<Size>651264</Size>
<Path>C:\Program Files\Windows Defender\MSASCuiL.exe</Path>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Defender notification icon</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4560000</BaseAddress>
<Size>950272</Size>
<Path>C:\Program Files\Windows Defender\mpclient.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Client Interface</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>41</ProcessIndex>
<ProcessId>4928</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778406250112</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>uTorrent.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe&quot;  /MINIMIZED</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>3.5.4.44498</Version>
<Description>µTorrent</Description>
<modulelist>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>5406720</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</Path>
<Version>3.5.4.44498</Version>
<Company>BitTorrent Inc.</Company>
<Description>µTorrent</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e140000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SysWOW64\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1c0000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\SysWOW64\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6ef20000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70af0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fc0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fd0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fe0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>42</ProcessIndex>
<ProcessId>3608</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778496229053</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ApplicationFrameHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\ApplicationFrameHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\ApplicationFrameHost.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Application Frame Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ff6aa270000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\ApplicationFrameHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Frame Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5240000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\ApplicationFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фрейм приложения</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\system32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795786034558955</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\D3D10Warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>43</ProcessIndex>
<ProcessId>5952</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778883326814</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54150_1240996307 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>44</ProcessIndex>
<ProcessId>5800</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765779120650795</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\esent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>45</ProcessIndex>
<ProcessId>340</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765800389528045</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54870_1839591030 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c50000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\Ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>46</ProcessIndex>
<ProcessId>2736</ProcessId>
<ParentProcessId>3976</ParentProcessId>
<ParentProcessIndex>47</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765800903010156</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Taskmgr.exe</ProcessName>
<ImagePath>C:\Windows\System32\Taskmgr.exe</ImagePath>
<CommandLine>&quot;C:\Windows\System32\Taskmgr.exe&quot; /2 </CommandLine>
<CompanyName>Microsoft® Windows® Operating System</CompanyName>
<Version>1, 0, 0, 1</Version>
<Description>Task Manager</Description>
<modulelist>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ff7c2a70000</BaseAddress>
<Size>1286144</Size>
<Path>C:\Windows\System32\Taskmgr.exe</Path>
<Version>1, 0, 0, 1</Version>
<Company>Microsoft® Windows® Operating System</Company>
<Description>Task Manager</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdfa0000</BaseAddress>
<Size>393216</Size>
<Path>C:\Windows\System32\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\System32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>49</ProcessIndex>
<ProcessId>6724</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803507001117</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHActiveDefense.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe&quot;</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1008</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795778431738530</Timestamp>
<BaseAddress>0x10000</BaseAddress>
<Size>413696</Size>
<Path>C:\ProgramData\Package Cache\{b8e12890-118d-4721-8e54-05d978086712}\VC_redist.x64.exe</Path>
<Version>14.0.24516.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24516</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0xd0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</Path>
<Version>10,0,0,1008</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795778469924367</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Wireshark\WinPcap_4_1_3.exe</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>WinPcap 4.1.3 installer</Description>
</module>
<module>
<Timestamp>131795778203065490</Timestamp>
<BaseAddress>0x840000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files\Wireshark\vcredist_x64.exe</Path>
<Version>14.12.25810.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810</Description>
</module>
<module>
<Timestamp>131795786058722021</Timestamp>
<BaseAddress>0x34c0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\browser_broker.exe</Path>
<Version>11.00.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>Browser_Broker</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x3c80000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795780944214585</Timestamp>
<BaseAddress>0x40a0000</BaseAddress>
<Size>438272</Size>
<Path>C:\Program Files\Wireshark\dumpcap.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community</Company>
<Description>Dumpcap</Description>
</module>
<module>
<Timestamp>131795780231568066</Timestamp>
<BaseAddress>0x4630000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SysWOW64\net1.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Command</Description>
</module>
<module>
<Timestamp>131795778389953959</Timestamp>
<BaseAddress>0xa8e0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786140191230</Timestamp>
<BaseAddress>0xe830000</BaseAddress>
<Size>2416640</Size>
<Path>C:\Windows\System32\smartscreen.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreen</Description>
</module>
<module>
<Timestamp>131795780691287613</Timestamp>
<BaseAddress>0xf730000</BaseAddress>
<Size>8298496</Size>
<Path>C:\Program Files\Wireshark\Wireshark.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark</Description>
</module>
<module>
<Timestamp>131795780222197886</Timestamp>
<BaseAddress>0x10000000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fb90000</BaseAddress>
<Size>2736128</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\deepscan.dll</Path>
<Version>3, 5, 1, 2130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60190000</BaseAddress>
<Size>475136</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360SafeCamera.tpi</Path>
<Version>2, 0, 0, 1031</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60210000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\jcloudscan.dll</Path>
<Version>1, 0, 0, 1012</Version>
<Company>360.cn</Company>
<Description>360安全卫士 移动云查询模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604a0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appdext.dll</Path>
<Version>1, 0, 0, 1483</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604e0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\DrvUtility.dll</Path>
<Version>1, 0, 0, 1081</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60510000</BaseAddress>
<Size>409600</Size>
<Path>C:\Program Files (x86)\360\Total Security\SafeScan.dll</Path>
<Version>1, 0, 0, 1074</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60580000</BaseAddress>
<Size>204800</Size>
<Path>C:\Program Files (x86)\360\Total Security\ScanStub.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x605c0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360gameidentify.dll</Path>
<Version>1, 0, 1, 1050</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏识别模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60640000</BaseAddress>
<Size>430080</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\Netgm.dll</Path>
<Version>9,0,0,1005</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏模式判断模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60a50000</BaseAddress>
<Size>479232</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\DsSysRepair.dll</Path>
<Version>1, 0, 0, 1062</Version>
<Company>QIHU360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security System Repair Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61000000</BaseAddress>
<Size>184320</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\qutmipc.dll</Path>
<Version>7, 3, 0, 1267</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61030000</BaseAddress>
<Size>262144</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg.dll</Path>
<Version>3, 0, 0, 1160</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x610d0000</BaseAddress>
<Size>1097728</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\SomAdvUtils.dll</Path>
<Version>3, 1, 1, 2020</Version>
<Company>360.cn</Company>
<Description>360 Safeguard PC Boost</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61480000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qex\qex.dll</Path>
<Version>4.1.13.3366</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2017 Antivirus</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x616a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SelfProtectAPI2.dll</Path>
<Version>7, 1, 1, 1033</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61700000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360procmon.dll</Path>
<Version>7, 1, 1, 1221</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61780000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\netdefender.dll</Path>
<Version>1, 0, 0, 1129</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x617e0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appd.dll</Path>
<Version>7, 3, 6, 3113</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360HipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61ab0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\fileMgr.dll</Path>
<Version>7, 3, 0, 1963</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x621a0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\yhregd.dll</Path>
<Version>7, 2, 0, 1903</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62280000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\360SoftMgrS.dll</Path>
<Version>2, 1, 6, 1490</Version>
<Company>360.cn</Company>
<Description>360软件管家 服务模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62470000</BaseAddress>
<Size>405504</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll</Path>
<Version>7, 2, 1, 1279</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x624e0000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\360box.dll</Path>
<Version>2, 0, 0, 1043</Version>
<Company>360.cn</Company>
<Description>360隔离沙箱模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\deepscan\DsRes.dll</Path>
<Version>1,0,0,1012</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security Resource</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b70000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\gamemode.tpi</Path>
<Version>9,0,0,1001</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Game Mode Control</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67130000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\devenum.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечисление устройств.</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\fltlib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6c0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6ea80000</BaseAddress>
<Size>860160</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\QVM\360QVM.dll</Path>
<Version>5.0.2.1003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security QVM Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70210000</BaseAddress>
<Size>966656</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEngine.dll</Path>
<Version>1, 0, 0, 2016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70300000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEI.dll</Path>
<Version>1, 0, 0, 2003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>50</ProcessIndex>
<ProcessId>6340</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765803510844292</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>QHSafeTray.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</ImagePath>
<CommandLine>/showtrayicon</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1024</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0xec0000</BaseAddress>
<Size>2351104</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</Path>
<Version>10,0,0,1024</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x68f0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c480000</BaseAddress>
<Size>245760</Size>
<Path>C:\Program Files (x86)\360\Total Security\PDown.dll</Path>
<Version>1, 3, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Security Center Network Module </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5fe30000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll</Path>
<Version>9,6,0,1001</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60020000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360netctrl.dll</Path>
<Version>5, 3, 15, 2232</Version>
<Company>360.cn</Company>
<Description>360 Total Security NetwokrMonCtrl</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60090000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\netmon.tpi</Path>
<Version>5, 1, 1, 3157</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360安全卫士 流量防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60350000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Program Files (x86)\360\Total Security\ToolBox.dll</Path>
<Version>1, 0, 0, 1094</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x606b0000</BaseAddress>
<Size>598016</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe.dll</Path>
<Version>1, 0, 0, 1120</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x609b0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360GuardBase.dll</Path>
<Version>3, 1, 0, 1060</Version>
<Company>360.cn</Company>
<Description>360保镖</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61070000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SomProxy.dll</Path>
<Version>1, 0, 0, 1900</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x611e0000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360connect.tpi</Path>
<Version>9,2,0,1030</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Connect</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x618c0000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files (x86)\360\Total Security\sites.dll</Path>
<Version>11, 1, 0, 1212</Version>
<Company>360.cn</Company>
<Description>360安全卫士</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360hipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\softmgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\Cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62210000</BaseAddress>
<Size>446464</Size>
<Path>C:\Program Files (x86)\360\Total Security\360TSCommon.dll</Path>
<Version>9, 0, 0, 1016</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62960000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\CleanPlusCache.tpi</Path>
<Version>1, 0, 0, 1004</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>CleanPlusCache</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795771279916892</Timestamp>
<BaseAddress>0x68850000</BaseAddress>
<Size>2764800</Size>
<Path>C:\Windows\SysWOW64\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e6e0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e770000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SysWOW64\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71170000</BaseAddress>
<Size>466944</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\CQhCltHttpW.dll</Path>
<Version>1, 4, 0, 1030</Version>
<Company>QIHU 360 SOFTWARE  CO. LIMITED</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>51</ProcessIndex>
<ProcessId>6860</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803555957830</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHWatchdog.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe&quot; /watch</CommandLine>
<CompanyName>QIHU 360 SOFTWARE CO. LIMITED</CompanyName>
<Version>8,2,0,1000</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0xdf0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</Path>
<Version>8,2,0,1000</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>52</ProcessIndex>
<ProcessId>5924</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765805232900810</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>wmiprvse.exe</ProcessName>
<ImagePath>C:\Windows\sysWOW64\wbem\wmiprvse.exe</ImagePath>
<CommandLine>C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Description>WMI Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x950000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\sysWOW64\wbem\wmiprvse.exe</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Provider Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\storagewmi_passthru.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60160000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x604d0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\delegatorprovider.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>54</ProcessIndex>
<ProcessId>4408</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765812380694767</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x17826230000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1140000</BaseAddress>
<Size>1134592</Size>
<Path>C:\Windows\System32\ReAgent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>C:\Windows\System32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\system32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe000000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\system32\WinSATAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Assessment Tool API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf050000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\sdiageng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема выполнения сценариев диагностики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4ae0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sdiagschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запланированная задача сценариев проверки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4b00000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\MemoryDiagnostic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач средства проверки памяти Windows (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac5c80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\TempSignedLicenseExchangeTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TempSignedLicenseExchangeTask Task</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca200000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\ReAgentTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca210000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\RstrtMgr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер перезапуска</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacac00000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\radarrs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>программа устранения нехватки системных ресурсов Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>55</ProcessIndex>
<ProcessId>6944</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131767576301455145</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SkypeHost.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe&quot; -ServerName:SkypeHost.ServerServer</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>12.1815.210.0</Version>
<Description>Microsoft Skype</Description>
<modulelist>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ff7e8670000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaae130000</BaseAddress>
<Size>22437888</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkyWrap.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabe150000</BaseAddress>
<Size>2691072</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\skypert.dll</Path>
<Version>2018.15.01.31</Version>
<Company></Company>
<Description>SkypeRT shared library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1a80000</BaseAddress>
<Size>978944</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7c80000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>56</ProcessIndex>
<ProcessId>1048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131768729449405953</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>sedsvc.exe</ProcessName>
<ImagePath>C:\Program Files\rempl\sedsvc.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\rempl\sedsvc.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Description>sedsvc</Description>
<modulelist>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ff751430000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\rempl\sedsvc.exe</Path>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>sedsvc</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>57</ProcessIndex>
<ProcessId>7744</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081112364684</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; </CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x11330000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60900000</BaseAddress>
<Size>720896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\urlproc.dll</Path>
<Version>2, 9, 5, 1260</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x68b00000</BaseAddress>
<Size>44998656</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ce30000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6dc80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files (x86)\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6df70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\SysWOW64\shdocvw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e070000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e090000</BaseAddress>
<Size>233472</Size>
<Path>C:\Windows\SysWOW64\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e110000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e120000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multimedia Realtime Runtime</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e2a0000</BaseAddress>
<Size>4440064</Size>
<Path>C:\Windows\SysWOW64\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb60000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb70000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ec40000</BaseAddress>
<Size>442368</Size>
<Path>C:\Windows\SysWOW64\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd00000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd20000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe40000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe50000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SysWOW64\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ff90000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\SysWOW64\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ffe0000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\SysWOW64\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70190000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x701a0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\dllyupdate.dll</Path>
<Version>1.2.0.1831</Version>
<Company>Yandex LLC</Company>
<Description>Yandex updater (CU)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b30000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\WINUSB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows USB Driver User Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b60000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x711f0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>58</ProcessIndex>
<ProcessId>5696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081114193232</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe --type=crashpad-handler &quot;--user-data-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler &quot;--database=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data\Crashpad&quot; &quot;--metrics-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; --url=https://crash-reports.browser.yandex.net/submit --annotation=machine_id=c46245ef0fec9d5c44d2fa20241f2070 --annotation=main_process_pid=7744 --annotation=metrics_client_id=520f4dd3247d4cdfb744f32b1130b1bf --annotation=plat=Win32 --annotation=prod=Yandex --annotation=ver=18.6.1.770 --initial-client-data=0x1c4,0x1cc,0x1d0,0x1c0,0x1d4,0x700b800c,0x700b7ffc,0x700b7fe0,0x1c8</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>59</ProcessIndex>
<ProcessId>4664</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081123844756</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=gpu-process --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --service-request-channel-token=CC1AC8FA9C8EFF1EEBC2375FE4F704C6 --mojo-platform-channel-handle=1588 --ignored=&quot; --type=renderer &quot; /prefetch:2</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ecb0000</BaseAddress>
<Size>2228224</Size>
<Path>C:\Windows\SysWOW64\mfh264enc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation H264 Encoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f250000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\SysWOW64\ddraw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectDraw</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f340000</BaseAddress>
<Size>3784704</Size>
<Path>C:\Windows\SysWOW64\D3DCompiler_47.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D HLSL Compiler</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f6e0000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\SysWOW64\msvproc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Video Processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fbe0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\mf.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff20000</BaseAddress>
<Size>118784</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\swiftshader\libegl.dll</Path>
<Version>4.0.0.3</Version>
<Company></Company>
<Description>SwiftShader libEGL 32-bit Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dxva2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Video Acceleration 2.0 DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x705d0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\DCIMAN32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DCI Manager</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>60</ProcessIndex>
<ProcessId>8968</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081206363215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=183F52B8A6577BFD721F95F3A9641348 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=183F52B8A6577BFD721F95F3A9641348 --renderer-client-id=4 --mojo-platform-channel-handle=2640 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>61</ProcessIndex>
<ProcessId>4992</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081244357280</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=7E8A8199C364F4B0114F2A163B757250 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E8A8199C364F4B0114F2A163B757250 --renderer-client-id=10 --mojo-platform-channel-handle=3904 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>63</ProcessIndex>
<ProcessId>9504</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956266598229</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgent.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgent.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgent.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>InstallAgent</Description>
<modulelist>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ff63d380000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\InstallAgent.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffabea60000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\VEStoreEventHandlers.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDL Store Event Handlers</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4ad0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\EAMProgressHandler.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>EAMProgressHandler</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>64</ProcessIndex>
<ProcessId>8768</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956321853179</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgentUserBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgentUserBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgentUserBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>InstallAgentUserBroker</Description>
<modulelist>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x22530450000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ff74f890000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\InstallAgentUserBroker.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgentUserBroker</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>65</ProcessIndex>
<ProcessId>9636</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956424585250</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettingsBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\SystemSettingsBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\SystemSettingsBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>System Settings Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ff6015f0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\SystemSettingsBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Broker</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>66</ProcessIndex>
<ProcessId>10592</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956519902643</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettings.exe</ProcessName>
<ImagePath>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</ImagePath>
<CommandLine>&quot;C:\Windows\ImmersiveControlPanel\SystemSettings.exe&quot; -ServerName:microsoft.windows.immersivecontrolpanel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Параметры</Description>
<modulelist>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x18099ef0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\WMI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI DC and DP functionality</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ff7937a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaabce0000</BaseAddress>
<Size>2535424</Size>
<Path>C:\Windows\System32\NetworkMobileSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System settings network mobile handlers group</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac220000</BaseAddress>
<Size>4952064</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Application</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaadd90000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\NetworkDesktopSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Группа обработчиков системных параметров сетевого рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaaf920000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettingsViewModel.Desktop.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings View Model Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0970000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\credprovhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост инфраструктуры поставщика учетных данных</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0a70000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\System32\fhcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигураций истории файлов</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\SYSTEM32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\SYSTEM32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab91d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\ImmersiveControlPanel\Telemetry.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Telemetry Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcc60000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\System32\MiracastReceiver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API приемника Miracast</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2bf0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\EFSUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>EFS Utility Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\SYSTEM32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\wmiclnt.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca560000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\NcaApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Network Connectivity Assistant API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>67</ProcessIndex>
<ProcessId>10964</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794956837373387</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{BA126F01-2166-11D1-B1D0-00805FC1270E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\system32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>76</ProcessIndex>
<ProcessId>11496</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958406617238</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SearchUI.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe&quot; -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>Search and Cortana application</Description>
<modulelist>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ff79c3c0000</BaseAddress>
<Size>10706944</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Search and Cortana application</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\SYSTEM32\chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\SYSTEM32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4c70000</BaseAddress>
<Size>4874240</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab52c0000</BaseAddress>
<Size>2445312</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5840000</BaseAddress>
<Size>3108864</Size>
<Path>C:\Windows\System32\Speech_OneCore\Common\sapi_onecore.dll</Path>
<Version>5.3.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Speech API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5db0000</BaseAddress>
<Size>9781248</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9d50000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;CortanaApi.ProxyStub.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe770000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabefa0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\Cortana.Persona.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana.Persona</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac10b0000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\PersonaX.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PersonaX</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\SYSTEM32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3bf0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionMgr.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana Action Manager</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bb0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\windows.cortana.pal.desktop.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.PAL.Desktop</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7c50000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\BingConfigurationClient.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bing Configuration Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\SYSTEM32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780654647361</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>79</ProcessIndex>
<ProcessId>5612</ProcessId>
<ParentProcessId>904</ParentProcessId>
<ParentProcessIndex>22</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131794965205293998</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>dashost.exe</ProcessName>
<ImagePath>C:\Windows\system32\dashost.exe</ImagePath>
<CommandLine>dashost.exe {609e1ffd-7b4d-4dbc-a36f725917d81f2d}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Device Association Framework Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ff6559c0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\dashost.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Framework Provider Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabb1a0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\DAFWSD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF WSD Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabc970000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\dafupnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF UPnP Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>80</ProcessIndex>
<ProcessId>9720</ProcessId>
<ParentProcessId>9180</ParentProcessId>
<ParentProcessIndex>81</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794969418818027</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Windows10UpgraderApp.exe</ProcessName>
<ImagePath>C:\Windows10Upgrade\Windows10UpgraderApp.exe</ImagePath>
<CommandLine>&quot;C:\Windows10Upgrade\Windows10UpgraderApp.exe&quot;  /Install /ClientID Win10Upgrade:VNL:NHV18:{} /SkipEULA /PostEosUi</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>1.4.9200.22452</Version>
<Description>Помощник по обновлению Windows 10</Description>
<modulelist>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0xb30000</BaseAddress>
<Size>1875968</Size>
<Path>C:\Windows10Upgrade\Windows10UpgraderApp.exe</Path>
<Version>1.4.9200.22452</Version>
<Company>Microsoft Corporation</Company>
<Description>Помощник по обновлению Windows 10</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d6e0000</BaseAddress>
<Size>634880</Size>
<Path>C:\Windows\SysWOW64\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d780000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\SysWOW64\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d860000</BaseAddress>
<Size>1245184</Size>
<Path>C:\Windows\SysWOW64\MFC42u.dll</Path>
<Version>6.06.8063.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека MFCDLL - розничная версия</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6ded0000</BaseAddress>
<Size>630784</Size>
<Path>C:\Windows\SysWOW64\ODBC32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ODBC Driver Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfc0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfd0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SysWOW64\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e010000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows10Upgrade\Downloader.dll</Path>
<Version>1.4.9200.22452 (win8_ldr.180426-0600)</Version>
<Company>Microsoft Corporation</Company>
<Description>Downloader</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e050000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.DLL</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>82</ProcessIndex>
<ProcessId>8944</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795005508439638</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>fontdrvhost.exe</ProcessName>
<ImagePath>C:\Windows\system32\fontdrvhost.exe</ImagePath>
<CommandLine>&quot;fontdrvhost.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Usermode Font Driver Host</Description>
<modulelist>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ff654db0000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\system32\fontdrvhost.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Usermode Font Driver Host</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>83</ProcessIndex>
<ProcessId>6684</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795006053748558</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Microsoft.Photos.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe&quot; -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ff705e40000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bb10000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bc70000</BaseAddress>
<Size>3158016</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bf80000</BaseAddress>
<Size>2994176</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9c260000</BaseAddress>
<Size>20144128</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9d5a0000</BaseAddress>
<Size>29011968</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9fb20000</BaseAddress>
<Size>7950336</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.3_1.3.24201.0_x64__8wekyb3d8bbwe\SharedLibrary.dll</Path>
<Version></Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Shared Framework</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa03f0000</BaseAddress>
<Size>4546560</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\FaceSdkStoreWrapper.dll</Path>
<Version>16.425.0.0</Version>
<Company>Microsoft Corporation</Company>
<Description>FaceSdkStoreWrapper</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa0850000</BaseAddress>
<Size>2371584</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\MediaEngine.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab270000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\System32\Windows.AccountsControl.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Accounts Control</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\Windows.System.Diagnostics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Diagnostics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f60000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\CryptoWinRT.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto WinRT Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9270000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9b40000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x64__8wekyb3d8bbwe\mrt100_app.dll</Path>
<Version>1.4.24201.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabea30000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\Windows.Energy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Energy Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0fa0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1c70000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCOMP140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C/C++ OpenMP Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2c00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\clrcompression.dll</Path>
<Version>1.0.23123.00 built by: PROJECTKREL</Version>
<Company>Microsoft Corporation</Company>
<Description>ClrCompression</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SYSTEM32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\mrt100.dll</Path>
<Version>1.0.24120.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OleAut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>84</ProcessIndex>
<ProcessId>6208</ProcessId>
<ParentProcessId>12140</ParentProcessId>
<ParentProcessIndex>85</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795181740423780</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>OneDrive.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</ImagePath>
<CommandLine> /updateInstalled /background</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>18.131.0701.0007</Version>
<Description>Microsoft OneDrive</Description>
<modulelist>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x11f0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x55a0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSync.Resources.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\MSHTML.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6bab0000</BaseAddress>
<Size>4472832</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Widgets.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d210000</BaseAddress>
<Size>4993024</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Gui.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\Wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ce0000</BaseAddress>
<Size>1519616</Size>
<Path>C:\Windows\SysWOW64\wpc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека параметров родительского контроля</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70f00000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71200000</BaseAddress>
<Size>708608</Size>
<Path>C:\Windows\SysWOW64\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x712b0000</BaseAddress>
<Size>602112</Size>
<Path>C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71350000</BaseAddress>
<Size>2867200</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Quick.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71630000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x716b0000</BaseAddress>
<Size>1294336</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LIBEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x717f0000</BaseAddress>
<Size>2637824</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Qml.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71a80000</BaseAddress>
<Size>4796416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Core.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71f20000</BaseAddress>
<Size>6033408</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SyncEngine.DLL</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Sync Engine</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72530000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72550000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72810000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72820000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SysWOW64\MicrosoftAccountTokenProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Token Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72850000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\SysWOW64\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728b0000</BaseAddress>
<Size>135168</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncFAL.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDriveFile Sync FAL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\SysWOW64\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72bb0000</BaseAddress>
<Size>1105920</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\platforms\qwindows.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e90000</BaseAddress>
<Size>299008</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SSLEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ee0000</BaseAddress>
<Size>950272</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Network.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72fd0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\loadperf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Загрузка и выгрузка счетчиков производительности</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ff0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\pdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль поддержки данных производительности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73040000</BaseAddress>
<Size>253952</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5WinExtras.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73080000</BaseAddress>
<Size>880640</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ADAL.dll</Path>
<Version>1.0.2110.0526</Version>
<Company>Microsoft</Company>
<Description>ADAL.Native</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73160000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WSOCK32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73170000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SysWOW64\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x731d0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\WnsClientApi.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive WNS Client Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73240000</BaseAddress>
<Size>520192</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LogUploader.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive Sync LogUploader Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x732c0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncViews.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Qt Components</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73400000</BaseAddress>
<Size>159744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\UpdateRingSettings.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Ring Settings</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73430000</BaseAddress>
<Size>1748992</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncSessions.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>P2P Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x735e0000</BaseAddress>
<Size>671744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\RemoteAccess.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73690000</BaseAddress>
<Size>188416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Telemetry.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Telemetry Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ETWLog.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>ETW Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736d0000</BaseAddress>
<Size>3600384</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncClient.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Client</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73af0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LoggingPlatform.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Logging Platform</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73dc0000</BaseAddress>
<Size>1171456</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ucrtbase.dll</Path>
<Version>10.0.17134.12 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73fb0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\MSWSOCK.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74090000</BaseAddress>
<Size>462848</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\MSVCP140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\VCRUNTIME140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74220000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>86</ProcessIndex>
<ProcessId>6140</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795747339404666</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=764E64A4EA650A23B18EB059FF0B4B51 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=764E64A4EA650A23B18EB059FF0B4B51 --renderer-client-id=106 --mojo-platform-channel-handle=6612 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>87</ProcessIndex>
<ProcessId>11432</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755605761168</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=9DD318D38190D474A9A0F5AFD262A449 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=9DD318D38190D474A9A0F5AFD262A449 --renderer-client-id=109 --mojo-platform-channel-handle=4152 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>88</ProcessIndex>
<ProcessId>10384</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755746873891</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=7E669976FFDCEE94D9B90B02CADE1179 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E669976FFDCEE94D9B90B02CADE1179 --renderer-client-id=112 --mojo-platform-channel-handle=5412 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>90</ProcessIndex>
<ProcessId>6936</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795756360200321</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --renderer-client-id=116 --mojo-platform-channel-handle=4024 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>98</ProcessIndex>
<ProcessId>6080</ProcessId>
<ParentProcessId>84</ParentProcessId>
<ParentProcessIndex>97</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795771125310655</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MCLauncher.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe&quot; </CommandLine>
<CompanyName></CompanyName>
<Version>1.0</Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795771127806606</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>2830336</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Version>1.0</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771129292604</Timestamp>
<BaseAddress>0x750000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771335510731</Timestamp>
<BaseAddress>0x11000000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771334241016</Timestamp>
<BaseAddress>0x12000000</BaseAddress>
<Size>360448</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771129285523</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795771129286235</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795771129295328</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795771135408057</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795771129575672</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129398434</Timestamp>
<BaseAddress>0x66680000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771136825814</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795771129423112</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771129349562</Timestamp>
<BaseAddress>0x6b830000</BaseAddress>
<Size>2584576</Size>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795771329638947</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795771329610149</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795771329592759</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795771136045859</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795771131298623</Timestamp>
<BaseAddress>0x6d180000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795771136082794</Timestamp>
<BaseAddress>0x6dca0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Script Runtime</Description>
</module>
<module>
<Timestamp>131795771133718253</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795771129406131</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795771329618480</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795771329601483</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795771336447829</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771135435621</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795771135446667</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771136073867</Timestamp>
<BaseAddress>0x70e90000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Script Host Runtime Library</Description>
</module>
<module>
<Timestamp>131795771135423397</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795771135552456</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795771136181434</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771328759427</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771135541570</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795771347140137</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795771347110306</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795771135314174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771347090516</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795771347075776</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795771328179609</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795771130913562</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795771135359123</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795771129415027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795771130899582</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795771133098293</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795771132990161</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795771131765102</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795771129389543</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795771129317462</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795771129360685</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795771129360034</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771129496759</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795771129358136</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129357408</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795771129365891</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795771129359203</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795771129353720</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771135412052</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795771129350362</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795771129366695</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795771136054082</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795771131750596</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795771129363162</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795771328737550</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795771135228888</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795771129301509</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771129362062</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795771135227735</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795771129363985</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795771129356607</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795771129364960</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795771129354665</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795771129370252</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795771129352041</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795771129367584</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795771129351257</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771129361361</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795771129369244</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129368545</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795771131168008</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795771129352931</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771133704572</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795771129355632</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795771347076821</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795771127807387</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795771127807116</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>104</ProcessIndex>
<ProcessId>12696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777567759490</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=E83DB721798C8A70C76CD26F6F4EE1BC --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=E83DB721798C8A70C76CD26F6F4EE1BC --renderer-client-id=119 --mojo-platform-channel-handle=7052 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777567991690</Timestamp>
<BaseAddress>0xc00000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777567961139</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777569452751</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777567980184</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777567981270</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777567994943</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777570994535</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777570968696</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777570908362</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777570920904</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777570943637</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777570874151</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777570891841</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777568100773</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777570569484</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777570619251</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777570607590</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777570676211</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777570557202</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777570691164</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777570539079</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777569494420</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777570658737</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777569526517</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777569154123</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777570594964</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777570630821</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777570523174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777570582120</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777570646486</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777570953652</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777569213807</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777568156054</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777569481011</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777568142933</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777568179155</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777568043561</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777568042430</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777569239058</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777568075566</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777568073430</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777568086784</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777568041126</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777568081914</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777568046844</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777568038347</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777568088134</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777569468247</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777569466798</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777568077279</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777569469408</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777568024100</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777568039823</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777569470854</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777568036731</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777568054568</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777568078714</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777568050811</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777568084892</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777568089486</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777568083413</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777568044758</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777569464930</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777569463567</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777568116745</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777568080182</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777569457550</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777568052363</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777570632192</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777567961904</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777567961630</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>106</ProcessIndex>
<ProcessId>5556</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777595302537</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=3ADFA2396247AD5E547F61590603D06D --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=3ADFA2396247AD5E547F61590603D06D --renderer-client-id=121 --mojo-platform-channel-handle=6636 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777595490187</Timestamp>
<BaseAddress>0x1020000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595475498</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595491301</Timestamp>
<BaseAddress>0x5550000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777596381097</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595481485</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777595482474</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777595494304</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777597543015</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777597521210</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777597472595</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777597484525</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777597497517</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777597428793</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777597448444</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777595565558</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777597103476</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777597165296</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777597153510</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777597221087</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777597072535</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777597233493</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777597059294</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777596424202</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777597205195</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777596436120</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777596128973</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777597128037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777597177209</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777597044137</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777597116160</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777597192860</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777597506812</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777596148547</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777595627397</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777596410831</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777595610560</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777595638942</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777595529014</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777595527983</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777596182171</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777595541526</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777595540326</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777595551866</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777595526606</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777595547732</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777595531563</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777595524005</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777595553384</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777596396507</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777596394953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777595543299</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777596397607</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777595508927</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595525398</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777596398892</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777595522182</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777595538927</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777595544568</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777595535397</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777595550455</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777595554628</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777595549128</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777595530150</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777596393437</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777596392132</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777595583766</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777595545878</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777596385979</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777595536930</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777597178434</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777595476066</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777595475814</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>111</ProcessIndex>
<ProcessId>9032</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777895284069</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>explorer.exe</ProcessName>
<ImagePath>C:\Windows\explorer.exe</ImagePath>
<CommandLine>C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795777911330291</Timestamp>
<BaseAddress>0x4d80000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795777920515787</Timestamp>
<BaseAddress>0x6530000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\Microsoft Office\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795777903881315</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795777903867506</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795777895813346</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\explorer.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795777906005639</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\duser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795777922060868</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795777918507242</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795777907532495</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\System32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795777910997447</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795777915260331</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795777910978745</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\System32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795778008622616</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795778007235790</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\devrtl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795777909146457</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795777902950088</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\System32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795778007048279</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795777902932644</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795777909802797</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777909791020</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777917395017</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\linkinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795777918158137</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795777966565943</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795777908125051</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795777905900322</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\dui70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795777908270107</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795777922014669</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\System32\networkexplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795778007216762</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795777919764442</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795777915281766</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795777909775471</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795777910387599</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795777905243222</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795777919412503</Timestamp>
<BaseAddress>0x7ffac1710000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\amd64\FileSyncShell64.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795777904716802</Timestamp>
<BaseAddress>0x7ffac18b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg64.dll</Path>
<Version>1, 0, 0, 1140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795777944562485</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795777903915791</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777922001525</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795777903903305</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777909321798</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777909330655</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777906462233</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795777910949757</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795777920555307</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795777906356495</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795777905097743</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\System32\ExplorerFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795777908567233</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795777911007559</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795777914831974</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795777905390625</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777902894862</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795777906986296</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795777906995835</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795777903975733</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795777906257948</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795777919424461</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795777902880674</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777908138610</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795777902921260</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778008641775</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795777907005063</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795777918659102</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777918649579</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777909306748</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795777902905939</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795777906474194</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902941219</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795778008632518</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795777918171528</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795777907014508</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777903933947</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777902985171</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777903008375</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777902974089</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777905657867</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795777902999880</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777902852334</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777902849489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777902853126</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777902855116</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777902843222</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777902836309</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902838974</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777902841617</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777902844144</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777902848566</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777902824318</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777902854301</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777902835470</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902847555</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777902846521</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777902834719</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777916996283</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795777902838016</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777902833378</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777904879129</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777902823359</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777905449820</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795777920556415</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795777902842396</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777903888252</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777903413262</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777902840664</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777902837229</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777903887407</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795777902850328</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777903886124</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777902845086</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777902851375</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777895813598</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>144</ProcessIndex>
<ProcessId>12892</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780695167004</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Wireshark.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\Wireshark.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\Wireshark.exe&quot; </CommandLine>
<CompanyName>The Wireshark developer community, http://www.wireshark.org/</CompanyName>
<Version>2.6.2</Version>
<Description>Wireshark</Description>
<modulelist>
<module>
<Timestamp>131795780706141890</Timestamp>
<BaseAddress>0xbd0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\libwinpthread-1.dll</Path>
<Version>1, 0, 0, 0</Version>
<Company>MingW-W64 Project. All rights reserved.</Company>
<Description>POSIX WinThreads for Windows</Description>
</module>
<module>
<Timestamp>131795780721765742</Timestamp>
<BaseAddress>0xbf0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\k5sprt64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>Kerberos v5 support - internal support code for MIT Kerberos v5 /GSS distribution</Description>
</module>
<module>
<Timestamp>131795780722106261</Timestamp>
<BaseAddress>0xc00000</BaseAddress>
<Size>45056</Size>
<Path>C:\Program Files\Wireshark\comerr64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>COM_ERR - Common Error Handler for MIT Kerberos v5 / GSS distribution</Description>
</module>
<module>
<Timestamp>131795780719731475</Timestamp>
<BaseAddress>0x1c000000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\krb5_64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>Kerberos v5 - MIT GSS / Kerberos v5 distribution</Description>
</module>
<module>
<Timestamp>131795780773060331</Timestamp>
<BaseAddress>0x5af30000</BaseAddress>
<Size>348160</Size>
<Path>C:\Program Files\Wireshark\Qt5Svg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780721210805</Timestamp>
<BaseAddress>0x5af90000</BaseAddress>
<Size>1286144</Size>
<Path>C:\Program Files\Wireshark\libxml2-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780696840198</Timestamp>
<BaseAddress>0x5b0d0000</BaseAddress>
<Size>5865472</Size>
<Path>C:\Program Files\Wireshark\Qt5Core.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780696801039</Timestamp>
<BaseAddress>0x5b670000</BaseAddress>
<Size>5619712</Size>
<Path>C:\Program Files\Wireshark\Qt5Widgets.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780721068755</Timestamp>
<BaseAddress>0x5bcf0000</BaseAddress>
<Size>733184</Size>
<Path>C:\Program Files\Wireshark\libsmi-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720701584</Timestamp>
<BaseAddress>0x5bdb0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Program Files\Wireshark\liblz4.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720048995</Timestamp>
<BaseAddress>0x5bdf0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Program Files\Wireshark\libcares-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780701085625</Timestamp>
<BaseAddress>0x5be10000</BaseAddress>
<Size>122880</Size>
<Path>C:\Program Files\Wireshark\libbcg729.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700086118</Timestamp>
<BaseAddress>0x5be30000</BaseAddress>
<Size>1261568</Size>
<Path>C:\Program Files\Wireshark\Qt5Network.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780701499544</Timestamp>
<BaseAddress>0x61cc0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Wireshark\libintl-8.dll</Path>
<Version>0.18.1</Version>
<Company>Free Software Foundation</Company>
<Description>LGPLed libintl for Windows NT/2000/XP/Vista/7 and Windows 95/98/ME</Description>
</module>
<module>
<Timestamp>131795780704834900</Timestamp>
<BaseAddress>0x646c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libgpg-error6-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780703191110</Timestamp>
<BaseAddress>0x64840000</BaseAddress>
<Size>1220608</Size>
<Path>C:\Program Files\Wireshark\libgnutls-30.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720700188</Timestamp>
<BaseAddress>0x64a00000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\lua52.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780702785552</Timestamp>
<BaseAddress>0x653c0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\libgcrypt-20.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780706408972</Timestamp>
<BaseAddress>0x65f00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Program Files\Wireshark\libtasn1-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705520711</Timestamp>
<BaseAddress>0x66f00000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Wireshark\libhogweed-4-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780696518462</Timestamp>
<BaseAddress>0x685c0000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Program Files\Wireshark\libglib-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GLib</Description>
</module>
<module>
<Timestamp>131795780706610973</Timestamp>
<BaseAddress>0x68ec0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\Wireshark\libp11-kit-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720967901</Timestamp>
<BaseAddress>0x69340000</BaseAddress>
<Size>815104</Size>
<Path>C:\Program Files\Wireshark\libsnappy-1.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705423287</Timestamp>
<BaseAddress>0x69c80000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\libnettle-6-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700701891</Timestamp>
<BaseAddress>0x6a680000</BaseAddress>
<Size>122880</Size>
<Path>C:\Program Files\Wireshark\libsbc-1.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705248323</Timestamp>
<BaseAddress>0x6acc0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files\Wireshark\libgmp-10.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780707311684</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\libffi-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700957949</Timestamp>
<BaseAddress>0x6d7c0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files\Wireshark\libspandsp-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720746780</Timestamp>
<BaseAddress>0x6dc80000</BaseAddress>
<Size>167936</Size>
<Path>C:\Program Files\Wireshark\libnghttp2-14.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780698864675</Timestamp>
<BaseAddress>0x6dd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\Wireshark\libgmodule-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GModule</Description>
</module>
<module>
<Timestamp>131795780759720376</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\wpcap.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008)</Description>
</module>
<module>
<Timestamp>131795780760417804</Timestamp>
<BaseAddress>0x190ac770000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795780695991379</Timestamp>
<BaseAddress>0x7ff7f1130000</BaseAddress>
<Size>8298496</Size>
<Path>C:\Program Files\Wireshark\Wireshark.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark</Description>
</module>
<module>
<Timestamp>131795780718751145</Timestamp>
<BaseAddress>0x7ffaa6f50000</BaseAddress>
<Size>64282624</Size>
<Path>C:\Program Files\Wireshark\libwireshark.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark dissector library</Description>
</module>
<module>
<Timestamp>131795780697272337</Timestamp>
<BaseAddress>0x7ffaaaca0000</BaseAddress>
<Size>6094848</Size>
<Path>C:\Program Files\Wireshark\Qt5Gui.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896758694</Timestamp>
<BaseAddress>0x7ffab1e90000</BaseAddress>
<Size>593920</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimax.dll</Path>
<Version>1.2.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimax dissector</Description>
</module>
<module>
<Timestamp>131795780766458881</Timestamp>
<BaseAddress>0x7ffab1f30000</BaseAddress>
<Size>614400</Size>
<Path>C:\Windows\System32\riched20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795780699399720</Timestamp>
<BaseAddress>0x7ffab2280000</BaseAddress>
<Size>1916928</Size>
<Path>C:\Program Files\Wireshark\WinSparkle.dll</Path>
<Version>0.5.7</Version>
<Company>winsparkle.org</Company>
<Description>WinSparkle updater</Description>
</module>
<module>
<Timestamp>131795780771263589</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795780765326722</Timestamp>
<BaseAddress>0x7ffab9010000</BaseAddress>
<Size>1388544</Size>
<Path>C:\Program Files\Wireshark\platforms\qwindows.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896746168</Timestamp>
<BaseAddress>0x7ffab9b10000</BaseAddress>
<Size>135168</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\unistim.dll</Path>
<Version>0.0.2.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>unistim dissector</Description>
</module>
<module>
<Timestamp>131795780896708383</Timestamp>
<BaseAddress>0x7ffabaef0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\profinet.dll</Path>
<Version>0.2.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>profinet dissector</Description>
</module>
<module>
<Timestamp>131795780773615377</Timestamp>
<BaseAddress>0x7ffabb070000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files\Wireshark\imageformats\qwebp.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780702318544</Timestamp>
<BaseAddress>0x7ffabb0f0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780773096445</Timestamp>
<BaseAddress>0x7ffabb250000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files\Wireshark\imageformats\qtiff.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896696149</Timestamp>
<BaseAddress>0x7ffabc110000</BaseAddress>
<Size>237568</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\opcua.dll</Path>
<Version>1.0.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>opcua dissector</Description>
</module>
<module>
<Timestamp>131795780696290907</Timestamp>
<BaseAddress>0x7ffabc150000</BaseAddress>
<Size>729088</Size>
<Path>C:\Program Files\Wireshark\Qt5Multimedia.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780699299849</Timestamp>
<BaseAddress>0x7ffabcbb0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Program Files\Wireshark\libwiretap.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark capture file library</Description>
</module>
<module>
<Timestamp>131795780702235327</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795780699512168</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795780773039075</Timestamp>
<BaseAddress>0x7ffabe940000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\imageformats\qjpeg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896684027</Timestamp>
<BaseAddress>0x7ffabeb80000</BaseAddress>
<Size>163840</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\mate.dll</Path>
<Version>1.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>mate dissector</Description>
</module>
<module>
<Timestamp>131795780767100288</Timestamp>
<BaseAddress>0x7ffabebb0000</BaseAddress>
<Size>233472</Size>
<Path>C:\Windows\System32\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795780967804060</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795780703722010</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780896660120</Timestamp>
<BaseAddress>0x7ffabf990000</BaseAddress>
<Size>135168</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\gryphon.dll</Path>
<Version>0.0.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>gryphon dissector</Description>
</module>
<module>
<Timestamp>131795781117544658</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\NapiNSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795781117680972</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795780896781202</Timestamp>
<BaseAddress>0x7ffabff40000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimaxmacphy.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimaxmacphy dissector</Description>
</module>
<module>
<Timestamp>131795780975772674</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795781117813782</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795780967709675</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780896602379</Timestamp>
<BaseAddress>0x7ffac0b10000</BaseAddress>
<Size>180224</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\ethercat.dll</Path>
<Version>0.1.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>ethercat dissector</Description>
</module>
<module>
<Timestamp>131795780696305369</Timestamp>
<BaseAddress>0x7ffac12f0000</BaseAddress>
<Size>585728</Size>
<Path>C:\Program Files\Wireshark\Qt5WinExtras.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780696268510</Timestamp>
<BaseAddress>0x7ffac1380000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files\Wireshark\Qt5PrintSupport.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896769846</Timestamp>
<BaseAddress>0x7ffac1640000</BaseAddress>
<Size>81920</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimaxasncp.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimaxasncp dissector</Description>
</module>
<module>
<Timestamp>131795780703633136</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\zlib1.dll</Path>
<Version>1.2.11</Version>
<Company></Company>
<Description>zlib data compression library</Description>
</module>
<module>
<Timestamp>131795780968289847</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795780896672499</Timestamp>
<BaseAddress>0x7ffac21f0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\irda.dll</Path>
<Version>0.0.6.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>irda dissector</Description>
</module>
<module>
<Timestamp>131795780943468609</Timestamp>
<BaseAddress>0x7ffac2950000</BaseAddress>
<Size>32768</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\codecs\l16mono.dll</Path>
<Version>0.1.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>l16mono dissector</Description>
</module>
<module>
<Timestamp>131795780696778265</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780698025500</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libwsutil.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark utility library</Description>
</module>
<module>
<Timestamp>131795780964290332</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780896734845</Timestamp>
<BaseAddress>0x7ffac3730000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\transum.dll</Path>
<Version>2.0.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>transum dissector</Description>
</module>
<module>
<Timestamp>131795780962958391</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780891504201</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795780896719593</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\stats_tree.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>stats_tree dissector</Description>
</module>
<module>
<Timestamp>131795780893701095</Timestamp>
<BaseAddress>0x7ffac4c50000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\wiretap\usbdump.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>usbdump dissector</Description>
</module>
<module>
<Timestamp>131795780891269455</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795780965552062</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795780963571749</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795780963646684</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795780773109195</Timestamp>
<BaseAddress>0x7ffac6aa0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qwbmp.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773083338</Timestamp>
<BaseAddress>0x7ffac6ab0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qtga.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780700311672</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780700270884</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780773051219</Timestamp>
<BaseAddress>0x7ffac7710000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qsvg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773027062</Timestamp>
<BaseAddress>0x7ffac7c70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\imageformats\qico.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773014999</Timestamp>
<BaseAddress>0x7ffac7cc0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files\Wireshark\imageformats\qicns.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773002354</Timestamp>
<BaseAddress>0x7ffac7e80000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\imageformats\qgif.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780968266724</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795780968255503</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795780966275544</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795780892525330</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795780963686201</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795780892534590</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795781117718740</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795780698877286</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wsock32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795780891204535</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795780696645603</Timestamp>
<BaseAddress>0x7ffaca540000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\libwscodecs.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark codecs library</Description>
</module>
<module>
<Timestamp>131795780700298298</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780892543743</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795780766486586</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795780704258643</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795780702045466</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795780946467813</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795780696789076</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780891516231</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795780892568770</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795780892552823</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795780966945740</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795780735395573</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795780967734879</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795780699490686</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780703368899</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795780963669913</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795780735383654</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780725077080</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780735352973</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780735341669</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780963187802</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780703358385</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780696324267</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780696320774</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780696326027</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780700094061</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780696281753</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780696314418</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780696011047</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780967736295</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795780696325096</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780696319762</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780696000095</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780700093105</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780700405929</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780696318427</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780719380090</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795780696316518</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780700405056</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780696313332</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780703813608</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795780696317482</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780891250440</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780695999112</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780892432004</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795780696011842</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780696829366</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780722304611</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780696010125</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780696013618</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795780696312465</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780696321680</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780696311589</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780696323259</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780696315318</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780695991736</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>154</ProcessIndex>
<ProcessId>10368</ProcessId>
<ParentProcessId>12892</ParentProcessId>
<ParentProcessIndex>144</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795781110701520</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>dumpcap.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\dumpcap.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\dumpcap.exe&quot; -n -i \Device\NPF_{8742EB38-E176-4D94-AB83-DB4440CD90E6} -y EN10MB -Z 12892</CommandLine>
<CompanyName>The Wireshark developer community</CompanyName>
<Version>2.6.2</Version>
<Description>Dumpcap</Description>
<modulelist>
<module>
<Timestamp>131795781112729961</Timestamp>
<BaseAddress>0xe30000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\libwinpthread-1.dll</Path>
<Version>1, 0, 0, 0</Version>
<Company>MingW-W64 Project. All rights reserved.</Company>
<Description>POSIX WinThreads for Windows</Description>
</module>
<module>
<Timestamp>131795781112668516</Timestamp>
<BaseAddress>0x61cc0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Wireshark\libintl-8.dll</Path>
<Version>0.18.1</Version>
<Company>Free Software Foundation</Company>
<Description>LGPLed libintl for Windows NT/2000/XP/Vista/7 and Windows 95/98/ME</Description>
</module>
<module>
<Timestamp>131795781112689838</Timestamp>
<BaseAddress>0x646c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libgpg-error6-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112636826</Timestamp>
<BaseAddress>0x64840000</BaseAddress>
<Size>1220608</Size>
<Path>C:\Program Files\Wireshark\libgnutls-30.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112629190</Timestamp>
<BaseAddress>0x653c0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\libgcrypt-20.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112737406</Timestamp>
<BaseAddress>0x65f00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Program Files\Wireshark\libtasn1-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112705672</Timestamp>
<BaseAddress>0x66f00000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Wireshark\libhogweed-4-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112573973</Timestamp>
<BaseAddress>0x685c0000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Program Files\Wireshark\libglib-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GLib</Description>
</module>
<module>
<Timestamp>131795781112722622</Timestamp>
<BaseAddress>0x68ec0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\Wireshark\libp11-kit-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112715396</Timestamp>
<BaseAddress>0x69c80000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\libnettle-6-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112698255</Timestamp>
<BaseAddress>0x6acc0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files\Wireshark\libgmp-10.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112775160</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\libffi-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112582576</Timestamp>
<BaseAddress>0x6dd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\Wireshark\libgmodule-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GModule</Description>
</module>
<module>
<Timestamp>131795781112962306</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\wpcap.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008)</Description>
</module>
<module>
<Timestamp>131795781112975613</Timestamp>
<BaseAddress>0x2203d070000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795781110777700</Timestamp>
<BaseAddress>0x7ff79b530000</BaseAddress>
<Size>438272</Size>
<Path>C:\Program Files\Wireshark\dumpcap.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community</Company>
<Description>Dumpcap</Description>
</module>
<module>
<Timestamp>131795781112745027</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\zlib1.dll</Path>
<Version>1.2.11</Version>
<Company></Company>
<Description>zlib data compression library</Description>
</module>
<module>
<Timestamp>131795781112991873</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795781112551689</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libwsutil.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark utility library</Description>
</module>
<module>
<Timestamp>131795781112616429</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781113081556</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795781113068402</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795781112593287</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wsock32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795781112764136</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795781112680590</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795781112901553</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795781112603842</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795781112889933</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795781112922216</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795781112873689</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795781112851456</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795781112862535</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795781112564185</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795781112558680</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795781112565891</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795781112638400</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795781112561378</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781112543433</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781112557787</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795781112563121</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795781112564994</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795781112555945</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795781111306780</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781112637496</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795781112554892</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795781112553795</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795781112541505</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795781113056743</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795781112539956</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795781111305815</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781112560555</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781112552568</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795781112797169</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795781112562317</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795781112556862</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795781112538759</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795781112574716</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795781112559630</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795781112540782</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795781110778043</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>155</ProcessIndex>
<ProcessId>10656</ProcessId>
<ParentProcessId>10368</ParentProcessId>
<ParentProcessIndex>154</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795781111864203</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Conhost.exe</ProcessName>
<ImagePath>C:\Windows\System32\Conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795781111913743</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795781111943590</Timestamp>
<BaseAddress>0x7ffac16b0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795781112487631</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795781111973094</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795781112447250</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795781112288506</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795781112268292</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795781112265698</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795781112269042</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795781111955891</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781111952093</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781111953761</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795781111957462</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795781111974737</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795781112264787</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795781111919763</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781111959779</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781112263740</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795781112262565</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795781111959111</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795781111952833</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795781111927637</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795781111918688</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781112429009</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795781111954501</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781111958338</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795781111956778</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795781111951234</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795781112266518</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795781112267424</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795781111973936</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795781111913976</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>162</ProcessIndex>
<ProcessId>4760</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786042098193</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MicrosoftEdge.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe&quot; -ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Microsoft Edge</Description>
<modulelist>
<module>
<Timestamp>131795786042630177</Timestamp>
<BaseAddress>0x7ff782940000</BaseAddress>
<Size>7663616</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786057154585</Timestamp>
<BaseAddress>0x7ffaad380000</BaseAddress>
<Size>5730304</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\eView.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge View</Description>
</module>
<module>
<Timestamp>131795786054805787</Timestamp>
<BaseAddress>0x7ffaad900000</BaseAddress>
<Size>4730880</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\eModel.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Model</Description>
</module>
<module>
<Timestamp>131795786066907553</Timestamp>
<BaseAddress>0x7ffab0430000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\System32\ieapfltr.dll</Path>
<Version>11.00.14393.2189</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SmartScreen Filter</Description>
</module>
<module>
<Timestamp>131795786128228596</Timestamp>
<BaseAddress>0x7ffab1df0000</BaseAddress>
<Size>602112</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\eData.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Data Store API Module</Description>
</module>
<module>
<Timestamp>131795786065479748</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\System32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795786063895095</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795786054266392</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795786230757616</Timestamp>
<BaseAddress>0x7ffab8fd0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\MicrosoftAccountTokenProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Token Provider</Description>
</module>
<module>
<Timestamp>131795786063975264</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786144818989</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795786059649322</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795786067415829</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786288759665</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786288473868</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795786288676720</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795786065177710</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795786066322832</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795786072876141</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795786088399099</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795786065841979</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795786055069007</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786147341523</Timestamp>
<BaseAddress>0x7ffabd220000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\Windows.Devices.Enumeration.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Enumeration</Description>
</module>
<module>
<Timestamp>131795786063327247</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795786125346246</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795786068479711</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\System32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795786065629245</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795786100800557</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795786057138366</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795786088259759</Timestamp>
<BaseAddress>0x7ffabf090000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform Diagnostics and Usage Settings DLL</Description>
</module>
<module>
<Timestamp>131795786241271463</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786064506043</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786066155936</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795786063962359</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795786069984086</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795786241104861</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786059637885</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\System32\Windows.UI.Core.TextInput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795786053932620</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795786241083669</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786056074983</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786100125856</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786075280874</Timestamp>
<BaseAddress>0x7ffac15d0000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Core.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Model Core API</Description>
</module>
<module>
<Timestamp>131795786070406699</Timestamp>
<BaseAddress>0x7ffac1600000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\mdmregistration.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>MDM Registration DLL</Description>
</module>
<module>
<Timestamp>131795786062579941</Timestamp>
<BaseAddress>0x7ffac1940000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Windows.System.Profile.RetailInfo.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Profile.RetailInfo Runtime DLL</Description>
</module>
<module>
<Timestamp>131795786070419915</Timestamp>
<BaseAddress>0x7ffac1f10000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\dmcmnutils.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmcmnutils</Description>
</module>
<module>
<Timestamp>131795786068039488</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795786089075107</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786065677921</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795786065270981</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786128841302</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\esent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795786054294330</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786063368609</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786202359997</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795786200068117</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795786055042484</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\eShims.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Compatibility Shims</Description>
</module>
<module>
<Timestamp>131795786089712128</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795786059830786</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795786150797625</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\System32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795786453454285</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\System32\UIAutomationCore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795786067621067</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786092263039</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786147367807</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795786065223183</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786147382918</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795786065248448</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786055777229</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795786453657664</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795786057001398</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795786057773467</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795786060164250</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786068353332</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795786070260699</Timestamp>
<BaseAddress>0x7ffac79e0000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\System32\netjoin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL присоединения к домену</Description>
</module>
<module>
<Timestamp>131795786066493970</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795786056922456</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\System32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795786092912724</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786060129754</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795786065322940</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786056749751</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795786070245572</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786054670572</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786056291342</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\System32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795786068265491</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795786082912516</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795786063291141</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786054280400</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786056308035</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786054309397</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795786060143604</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795786053885709</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795786056099190</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786063385911</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786054634364</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786064476035</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795786056663398</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795786070433601</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\devobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795786054821679</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786064343854</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795786741705319</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795786056649628</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795786240387843</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786241189729</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786241130378</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786065234326</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786070099854</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786070392550</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786055055520</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786065299260</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786067045090</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786061034021</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786070369175</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\joinutil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795786070463748</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786070448934</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786064523489</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786054651608</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786054249334</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786054809092</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786054683095</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786057003667</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795786053916113</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786053913423</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786053914306</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786053917903</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786241132060</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786054295713</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786054808089</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786053867639</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786057002708</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786053934160</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786054810350</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786072535568</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786053933393</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786070371970</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795786053910705</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786065324109</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786053908868</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786053866675</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786058760529</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795786053915276</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786065183195</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786053988560</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786053916977</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786053912669</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786053907976</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786053911866</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786054806876</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786053909990</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786042630465</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>163</ProcessIndex>
<ProcessId>11628</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786060723216</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser_broker.exe</ProcessName>
<ImagePath>C:\Windows\system32\browser_broker.exe</ImagePath>
<CommandLine>C:\Windows\system32\browser_broker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.1613 (rs1_release_d.170807-1806)</Version>
<Description>Browser_Broker</Description>
<modulelist>
<module>
<Timestamp>131795786060746750</Timestamp>
<BaseAddress>0x7ff7b0a20000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\browser_broker.exe</Path>
<Version>11.00.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>Browser_Broker</Description>
</module>
<module>
<Timestamp>131795786168836722</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786168862865</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786168827250</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\System32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786282574098</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786062630515</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786377997340</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786062639680</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786379114346</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786377416821</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786174396342</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786063237345</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786062620047</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786062594364</Timestamp>
<BaseAddress>0x7ffac37b0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\browserbroker.dll</Path>
<Version>11.00.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>BrowserBroker</Description>
</module>
<module>
<Timestamp>131795786062611592</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786373086635</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786062648299</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786374469208</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786169923245</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786169944900</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786375051635</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786170132533</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786168854180</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786372529204</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786060981181</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786373096703</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786062656563</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786376235194</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786377463635</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786062672588</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786169932479</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786372992934</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786282563295</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786170115721</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786168845591</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786377475058</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786377435415</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786377426421</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786065020552</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786168896935</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786060963845</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786065028759</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786065029803</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786062602748</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795786060771823</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786060765038</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786060766797</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786060769366</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786377447217</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786062597872</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786065027623</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786060754491</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786062601823</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786062599820</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786174124589</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786174123329</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786062599041</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786060765825</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786170133242</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786060762708</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786062743817</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786060753543</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786060770964</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786169882199</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786060799279</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786060768413</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786060764068</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786062600875</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786063238473</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786062621206</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786060767532</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786060746988</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>164</ProcessIndex>
<ProcessId>9260</ProcessId>
<ParentProcessId>3632</ParentProcessId>
<ParentProcessIndex>38</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786076559956</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>microsoftedgecp.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe&quot; SCODEF:4760 CREDAT:140545 /prefetch:2</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Microsoft Edge Content Process</Description>
<modulelist>
<module>
<Timestamp>131795786082343149</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786082139934</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786076857473</Timestamp>
<BaseAddress>0x7ff6405a0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content Process</Description>
</module>
<module>
<Timestamp>131795786340825586</Timestamp>
<BaseAddress>0x7ffaa65e0000</BaseAddress>
<Size>4526080</Size>
<Path>C:\Windows\System32\D3DCompiler_47.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D HLSL Compiler</Description>
</module>
<module>
<Timestamp>131795786083247759</Timestamp>
<BaseAddress>0x7ffaafb30000</BaseAddress>
<Size>3379200</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\EdgeContent.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content</Description>
</module>
<module>
<Timestamp>131795786086088180</Timestamp>
<BaseAddress>0x7ffab0430000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\System32\ieapfltr.dll</Path>
<Version>11.00.14393.2189</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SmartScreen Filter</Description>
</module>
<module>
<Timestamp>131795786159084433</Timestamp>
<BaseAddress>0x7ffab0d50000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795786202624192</Timestamp>
<BaseAddress>0x7ffab2230000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\elshyph.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ELS Hyphenation Service</Description>
</module>
<module>
<Timestamp>131795786084579233</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786084609324</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786084567131</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\System32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786088444599</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795786084123182</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786160557742</Timestamp>
<BaseAddress>0x7ffababa0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\icm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Color Management Module (CMM)</Description>
</module>
<module>
<Timestamp>131795786082878183</Timestamp>
<BaseAddress>0x7ffababf0000</BaseAddress>
<Size>806912</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe64.dll</Path>
<Version>1, 0, 0, 1150</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786390382274</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795786086580284</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786085595890</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795786083370196</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786137282976</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795786244144116</Timestamp>
<BaseAddress>0x7ffabe110000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\imgutil.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE plugin image decoder support DLL</Description>
</module>
<module>
<Timestamp>131795786154004846</Timestamp>
<BaseAddress>0x7ffabe530000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\WindowsCodecsExt.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Extended Library</Description>
</module>
<module>
<Timestamp>131795786089791507</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\System32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795786155347443</Timestamp>
<BaseAddress>0x7ffabe830000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\smartscreenps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreenPS</Description>
</module>
<module>
<Timestamp>131795786389154702</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795786114772856</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786296880485</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795786085297567</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786112051091</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786107069509</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786241015463</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786083065977</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>126976</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N64.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795786100196624</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786271419198</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795786086130048</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795786082410441</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786087301397</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795786082393485</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786086032569</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786321446812</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795786282318342</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795786082097229</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786085965984</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786083356981</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\eShims.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Compatibility Shims</Description>
</module>
<module>
<Timestamp>131795786210171775</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786104739299</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786085635138</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786085676901</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786089609753</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795786087107447</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795786088421856</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795786092153446</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795786100849928</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786089750406</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795786088584854</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\System32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795786270943858</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795786270495097</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795786104726596</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786086442135</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795786085717720</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786086457038</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795786082439684</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786084597848</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786184150347</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795786141307846</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795786240298598</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786092224838</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786086057183</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786089629599</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795786086481184</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795786082048569</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795786084078182</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786086008568</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786083279286</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786088520571</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795786083257346</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786086544984</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795786105438151</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786098058671</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786098091830</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786085647065</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786093150053</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786082425895</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786083270628</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786085695835</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786084588700</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786098076226</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786112038692</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786112026610</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786085316210</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786082453168</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786082355351</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786082352777</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786082356404</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786082346599</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786082076458</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786082077405</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786082344914</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786082078287</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786082074829</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786082351486</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786082030503</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786082079752</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786082360385</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786082350101</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786082348521</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786082359321</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786082073607</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786085718659</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786082071659</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786082029525</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786086063062</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795786082345765</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786082362660</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786082465073</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786082343975</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786082075682</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786082361662</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795786082070778</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786082357670</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786082354079</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786082072862</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786076857714</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>165</ProcessIndex>
<ProcessId>9716</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786078382267</CreateTime>
<FinishTime>131795786679713103</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>backgroundTaskHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\backgroundTaskHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\backgroundTaskHost.exe&quot; -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Background Task Host</Description>
<modulelist>
<module>
<Timestamp>131795786078418454</Timestamp>
<BaseAddress>0x7ff6c9470000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\backgroundTaskHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Task Host</Description>
</module>
<module>
<Timestamp>131795786443106818</Timestamp>
<BaseAddress>0x7ffaa63b0000</BaseAddress>
<Size>2260992</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentManagementSDK.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795786178014437</Timestamp>
<BaseAddress>0x7ffaadde0000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentDeliveryManager.Background.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795786446836026</Timestamp>
<BaseAddress>0x7ffab8f60000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\CryptoWinRT.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto WinRT Library</Description>
</module>
<module>
<Timestamp>131795786452519637</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786442096938</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795786184454951</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795786411124347</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795786447511170</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795786446350687</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795786178082701</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795786448549221</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795786087899215</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786439664619</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786178119779</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786438702275</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795786138262787</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795786087656774</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795786087636053</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795786178883132</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795786138319065</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786178060788</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\slc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795786564018964</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795786424168262</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795786085105196</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786630053916</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795786444935300</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786135208275</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786135908983</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786178148521</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786078586397</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786178071668</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795786675912834</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786448305262</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786447500168</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786447396943</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786178048432</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786085085167</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786078572417</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786444912775</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786087643960</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786087150180</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786078435842</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786078437510</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786087148614</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786085110036</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786444911600</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786078425607</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786178085269</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786178083562</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786078436568</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786078433692</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786078424455</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786087149421</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786087182640</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786087147697</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786078435030</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786178015977</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786444913925</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786078587414</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786078418747</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>166</ProcessIndex>
<ProcessId>10548</ProcessId>
<ParentProcessId>3632</ParentProcessId>
<ParentProcessIndex>38</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786089162133</CreateTime>
<FinishTime>131795786943874336</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>microsoftedgecp.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe&quot; SCODEF:4760 CREDAT:140546 /prefetch:2</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Microsoft Edge Content Process</Description>
<modulelist>
<module>
<Timestamp>131795786091222895</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786090902666</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786089403507</Timestamp>
<BaseAddress>0x7ff6405a0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content Process</Description>
</module>
<module>
<Timestamp>131795786093276149</Timestamp>
<BaseAddress>0x7ffaafb30000</BaseAddress>
<Size>3379200</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\EdgeContent.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content</Description>
</module>
<module>
<Timestamp>131795786097059549</Timestamp>
<BaseAddress>0x7ffab0430000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\System32\ieapfltr.dll</Path>
<Version>11.00.14393.2189</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SmartScreen Filter</Description>
</module>
<module>
<Timestamp>131795786095385025</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786095414401</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786095372148</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\System32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786098894292</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795786095060723</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786092008108</Timestamp>
<BaseAddress>0x7ffababf0000</BaseAddress>
<Size>806912</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe64.dll</Path>
<Version>1, 0, 0, 1150</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786097852913</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786095928005</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795786093350863</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786137298934</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795786099499942</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\System32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795786155511100</Timestamp>
<BaseAddress>0x7ffabe830000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\smartscreenps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreenPS</Description>
</module>
<module>
<Timestamp>131795786175106783</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795786126783504</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786095697218</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786126703773</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786126666772</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786092840839</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>126976</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N64.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795786122446702</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786097238400</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795786091280736</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786098823307</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795786091266496</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786097003528</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786168735686</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795786090797141</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786096821309</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786093337459</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\eShims.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Compatibility Shims</Description>
</module>
<module>
<Timestamp>131795786149406998</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786124866847</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786096204385</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786096235413</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786099433900</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795786098769154</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795786098876641</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795786099938691</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795786126416006</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786099479132</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795786098957527</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\System32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795786124773333</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786097660874</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795786096795570</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786097688469</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795786091312218</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786095403206</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786220221983</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795786176564935</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795786196210087</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786100083353</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786097022036</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786099453250</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795786097703788</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795786090732326</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795786094154074</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786096836522</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786093314951</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786098913536</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795786093292052</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786097717992</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795786125771324</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786118519493</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786118553070</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786096216041</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786109730985</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786091297207</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786093305950</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786096756389</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786095394201</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786118538156</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786126691616</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786126679897</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786095715320</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786091326041</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786091234983</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786091232285</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786091236180</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786091226209</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786090775583</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786090776791</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786091224549</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786090777738</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786090758361</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786091230916</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786090715101</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786090779459</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786091239738</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786091229511</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786091227932</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786091238674</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786226607039</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795786090757247</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786096796493</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786090755355</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786090714140</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786097027569</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795786091225372</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786091241982</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786091337871</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786091223732</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786090759164</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786091241004</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795786090754460</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786091237308</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786091233709</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786090756519</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786089403873</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>167</ProcessIndex>
<ProcessId>8360</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786145545826</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>smartscreen.exe</ProcessName>
<ImagePath>C:\Windows\System32\smartscreen.exe</ImagePath>
<CommandLine>C:\Windows\System32\smartscreen.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>SmartScreen</Description>
<modulelist>
<module>
<Timestamp>131795786149935538</Timestamp>
<BaseAddress>0x7ff75abc0000</BaseAddress>
<Size>2416640</Size>
<Path>C:\Windows\System32\smartscreen.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreen</Description>
</module>
<module>
<Timestamp>131795786314242815</Timestamp>
<BaseAddress>0x7ffaa6a40000</BaseAddress>
<Size>2936832</Size>
<Path>C:\Windows\System32\CertEnroll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент регистрации служб сертификатов Active Directory Microsoft®</Description>
</module>
<module>
<Timestamp>131795786321983797</Timestamp>
<BaseAddress>0x7ffab0360000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\certca.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ЦС служб сертификации Microsoft® Active Directory</Description>
</module>
<module>
<Timestamp>131795786150398418</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786338506430</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786156130630</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795786162891895</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795786155325960</Timestamp>
<BaseAddress>0x7ffabe830000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\smartscreenps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreenPS</Description>
</module>
<module>
<Timestamp>131795786290626130</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795786303817642</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786292777426</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786308881957</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786291185460</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795786303729142</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786295084336</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786150377395</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\System32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795786150443503</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786295137905</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786293100161</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786293113418</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786317286245</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\dsparse.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795786296541369</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786294026752</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786150415925</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786150432150</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786162900766</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786290836325</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\samlib.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795786293555790</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795786293160744</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795786340507243</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795786297745460</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786155834219</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786303757002</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786167890086</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786167870284</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786150424134</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786294009833</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786150385959</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786155846861</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786303746521</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786303737722</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786292790345</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786150407736</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786149962132</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786149968291</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786149971001</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786149965440</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786149952992</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786149956475</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786149963670</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786149971757</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786149957278</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786149967388</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786149943620</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786149960523</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786149952242</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786155995189</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786157141835</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786149955480</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786167871961</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786149957990</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786154314206</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786149942691</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786322132523</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\Wldap32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795786149964615</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786149966457</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786151032932</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786149962916</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786149954350</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786149969125</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786149970065</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786149959703</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786149935879</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>169</ProcessIndex>
<ProcessId>10296</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795786226372453</CreateTime>
<FinishTime>131795789233522663</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k wsappx</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795786226400516</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795786230130846</Timestamp>
<BaseAddress>0x7ffaa6d10000</BaseAddress>
<Size>2297856</Size>
<Path>C:\Windows\System32\AppXDeploymentServer.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера развертывания AppX</Description>
</module>
<module>
<Timestamp>131795786231602983</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795786230153246</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fltLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795786230145294</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795786231588260</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795786230170844</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786230189651</Timestamp>
<BaseAddress>0x7ffacb720000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\mintdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795786230158474</Timestamp>
<BaseAddress>0x7ffacb820000</BaseAddress>
<Size>712704</Size>
<Path>C:\Windows\System32\tdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795786231611090</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795786230164145</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786231594114</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786229616871</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786230136201</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786230137819</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795786229625340</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786229594723</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786229603946</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786229623786</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786231611929</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786230132115</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786229584668</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786230136994</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786230134090</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786230133328</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786229593263</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786229617635</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786229583632</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786229624570</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786229622783</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786229602893</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786230135123</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786229592437</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786226400757</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>170</ProcessIndex>
<ProcessId>10876</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786251236056</CreateTime>
<FinishTime>131795788181531259</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SearchProtocolHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchProtocolHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchProtocolHost.exe&quot; Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-3477790013-1571897634-1299942168-1000288_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-3477790013-1571897634-1299942168-1000288 1 -2147483646 &quot;Software\Microsoft\Windows Search&quot; &quot;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)&quot; &quot;C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc&quot; &quot;DownLevelDaemon&quot;  &quot;1&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Protocol Host</Description>
<modulelist>
<module>
<Timestamp>131795786251269067</Timestamp>
<BaseAddress>0x7ff77c170000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\SearchProtocolHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Protocol Host</Description>
</module>
<module>
<Timestamp>131795786252378762</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\System32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795786311861720</Timestamp>
<BaseAddress>0x7ffab7d50000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\mssph.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик протоколов поиска Microsoft</Description>
</module>
<module>
<Timestamp>131795786298907649</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795786252887437</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\System32\msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795786252245401</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786252238173</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786252246194</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786252240990</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786252230091</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786252232823</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786252244559</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786252236231</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786252237203</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786252218352</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786252229401</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786252228473</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786252231867</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786252227168</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786255090404</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786252217360</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786252240184</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786252464763</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786252243819</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786252231033</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786252234383</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786258307185</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786252239270</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786252235203</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786251269513</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>171</ProcessIndex>
<ProcessId>12864</ProcessId>
<ParentProcessId>4048</ParentProcessId>
<ParentProcessIndex>3</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795786259819446</CreateTime>
<FinishTime>131795788181883048</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchFilterHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchFilterHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\system32\SearchFilterHost.exe&quot; 0 708 712 720 8192 716 </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Microsoft Windows Search Filter Host</Description>
<modulelist>
<module>
<Timestamp>131795786260175133</Timestamp>
<BaseAddress>0x7ff6a9f90000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\SearchFilterHost.exe</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Search Filter Host</Description>
</module>
<module>
<Timestamp>131795786261457443</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\System32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795786263344012</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795786261520949</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786261484334</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786261436442</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786261439345</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786261482480</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786263346910</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786261425296</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786261435749</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786261434971</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786261438373</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786261433616</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786262531245</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786261424318</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786261483472</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786261480909</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786261481696</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786261437569</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786261440235</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786261442074</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786260175449</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>172</ProcessIndex>
<ProcessId>11924</ProcessId>
<ParentProcessId>3632</ParentProcessId>
<ParentProcessIndex>38</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786260517979</CreateTime>
<FinishTime>131795786892711288</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>microsoftedgecp.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe&quot; SCODEF:4760 CREDAT:271620 /prefetch:2</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Microsoft Edge Content Process</Description>
<modulelist>
<module>
<Timestamp>131795786262397181</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786262167704</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786260845950</Timestamp>
<BaseAddress>0x7ff6405a0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content Process</Description>
</module>
<module>
<Timestamp>131795786266817230</Timestamp>
<BaseAddress>0x7ffaafb30000</BaseAddress>
<Size>3379200</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\EdgeContent.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content</Description>
</module>
<module>
<Timestamp>131795786273171730</Timestamp>
<BaseAddress>0x7ffab0430000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\System32\ieapfltr.dll</Path>
<Version>11.00.14393.2189</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SmartScreen Filter</Description>
</module>
<module>
<Timestamp>131795786270806162</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786270839051</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786270772483</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\System32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786275446565</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795786270072489</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786265786335</Timestamp>
<BaseAddress>0x7ffababf0000</BaseAddress>
<Size>806912</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe64.dll</Path>
<Version>1, 0, 0, 1150</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786274051995</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786272010707</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795786268295906</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786276659367</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\System32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795786270998807</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786266702928</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>126976</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N64.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795786281591660</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786273587652</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795786263279818</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786274502821</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795786262999598</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786273075968</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786262124801</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786273039671</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786267816488</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\eShims.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Compatibility Shims</Description>
</module>
<module>
<Timestamp>131795786272372041</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786272398710</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786276370397</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795786274296386</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795786275429221</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795786277431755</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795786281870494</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786276415541</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795786275500652</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\System32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795786273929786</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795786272872598</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786273944650</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795786264741964</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786270826076</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786277530830</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786273013365</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786276389583</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795786273968562</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795786261792794</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795786269891965</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786273053460</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786267733064</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786275464402</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795786267710124</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786273983354</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795786272383802</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786264728389</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786267723907</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786272853268</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786270815412</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786271801017</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786264754931</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786262716363</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786262713703</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786262717336</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786262708096</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786262103806</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786262104662</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786262706569</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786262105460</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786262102390</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786262712493</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786261162555</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786262106757</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786262720644</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786262711177</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786262709636</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786262719660</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786262101329</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786272873296</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786262099282</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786261161608</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786273020851</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795786262707345</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786263695399</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786264820388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786262705735</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786262103125</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786262721852</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795786262098445</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786262718386</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786262715028</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786262100531</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786260846246</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>175</ProcessIndex>
<ProcessId>5516</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786458574348</CreateTime>
<FinishTime>131795786668714812</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\SysWOW64\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\SysWOW64\DllHost.exe /Processid:{53362C32-A296-4F2D-A2F8-FD984D08340B}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795786458625739</Timestamp>
<BaseAddress>0x1c0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795786458812497</Timestamp>
<BaseAddress>0x28a0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786458802018</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795786458803135</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795786459187647</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795786464828747</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786471755242</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795786467292564</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795786465884399</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786465896468</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786465871513</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786475201135</Timestamp>
<BaseAddress>0x72510000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\oleacchooks.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Event Hooks Library</Description>
</module>
<module>
<Timestamp>131795786464811068</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786465908090</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786465859315</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786460206704</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786460205088</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786464695607</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786460203002</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786461511851</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786460204080</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786464171982</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786465839162</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795786461513544</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786465833280</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786461526166</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786465840162</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786465830817</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786460190404</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786460954334</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786465573379</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786465829008</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786465832041</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786465577964</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786464044290</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786465834482</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786464043149</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786460952558</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786465838059</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786465836920</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786465835671</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786464045523</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786465579325</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786458626282</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795786458626030</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>176</ProcessIndex>
<ProcessId>10132</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786476963161</CreateTime>
<FinishTime>131795786539225053</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\SysWOW64\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\SysWOW64\DllHost.exe /Processid:{60A90A2F-858D-42AF-8929-82BE9D99E8A1}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795786477001176</Timestamp>
<BaseAddress>0x1c0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795786478398121</Timestamp>
<BaseAddress>0x2d30000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786478389241</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795786478390127</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795786478400908</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795786480674311</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786482887456</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795786483144498</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795786480744805</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786480755984</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786480732611</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786479600862</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786480770108</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786480721105</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786482897187</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786478425807</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786478424070</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786479420252</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786478422103</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786478445339</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786478423111</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786479406688</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786480701271</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795786478446378</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786480695805</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786478454213</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786480702108</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786480693547</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786478411433</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786478427541</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786480678971</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786480692449</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786480694624</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786480682946</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786479404153</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786480696852</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786479403125</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786478426691</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786480700210</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786480699254</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786480697952</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786479405386</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786480690377</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786477001678</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795786477001417</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>177</ProcessIndex>
<ProcessId>4460</ProcessId>
<ParentProcessId>360</ParentProcessId>
<ParentProcessIndex>26</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131795786483672847</CreateTime>
<FinishTime>131795789552424842</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>AUDIODG.EXE</ProcessName>
<ImagePath>C:\Windows\system32\AUDIODG.EXE</ImagePath>
<CommandLine>C:\Windows\system32\AUDIODG.EXE 0x3c8</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Изоляция графов аудиоустройств Windows </Description>
<modulelist>
<module>
<Timestamp>131795786483737234</Timestamp>
<BaseAddress>0x7ff644450000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\System32\audiodg.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Изоляция графов аудиоустройств Windows </Description>
</module>
<module>
<Timestamp>131795786489991459</Timestamp>
<BaseAddress>0x7ffaa61f0000</BaseAddress>
<Size>1802240</Size>
<Path>C:\Windows\System32\WMALFXGFXDSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SysFx DSP</Description>
</module>
<module>
<Timestamp>131795786491203172</Timestamp>
<BaseAddress>0x7ffab02d0000</BaseAddress>
<Size>552960</Size>
<Path>C:\Windows\System32\AudioEng.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Audio Engine</Description>
</module>
<module>
<Timestamp>131795786493632244</Timestamp>
<BaseAddress>0x7ffab2210000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\System32\AUDIOKSE.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Audio Ks Endpoint</Description>
</module>
<module>
<Timestamp>131795786489315184</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\AudioSes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795786491212877</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\avrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795786489374175</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786486995361</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795786487023199</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786487012555</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\devobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795786487110854</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786489316223</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786487130406</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786487013350</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786487027890</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786487128514</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786487028876</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786486974715</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786487025610</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786487014184</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786487024061</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786486996225</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786486983209</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786487161583</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786486973739</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786487129567</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786487127680</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786487026948</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786486997505</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786483737473</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>178</ProcessIndex>
<ProcessId>3980</ProcessId>
<ParentProcessId>3632</ParentProcessId>
<ParentProcessIndex>38</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786542534038</CreateTime>
<FinishTime>131795787153665956</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>microsoftedgecp.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe&quot; SCODEF:4760 CREDAT:75042 /prefetch:2</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Microsoft Edge Content Process</Description>
<modulelist>
<module>
<Timestamp>131795786543166673</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786543156173</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786543023139</Timestamp>
<BaseAddress>0x7ff6405a0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content Process</Description>
</module>
<module>
<Timestamp>131795786544668949</Timestamp>
<BaseAddress>0x7ffaafb30000</BaseAddress>
<Size>3379200</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\EdgeContent.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content</Description>
</module>
<module>
<Timestamp>131795786547134753</Timestamp>
<BaseAddress>0x7ffab0430000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\System32\ieapfltr.dll</Path>
<Version>11.00.14393.2189</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SmartScreen Filter</Description>
</module>
<module>
<Timestamp>131795786546099229</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786546132872</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786546086736</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\System32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786545840173</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786544284320</Timestamp>
<BaseAddress>0x7ffababf0000</BaseAddress>
<Size>806912</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe64.dll</Path>
<Version>1, 0, 0, 1150</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786546767845</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795786544756593</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786546447893</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786544441946</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>126976</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N64.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795786547370949</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795786543249419</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786543235314</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786547074480</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786543110293</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786547037950</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786544742430</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\eShims.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Compatibility Shims</Description>
</module>
<module>
<Timestamp>131795786546808750</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786546837985</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786547008646</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786543281081</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786546121243</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786547103227</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786543050856</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795786545377082</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786547051625</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786544707036</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786544683494</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786546820375</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786543266200</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786544697655</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786546988052</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786546108435</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786546466846</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786543295712</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786543199419</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786543196715</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786543200430</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786543170597</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786543084116</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786543085632</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786543168463</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786543086449</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786543082543</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786543195302</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786543031329</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786543087768</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786543204245</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786543193930</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786543172173</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786543203070</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786543081398</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786547009355</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786543079163</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786543030185</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786547109372</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795786543169353</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786543206414</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786543310277</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786543167391</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786543083335</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786543205475</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795786543078284</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786543201502</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786543198161</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786543080673</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786543023544</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>179</ProcessIndex>
<ProcessId>4244</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786562592500</CreateTime>
<FinishTime>131795786637941751</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\SysWOW64\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\SysWOW64\DllHost.exe /Processid:{60A90A2F-858D-42AF-8929-82BE9D99E8A1}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795786562663462</Timestamp>
<BaseAddress>0x1c0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\dllhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795786566149636</Timestamp>
<BaseAddress>0x2570000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786566140612</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795786566141510</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795786566152332</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795786566701565</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786566985276</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795786567016478</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795786566774423</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786566785906</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786566761847</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786566608422</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786566797077</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786566749632</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786566994350</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786566177367</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786566175458</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786566570216</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786566173446</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786566196561</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786566174491</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786566555155</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786566724982</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795786566197606</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786566719272</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786566206211</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786566725849</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786566716931</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786566162375</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786566179145</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786566705915</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786566713044</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786566718069</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786566709979</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786566552722</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786566720344</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786566551478</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786566178270</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786566723865</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786566722849</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786566721499</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786566554011</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786566711273</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786562664241</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795786562663905</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>1</ProcessIndex>
<ProcessId>11372</ProcessId>
<ParentProcessId>10560</ParentProcessId>
<ParentProcessIndex>2</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770632346846</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon64.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Temp\Procmon64.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Temp\Procmon64.exe&quot;  /originalpath &quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot;</CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645297135</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>2</ProcessIndex>
<ProcessId>10560</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131795770594566098</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Procmon.exe</ProcessName>
<ImagePath>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\Downloads\ProcessMonitor\Procmon.exe&quot; </CommandLine>
<CompanyName>Sysinternals - www.sysinternals.com</CompanyName>
<Version>3.50</Version>
<Description>Process Monitor</Description>
<modulelist>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x1000000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Users\User\Downloads\ProcessMonitor\Procmon.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x62530000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6dd70000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\RICHED20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70cd0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x70ec0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\SysWOW64\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72520000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\Riched32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wrapper Dll for Richedit 1.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645662037</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>3</ProcessIndex>
<ProcessId>4048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765778109600457</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>SearchIndexer.exe</ProcessName>
<ImagePath>C:\Windows\system32\SearchIndexer.exe</ImagePath>
<CommandLine>C:\Windows\system32\SearchIndexer.exe /Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Индексатор службы Microsoft Windows Search</Description>
<modulelist>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ff63db40000</BaseAddress>
<Size>929792</Size>
<Path>C:\Windows\system32\SearchIndexer.exe</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индексатор службы Microsoft Windows Search</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\MSSRCH.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabd990000</BaseAddress>
<Size>720896</Size>
<Path>C:\Windows\system32\ElsLad.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ELS Language Detection</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\vssapi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac7e40000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\Msidle.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Idle Monitor</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645302950</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>4</ProcessIndex>
<ProcessId>580</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776275984299</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>services.exe</ProcessName>
<ImagePath>C:\Windows\system32\services.exe</ImagePath>
<CommandLine>C:\Windows\system32\services.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Приложение служб и контроллеров</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>6</ProcessIndex>
<ProcessId>664</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776282506625</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k DcomLaunch</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc6a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\SebBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; SEB Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc7e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\SmartCardBackgroundPolicy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartCardBackgroundPolicy</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8c0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\CbtBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; CBT Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc8d0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\ACPBackgroundManagerPolicy.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; ACP Background Manager Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc900000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BackgroundMediaPolicy.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Background Media Policy DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\RmClient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaca740000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\DAB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL брокера активности компьютера</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacabd0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\OnDemandBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OnDemandBrokerClient</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacae70000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\systemeventsbrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер системных событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacafc0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy RM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb010000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SYSTEM32\psmserviceexthost.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager PSM Service Extension</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb390000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\psmsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process State Manager (PSM) Service</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb4f0000</BaseAddress>
<Size>794624</Size>
<Path>c:\windows\system32\bisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба инфраструктуры фоновых задач</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb720000</BaseAddress>
<Size>344064</Size>
<Path>c:\windows\system32\mintdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>c:\windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb820000</BaseAddress>
<Size>712704</Size>
<Path>C:\Windows\SYSTEM32\tdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Вспомогательная библиотека трассировки событий</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8d0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\umpoext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения службы пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb8f0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\umpo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба пользовательского режима питания</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacb940000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\umpnpmgr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский режим службы самонастройки (Plug-and-Play)</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375819</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>7</ProcessIndex>
<ProcessId>884</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776292813936</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9230000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\bluetoothapis.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Usermode Api host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab9580000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\BthRadioMedia.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bluetooth Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffab95a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WlanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wlan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaba920000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\rmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Radio Manager API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabae80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\NfcRadioMedia.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NFC Radio Media Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabb8a0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\XboxGipRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Xbox GIP Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc0e0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\WwanRadioManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wwan Radio Manager</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac78c0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\shacct.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Classes</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac7f80000</BaseAddress>
<Size>208896</Size>
<Path>c:\windows\system32\wscsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8490000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\dhcpcore6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8c90000</BaseAddress>
<Size>385024</Size>
<Path>c:\windows\system32\dhcpcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>c:\windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffac9c30000</BaseAddress>
<Size>1732608</Size>
<Path>c:\windows\system32\wevtsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба протоколирования событий</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca2a0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\timebrokerserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Брокер событий времени</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca330000</BaseAddress>
<Size>36864</Size>
<Path>c:\windows\system32\nrpsrv.DLL</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Name Resolution Proxy (NRP) RPC interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4d0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lmhsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб транспорта TCPIP NetBios</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645326170</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>8</ProcessIndex>
<ProcessId>0</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:00000000</AuthenticationId>
<CreateTime>131765775874898587</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>4294967295</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity></Integrity>
<Owner></Owner>
<ProcessName>Idle</ProcessName>
<ImagePath>Idle</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ff7ed960000</BaseAddress>
<Size>1224704</Size>
<Path>C:\Users\User\AppData\Local\Temp\Procmon64.exe</Path>
<Version>3.50</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\SYSTEM32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\system32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645349496</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>9</ProcessIndex>
<ProcessId>4</ProcessId>
<ParentProcessId>0</ParentProcessId>
<ParentProcessIndex>8</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775907178738</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>System</ProcessName>
<ImagePath>System</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b6e00000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\System32\win32kfull.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Win32k Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7190000</BaseAddress>
<Size>1576960</Size>
<Path>C:\Windows\System32\win32kbase.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Базовый драйвер ядра Win32k</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7320000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\TSDDD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Framebuffer Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b7330000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\cdd.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Canonical Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xffffc709b74a0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\win32k.sys</Path>
<Version>10.0.14393.594 (rs1_release_inmarket.161213-1754)</Version>
<Company>Microsoft Corporation</Company>
<Description>Full/Desktop Multi-User Win32 Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80278934000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\kd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Kernel Debugger</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80279678000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92e00000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\ksecdd.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ee0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\cmimcext.sys</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Configuration Manager Initial Configuration Extension Host Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92ef0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\ntosext.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTOS extension host driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d92fa0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\drivers\cng.sys</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Cryptography, Next Generation</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93040000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\system32\drivers\Wdf01000.sys</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения платформы драйвера режима ядра</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93120000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\drivers\WDFLDR.SYS</Path>
<Version>1.19.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Mode Driver Framework Loader</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93140000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\Drivers\acpiex.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPIEx Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93170000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\Drivers\WppRecorder.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WPP Trace Recorder</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93180000</BaseAddress>
<Size>733184</Size>
<Path>C:\Windows\System32\drivers\ACPI.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ACPI драйвер для NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93240000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\WMILIB.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMILIB WMI support library Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93260000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\intelpep.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Power Engine Plugin</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93280000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\drivers\WindowsTrustedRT.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932a0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Trusted Runtime Service Proxy Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\pcw.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Performance Counters for Windows Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932d0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\msisadrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ISA Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932e0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\isapnp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер шины PNP ISA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d932f0000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\drivers\pci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Plug and Play PCI-перечислитель</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93350000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\vdrvroot.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Drive Root Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93370000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\drivers\pdc.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Power Dependency Coordinator Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933a0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\CEA.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation Kernel Mode Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\partmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Partition driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d933f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\drivers\nvraid.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) RAID Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93420000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\CLASSPNP.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI Class System Dll</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93490000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\vmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Дочерний драйвер шины виртуальной машины Microsoft Hyper-V</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d934c0000</BaseAddress>
<Size>1212416</Size>
<Path>C:\Windows\System32\drivers\NDIS.SYS</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS (Network Driver Interface Specification)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d935f0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\drivers\NETIO.SYS</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network I/O Subsystem</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93670000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\hvsocket.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Hyper-V Socket Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\vmbkmcl.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V VMBus KMCL</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\winhv.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Hypervisor Interface Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\pciide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Generic PCI IDE Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d936e0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\PCIIDEX.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PCI IDE Bus Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93700000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\drivers\spaceport.sys</Path>
<Version>10.0.14393.1914 (rs1_release_inmarket.171117-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Spaces Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937a0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\intelide.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel PCI IDE Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937b0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\volmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d937d0000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\drivers\volmgrx.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер расширения диспетчера томов</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93830000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\drivers\mountmgr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер точек подключения</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93850000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\nvstor.sys</Path>
<Version>10.6.0.23 (PART_L3.131021-1012)</Version>
<Company>NVIDIA Corporation</Company>
<Description>NVIDIA® nForce(TM) Sata Performance Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\drivers\storport.sys</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Storage Port Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93910000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\atapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI IDE Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93920000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\System32\drivers\ataport.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ATAPI Driver Extension</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93960000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\drivers\storahci.sys</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS AHCI Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93990000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\stornvme.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft NVM Express Storport Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\drivers\EhStorClass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enhanced Storage Class driver for IEEE 1667 devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\fileinfo.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FileInfo Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d939f0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\Drivers\Wof.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр оверлея Windows</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93a80000</BaseAddress>
<Size>2297856</Size>
<Path>C:\Windows\System32\Drivers\NTFS.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер файловой системы NT</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\storvsc.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage VSC Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93cd0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\Drivers\Fs_Rec.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>File System Recognizer Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93d10000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\System32\drivers\USBPORT.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта USB 1.1 и 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93db0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\mcupdate_GenuineIntel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Intel Microcode Update Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93e50000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\System32\drivers\CLFS.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Common Log File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ec0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\tm.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Transaction Manager Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93ef0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\PSHED.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер аппаратных ошибок, специфичных для платформы</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f10000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\BOOTVID.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>VGA Boot Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f20000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\System32\drivers\FLTMGR.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер фильтров файловых систем Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d93f90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\drivers\msrpc.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Remote Procedure Call Provider</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94000000</BaseAddress>
<Size>430080</Size>
<Path>C:\Windows\System32\drivers\fwpkclnt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FWP/IPsec Kernel-Mode API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94070000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\drivers\wfplwfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WFP NDIS 6.30 Lightweight Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d940b0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DRIVERS\fvevol.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BitLocker Drive Encryption Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94160000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\drivers\volume.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94170000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\System32\drivers\volsnap.sys</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Volume Shadow Copy driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d941e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\scmbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Class Memory Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\drivers\rdyboost.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ReadyBoost Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94250000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\Drivers\mup.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер поставщика множественных UNC</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94280000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\drivers\iorate.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>I/O rate control Filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942a0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\disk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PnP Disk Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d942e0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\crashdmp.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crash Dump Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d943c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\drivers\cdrom.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SCSI CD-ROM Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94400000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\drivers\filecrypt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows sandboxing and encryption filter</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94420000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\tbs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Export driver for kernel mode TPM API</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94430000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Null.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NULL Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94440000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\Drivers\Beep.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BEEP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94450000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\BasicDisplay.sys</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Display Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94470000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\watchdog.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Watchdog Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94490000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\System32\drivers\dxgkrnl.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Kernel</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946b0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\BasicRender.sys</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Basic Render Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d946d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Drivers\Npfs.SYS</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPFS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94700000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\DRIVERS\tdx.sys</Path>
<Version>10.0.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDI Translation Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94740000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\DRIVERS\netbt.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>MBT Transport driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94790000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\drivers\afd.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер дополнительных функций для Winsock</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94830000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\vwififlt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual WiFi Filter Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94850000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\pacer.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Планировщик пакетов QoS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\drivers\netbios.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetBIOS interface driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d948a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\rdbss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер подсистемы буферизации перенаправленного диска</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94920000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\system32\drivers\csc.sys</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Client Side Caching Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\nsiproxy.sys</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\npsvctrig.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Named pipe service triggers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d949f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\drivers\gpuenergydrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GPU Energy Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a00000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Drivers\dfsc.sys</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DFS Namespace Client Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a50000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\DRIVERS\ahcache.sys</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Compatibility Cache</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94a90000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-Transport Composite Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\kdnic.sys</Path>
<Version>6.01.00.0000 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Kernel Debugger Network Miniport</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ac0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\drivers\umbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User-Mode Bus Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ae0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\System32\drivers\i8042prt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер порта i8042</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b10000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\drivers\kbdclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса клавиатуры</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b30000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\mouclass.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер класса мыши</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94b80000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\HDAudBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ba0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\drivers\portcls.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Port Class (Class Driver for Port/Miniport Devices)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c10000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\drivers\drmk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trusted Audio Drivers</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94c40000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\drivers\ks.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel CSA Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cb0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\usbohci.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OHCI USB Miniport Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cc0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\CmBatt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Control Method Battery Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94cd0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\BATTC.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Class Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94ce0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\drivers\intelppm.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Processor Device Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d10000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\drivers\NdisVirtualBus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечислитель виртуальных сетевых адаптеров (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94d20000</BaseAddress>
<Size>2588672</Size>
<Path>C:\Windows\System32\drivers\tcpip.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fa0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\swenum.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Plug and Play Software Device Enumerator</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d94fb0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\rdpbus.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft RDP Bus Device driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95200000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\DRIVERS\udfs.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UDF File System Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95280000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\Drivers\dump_diskdump.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d952c0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\System32\Drivers\dump_storahci.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95310000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\Drivers\dump_dumpfve.sys</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95330000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\system32\drivers\HTTP.sys</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Стек протокола HTTP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95450000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\drivers\WudfPf.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - User-mode Driver Framework Platform Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95470000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\DRIVERS\bowser.sys</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Lan Manager Datagram Receiver Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d954a0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT SMB Minirdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95520000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\drivers\mpsdrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Protection Service Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95540000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb20.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB 2.0 Redirector</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95580000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\DRIVERS\srvnet.sys</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Network driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d955d0000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\System32\DRIVERS\srv2.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер сервера SMB 2.0</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95690000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\system32\DRIVERS\mrxsmb10.sys</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Longhorn SMB Downlevel SubRdr</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d956e0000</BaseAddress>
<Size>573440</Size>
<Path>C:\Windows\System32\DRIVERS\srv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95770000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\drivers\tcpipreg.sys</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>TCP/IP Registry Compatibility Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95860000</BaseAddress>
<Size>684032</Size>
<Path>C:\Windows\System32\drivers\dxgmms2.sys</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics MMS</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95910000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\luafv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра виртуализации файлов LUA</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95960000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\drivers\storqosflt.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр качества обслуживания хранилища</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95980000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\drivers\registry.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Registry Containment Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959a0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\drivers\lltdio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Mapper I/O Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959c0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\drivers\mslldp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер протокола Microsoft LLDP</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d959e0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\drivers\rspndr.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Link-Layer Topology Responder Driver for NDIS 6</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95ae0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\drivers\USBD.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Universal Serial Bus Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95af0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\DRIVERS\HdAudio.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>High Definition Audio Function Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95b60000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\drivers\ksthunk.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kernel Streaming WOW Thunk Service</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d95bc0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\HIDPARSE.SYS</Path>
<Version>10.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hid Parsing Library</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97020000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\Drivers\360AntiHacker64.sys</Path>
<Version>1.0.0.1149</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络防黑模块</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97060000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\DRIVERS\360AvFlt.sys</Path>
<Version>1.1.0.1056</Version>
<Company>360.cn</Company>
<Description>360杀毒 文件监控驱动</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97080000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\DRIVERS\BAPIDRV64.sys</Path>
<Version>2.0.0.1221</Version>
<Company>360.cn</Company>
<Description>BAPIDRV</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d970c0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\drivers\360netmon.sys</Path>
<Version>2.1.11.5195</Version>
<Company>360.cn</Company>
<Description>360netmon</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97120000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\system32\DRIVERS\360Box64.sys</Path>
<Version>2.1.0.1253</Version>
<Company>360.cn</Company>
<Description>360Box64</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97180000</BaseAddress>
<Size>811008</Size>
<Path>C:\Windows\system32\DRIVERS\360FsFlt.sys</Path>
<Version>6.9.1.1751</Version>
<Company>360.cn</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97330000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\drivers\hidusb.sys</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>USB Miniport Driver for Input Devices</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97350000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\HIDCLASS.SYS</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека классов HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97380000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\drivers\mouhid.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер фильтра мыши HID</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97390000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\drivers\rassstp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS SSTP Miniport Call Manager</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973b0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\DRIVERS\NDProxy.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS Proxy</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d973d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\drivers\AgileVpn.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер вызовов минипорта RAS Agile VPN</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97420000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\drivers\rasl2tp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS L2TP mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97460000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\drivers\raspptp.sys</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Peer-to-Peer Tunneling Protocol</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974a0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\drivers\raspppoe.sys</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>RAS PPPoE mini-port/call-manager driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\DRIVERS\ndistapi.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NDIS 3.0 connection wrapper driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d974d0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\drivers\ndiswan.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS PPP Framing Driver (Strong Encryption)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97510000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\DRIVERS\wanarp.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MS Remote Access and Routing ARP Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97550000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\drivers\E1G6032E.sys</Path>
<Version>8.4.13.0 built by: WinDDK</Version>
<Company>Intel Corporation</Company>
<Description>Intel(R) PRO/1000 Adapter NDIS 6 deserialized driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97580000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\drivers\tunnel.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер интерфейса туннеля (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97600000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\Drivers\PROCMON24.SYS</Path>
<Version>3.10</Version>
<Company>Sysinternals - www.sysinternals.com</Company>
<Description>Process Monitor Driver</Description>
</module>
<module>
<Timestamp>131795780236159256</Timestamp>
<BaseAddress>0xfffff80d97620000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\drivers\npf.sys</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>npf.sys (NT5/6 AMD64) Kernel Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97a60000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\system32\drivers\peauth.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Protected Environment Authentication and Authorization Export Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b30000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\drivers\Ndu.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Network Data Usage Monitoring Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97b60000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\drivers\mmcss.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMCSS Driver</Description>
</module>
<module>
<Timestamp>131795770645349720</Timestamp>
<BaseAddress>0xfffff80d97bb0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\drivers\condrv.sys</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Driver</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>10</ProcessIndex>
<ProcessId>320</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765775908989732</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>smss.exe</ProcessName>
<ImagePath>C:\Windows\System32\smss.exe</ImagePath>
<CommandLine>\SystemRoot\System32\smss.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер сеанса  Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>11</ProcessIndex>
<ProcessId>3108</ProcessId>
<ParentProcessId>3092</ParentProcessId>
<ParentProcessIndex>12</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777624392598</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Explorer.EXE</ProcessName>
<ImagePath>C:\Windows\Explorer.EXE</ImagePath>
<CommandLine>C:\Windows\Explorer.EXE</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x31b0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5db0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Program Files\Uninstall Tool\utshellext.dll</Path>
<Version>1.1.0.15</Version>
<Company>CrystalIDEA Software</Company>
<Description>Uninstall Tool Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x81a0000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\MICROS~1\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x8cb0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x5bf70000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_08e394a1a83e212f\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\Notepad++\NppShell_06.dll</Path>
<Version>0.1</Version>
<Company></Company>
<Description>ShellHandler for Notepad++ (64 bit)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\Explorer.EXE</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaa6c80000</BaseAddress>
<Size>2093056</Size>
<Path>C:\Windows\system32\wpdshext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки для переносных устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab350000</BaseAddress>
<Size>1683456</Size>
<Path>C:\Windows\System32\comsvcs.dll</Path>
<Version>2001.12.10941.16384 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Services</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab4f0000</BaseAddress>
<Size>1400832</Size>
<Path>C:\Windows\system32\connect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Мастера подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab650000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\system32\rasgcw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Страницы мастера RAS</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>C:\Windows\System32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\System32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\system32\ieframe.DLL</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0df0000</BaseAddress>
<Size>1626112</Size>
<Path>C:\Windows\SYSTEM32\d3d9.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 9 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab0f80000</BaseAddress>
<Size>1777664</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoViewer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Просмотр фотографий Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab27c0000</BaseAddress>
<Size>516096</Size>
<Path>C:\Windows\System32\imapi2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>IMAPI версии 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2840000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\System32\bthprops.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложение панели управления Bluetooth</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2880000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\cscobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Внутрипроцессный COM-объект используемый клиентами CSC API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab29a0000</BaseAddress>
<Size>1912832</Size>
<Path>C:\Windows\System32\pnidui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Значок сетевой системы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2b80000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\system32\SettingMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Change Monitor</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab2bc0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\PortableDeviceTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device (Parameter) Types Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab34f0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\System32\Actioncenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5120000</BaseAddress>
<Size>1691648</Size>
<Path>C:\Windows\system32\BatMeter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Battery Meter Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\MsftEdit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab7e40000</BaseAddress>
<Size>3420160</Size>
<Path>C:\Windows\System32\SyncCenter.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр синхронизации Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\system32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\system32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab99b0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\dxp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки компонента Device Stage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffab9ba0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Windows\SYSTEM32\searchfolder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SearchFolder</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabac60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\System32\EhStorAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Enhanced Storage API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae20000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msiltcfg.dll</Path>
<Version>5.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer Configuration API Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaea0000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\system32\SHDOCVW.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\SYSTEM32\settingsynccore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SYSTEM32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786030517308</Timestamp>
<BaseAddress>0x7ffabb910000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\container.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Containers</Description>
</module>
<module>
<Timestamp>131795786030225106</Timestamp>
<BaseAddress>0x7ffabb970000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\daxexec.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>daxexec</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795786377372706</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786377355113</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\SYSTEM32\MSVCP140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\VCRUNTIME140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786377364261</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SYSTEM32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795786376748307</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd3c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\InputSwitch.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переключатель ввода Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd670000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\framedynos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI SDK Provider Framework</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd6c0000</BaseAddress>
<Size>1306624</Size>
<Path>C:\Windows\System32\werconcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PRS CPL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabd800000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\NPSMDesktopProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; Библиотека DLL локального поставщика рабочего стола NPSM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabda60000</BaseAddress>
<Size>1241088</Size>
<Path>C:\Windows\System32\wscui.cpl</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Центр безопасности и обслуживания</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabdeb0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\wpdshserviceobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Portable Device Shell Service Object</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabded0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\stobject.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Объект службы оболочки Systray</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe470000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\wscinterop.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Health Center WSC Interop</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe580000</BaseAddress>
<Size>831488</Size>
<Path>C:\Program Files (x86)\360\Total Security\MenuEx64.dll</Path>
<Version>9, 6, 0, 1001</Version>
<Company></Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe650000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\system32\zipfldr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сжатые ZIP-папки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9a0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\Syncreg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Synchronization Framework Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\system32\NetworkExplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0b0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\playtomenu.dll</Path>
<Version>12.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека меню функции &quot;Передать на устройство&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\System32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf590000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\syncui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Портфель Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795786456426767</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfba0000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\WSCAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\MICROS~1\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b40000</BaseAddress>
<Size>315392</Size>
<Path>C:\Windows\System32\dlnashext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLNA Namespace DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0b90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\srchadmin.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры индексирования</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac0f60000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SYSTEM32\CHARTV.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Chart View</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1cc0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.Sockets.PushEnabledApplication DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac27a0000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.111.0603.0006\amd64\FileSyncShell64.dll</Path>
<Version>18.111.0603.0006</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795786030406949</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fltLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac32e0000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\twext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Свойства: Предыдущие версии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3350000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\OLEACCHOOKS.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Event Hooks Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\dsreg.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SYSTEM32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5140000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\AboveLockAppHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AboveLockAppHost</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5190000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\NotificationController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5570000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\system32\twinui.pcshell.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Twinui.PCShell</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac55d0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\windows.immersiveshell.serviceprovider.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.ImmersiveShell.ServiceProvider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\system32\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5c70000</BaseAddress>
<Size>65536</Size>
<Path>C:\Program Files\Windows Photo Viewer\PhotoBase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Base Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6650000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\npsm.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>NPSM</Description>
</module>
<module>
<Timestamp>131795780903771340</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac78f0000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\hgcpl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Панель управления домашней группы</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795782572474169</Timestamp>
<BaseAddress>0x7ffac7ce0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\ploptin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Prelaunch OptIn</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d40000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\SYNCENG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Briefcase Engine</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7d90000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\SYSTEM32\SndVolSSO.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Громкость SCA </Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7f50000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\acppage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека расширений для вкладки &quot;Совместимость&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\SYSTEM32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795778062352400</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\ploptin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Prelaunch OptIn</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ea0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\hcproviders.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщики компонента &quot;Центр безопасности и обслуживания&quot;</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca190000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\WorkFoldersShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение оболочки рабочих папок (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795780604813666</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacac80000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SYSTEM32\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\SYSTEM32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645352881</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>13</ProcessIndex>
<ProcessId>404</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776186257169</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>15</ProcessIndex>
<ProcessId>468</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776223665667</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>csrss.exe</ProcessName>
<ImagePath>C:\Windows\system32\csrss.exe</ImagePath>
<CommandLine>%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Процесс исполнения клиент-сервер</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>17</ProcessIndex>
<ProcessId>484</ProcessId>
<ParentProcessId>396</ParentProcessId>
<ParentProcessIndex>14</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226419105</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>wininit.exe</ProcessName>
<ImagePath>C:\Windows\system32\wininit.exe</ImagePath>
<CommandLine>wininit.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Автозагрузка приложений Windows</Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>18</ProcessIndex>
<ProcessId>520</ProcessId>
<ParentProcessId>460</ParentProcessId>
<ParentProcessIndex>16</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776226825613</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>winlogon.exe</ProcessName>
<ImagePath>C:\Windows\system32\winlogon.exe</ImagePath>
<CommandLine>winlogon.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Программа входа в систему Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ff7b5570000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\winlogon.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа входа в систему Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaee0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\dwminit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMInit</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacafa0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\UXINIT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows User Experience Session Initialization Dll</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375500</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>19</ProcessIndex>
<ProcessId>588</ProcessId>
<ParentProcessId>484</ParentProcessId>
<ParentProcessIndex>17</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776277547408</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>lsass.exe</ProcessName>
<ImagePath>C:\Windows\system32\lsass.exe</ImagePath>
<CommandLine>C:\Windows\system32\lsass.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Description>Local Security Authority Process</Description>
<modulelist>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x222e3610000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\msprivs.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Переводы привилегий Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ff6b2d20000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\lsass.exe</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Local Security Authority Process</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffab9170000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\vaultsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба диспетчера учетных данных</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf170000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\hmkd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows HMAC Key Derivation API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf190000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\ngcpopkeysrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Passport Proof-of-possession Key Service</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1b0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\keyiso.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба изоляции ключей CNG</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SYSTEM32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf270000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SecureTimeAggregator.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Secure Time Aggregator</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacb9b0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\scecli.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент редактора конфигураций безопасности</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\SspiSrv.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA SSPI RPC interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacba90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\dpapisrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DPAPI Server</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbad0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\efslsaext.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>LSA extension for EFS</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbb70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wdigest.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Digest Access</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc00000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\MicrosoftAccountCloudAP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MicrosoftAccount Cloud AP Plugin</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbc50000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\cloudAP.DLL</Path>
<Version>10.0.14393.1358 (rs1_release.170602-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cloud AP Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbcb0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\system32\pku2u.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pku2u Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd00000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\system32\tspkg.DLL</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Web Service Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe30000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\gmsaclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;gmsaclient.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbe60000</BaseAddress>
<Size>843776</Size>
<Path>C:\Windows\system32\netlogon.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека службы Net Logon</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc030000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\KerbClientShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Kerberos Client Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc180000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\negoexts.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NegoExtender Security Package</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\JOINUTIL.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\netprovfw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Provisioning Service Framework DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc260000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\SYSTEM32\samsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сервера диспетчера учетных записей</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc380000</BaseAddress>
<Size>1527808</Size>
<Path>C:\Windows\system32\lsasrv.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера LSA</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375702</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>20</ProcessIndex>
<ProcessId>704</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776284978539</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k RPCSS</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8250000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\system32\wshhyperv.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Hyper-V Winsock2 Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb5c0000</BaseAddress>
<Size>913408</Size>
<Path>c:\windows\system32\rpcss.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Distributed COM Services</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6a0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\RpcRtRemote.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote RPC Extension</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb6c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\rpcepmap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сопоставитель конечных точек RPC
</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645375918</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>21</ProcessIndex>
<ProcessId>808</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0000c8d4</AuthenticationId>
<CreateTime>131765776288401882</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>Window Manager\DWM-1</Owner>
<ProcessName>dwm.exe</ProcessName>
<ImagePath>C:\Windows\system32\dwm.exe</ImagePath>
<CommandLine>&quot;dwm.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер окон рабочего стола</Description>
<modulelist>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ff683990000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\dwm.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\system32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7b70000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\System32\Windows.Gaming.Input.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Gaming Input API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\system32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\avrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9a30000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SYSTEM32\ism32k.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca110000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\dwmghost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DWMGhost</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaca8d0000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\system32\dwmcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека ядра Microsoft DWM</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacac90000</BaseAddress>
<Size>856064</Size>
<Path>C:\Windows\SYSTEM32\udwm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер окон рабочего стола Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\dwmredir.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компонент перенаправления диспетчера окон рабочего стола Microsoft</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376024</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>22</ProcessIndex>
<ProcessId>904</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776293087855</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x259b0640000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\system32\SFC.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab830000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\netman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab880000</BaseAddress>
<Size>532480</Size>
<Path>c:\windows\system32\MPRAPI.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT MP Router Administration DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaab910000</BaseAddress>
<Size>905216</Size>
<Path>c:\windows\system32\RASDLG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API общих диалогов службы удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab1260000</BaseAddress>
<Size>10350592</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll</Path>
<Version>4.7.2117.0 built by: NET47REL1LAST</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Common Language Runtime - WorkStation</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\System32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>c:\windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795778252487651</Timestamp>
<BaseAddress>0x7ffabc160000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\System32\aeinv.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Inventory Component</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795778007496118</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffabfa00000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\SYSTEM32\MSVCR120_CLR0400.dll</Path>
<Version>12.00.52519.0 built by: VSWINSERVICING</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\MSI.DLL</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac0fc0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\system32\spp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих точек защиты Microsoft® Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1010000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\system32\MSCOREE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac10f0000</BaseAddress>
<Size>421888</Size>
<Path>c:\windows\system32\storsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы хранения</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1240000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll</Path>
<Version>4.7.2623.0 built by: NET471REL1LAST_C</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Runtime Execution Engine</Description>
</module>
<module>
<Timestamp>131795781037721051</Timestamp>
<BaseAddress>0x7ffac1660000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\System32\aeinv.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Inventory Component</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2420000</BaseAddress>
<Size>466944</Size>
<Path>c:\windows\system32\das.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сопоставления устройств</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795778007645121</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac41c0000</BaseAddress>
<Size>139264</Size>
<Path>c:\windows\system32\trkwks.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент отслеживания изменившихся связей</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4650000</BaseAddress>
<Size>516096</Size>
<Path>c:\windows\system32\pcasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба помощника по совместимости программ</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Assembly manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5b50000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\dssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы NT для службы совместного доступа к данным</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>c:\windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6120000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\sysmain.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост службы Superfetch</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b10000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\SYSTEM32\WUDFPlatform.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation - библиотека платформ пользовательского режима</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac7b50000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\wudfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Driver Foundation (WDF) - служба среды выполнения платформы драйвера режима пользователя</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9800000</BaseAddress>
<Size>376832</Size>
<Path>c:\windows\system32\audioendpointbuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство построения конечных точек Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9de0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\portabledeviceconnectapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Portable Device Connection API Components</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9e00000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SYSTEM32\PortableDeviceApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Компоненты API для переносных устройств Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca2d0000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\ncbservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Посредник подключений к сети</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>c:\windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaca710000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\pcadm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Diagnostic Module</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\system32\SXS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>c:\windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376243</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>23</ProcessIndex>
<ProcessId>96</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776304995849</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2510000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\energyprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2580000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\ncuprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Connectivity Statistics Provider for System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2b90000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\nduprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик сетевой статистики для службы отслеживания использования ресурсов системы</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bb0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\appsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application System Resource Usage Monitor (SRUM) provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2bd0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\eeprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Energy Estimator SRUM provider</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2c20000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\wfapigp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall GPO Helper dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac2d70000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\wpnsruprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SRUM provider for WPN</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3310000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\srumsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor Service</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3730000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\pnpts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PlugPlay Troubleshooter</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3bd0000</BaseAddress>
<Size>106496</Size>
<Path>c:\windows\system32\ncdautosetup.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы автоматической настройки сетевых устройств</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac41f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\adhapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD harvest sites and subnets API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4470000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4500000</BaseAddress>
<Size>200704</Size>
<Path>c:\windows\system32\dps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба политики диагностики WDI</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4cd0000</BaseAddress>
<Size>933888</Size>
<Path>c:\windows\system32\mpssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба защиты (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac4f40000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\radardt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа обнаружения нехватки системных ресурсов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6740000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\dtsh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API состояния общего доступа и обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac74b0000</BaseAddress>
<Size>827392</Size>
<Path>c:\windows\system32\bfe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба базовой фильтрации</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>c:\windows\system32\coremessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb070000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\embeddedmodesvcapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Embedded Mode Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\system32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\CFGMGR32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376384</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>24</ProcessIndex>
<ProcessId>348</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776305446235</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k netsvcs</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaa0aa0000</BaseAddress>
<Size>2138112</Size>
<Path>c:\windows\system32\wlidsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба учетных записей Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0750000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\system32\rascustom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль настраиваемых протоколов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab07b0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\vpnike.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>VPNIKE Protocol Engine - Test dll</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab09b0000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\system32\rasppp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access PPP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab0a00000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\rastapi.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access TAPI Compliance Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795786944300478</Timestamp>
<BaseAddress>0x7ffab3410000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab3440000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\rasmans.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер подключений удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab4c50000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\eappprxy.dll</Path>
<Version>10.0.14393.187 (rs1_release_inmarket.160906-1818)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft EAPHost Peer Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffab9a90000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\system32\dmEnrollEngine.DLL</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Enroll Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabc210000</BaseAddress>
<Size>2355200</Size>
<Path>c:\windows\system32\wuaueng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Агент Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabdf60000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\raschap.dll</Path>
<Version>10.0.14393.1480 (rs1_release.170706-2004)</Version>
<Company>Microsoft Corporation</Company>
<Description>Удаленные доступ через PPP CHAP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4a0000</BaseAddress>
<Size>147456</Size>
<Path>c:\windows\system32\appinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о приложении</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabed80000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\system32\wbem\wbemess.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee10000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabee30000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\system32\wbem\wmiprvsd.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf010000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\elscore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL ядра платформы Els</Description>
</module>
<module>
<Timestamp>131795786151289779</Timestamp>
<BaseAddress>0x7ffabf030000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf090000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf0e0000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\system32\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf200000</BaseAddress>
<Size>405504</Size>
<Path>c:\windows\system32\cryptngc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API службы Microsoft Passport</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf2a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\system32\dssenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfda0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\wbem\ncprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Non-COM WMI Event Provision APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfdc0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\keepaliveprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Keep alive provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfe50000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\wpnprv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик подключения платформы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\system32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0000000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\wbem\repdrvfs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Repository Driver</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\shacctprofile.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Accounts Profile Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795783766785197</Timestamp>
<BaseAddress>0x7ffac13e0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\usocore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обновление ядра оркестратора сеанса</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1530000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SYSTEM32\dpx.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft(R) Delta Package Expander</Description>
</module>
<module>
<Timestamp>131795788214269808</Timestamp>
<BaseAddress>0x7ffac15d0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795783773591339</Timestamp>
<BaseAddress>0x7ffac1660000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\System32\updatehandlers.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Session Orchestrator Update Handlers</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1900000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\appxapplicabilityblob.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Appx Applicability Blob DLL</Description>
</module>
<module>
<Timestamp>131795783942703101</Timestamp>
<BaseAddress>0x7ffac1940000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1970000</BaseAddress>
<Size>1073152</Size>
<Path>c:\windows\system32\qmgr.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фоновая интеллектуальная служба передачи</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\DevDispItemProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DeviceItem inproc devquery</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1c30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\DMProcessXMLFiltered.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmprocessxmlfiltered</Description>
</module>
<module>
<Timestamp>131795779661934902</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1cf0000</BaseAddress>
<Size>417792</Size>
<Path>C:\Windows\SYSTEM32\wuuhext.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update Agent plugin for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1df0000</BaseAddress>
<Size>61440</Size>
<Path>c:\windows\system32\NCI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CoInstaller: NET</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e20000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1e80000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\System32\NetSetupShim.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f10000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\DMCmnUtils.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmcmnutils</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1f50000</BaseAddress>
<Size>471040</Size>
<Path>C:\Windows\system32\wbem\esscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac1fd0000</BaseAddress>
<Size>999424</Size>
<Path>C:\Windows\system32\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>c:\windows\system32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac20f0000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\system32\CLUSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека API кластера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac21d0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\wbem\wbemsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2210000</BaseAddress>
<Size>1351680</Size>
<Path>C:\Windows\system32\wbem\wbemcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инструментарий управления Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2360000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\TimeBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Time Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2370000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\adhsvc.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD Harvest Sites and Subnets Service</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2390000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\system32\httpprxm.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager</Description>
</module>
<module>
<Timestamp>131795775850813653</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac24a0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\system32\RESUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служебной программы ресурсов кластера (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2530000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\hnetcfgclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент API конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795790154003588</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2640000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\wmidcom.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2670000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\miutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура управления</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac26f0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\sscoreext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Core DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2720000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SYSTEM32\WPTaskScheduler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WP Task Scheduler DLL</Description>
</module>
<module>
<Timestamp>131795790154254642</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2770000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\SSCORE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основная DLL-библиотека службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2940000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CSystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Classic System Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac29f0000</BaseAddress>
<Size>159744</Size>
<Path>c:\windows\system32\NetSetupApi.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Configuration API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2a40000</BaseAddress>
<Size>974848</Size>
<Path>c:\windows\system32\iphlpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Эта служба предоставляет автоматическое подключение IPv6 в сети IPv4.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2c60000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\WDSCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Panther Engine Module</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\System32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\System32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3360000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\wpncore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Ядро извещающих уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\system32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3740000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3b40000</BaseAddress>
<Size>245760</Size>
<Path>c:\windows\system32\wbem\wmisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac3fa0000</BaseAddress>
<Size>331776</Size>
<Path>c:\windows\system32\srvsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) ресурсов для службы сервера</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4160000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\wpnservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба системы push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4220000</BaseAddress>
<Size>520192</Size>
<Path>C:\Windows\SYSTEM32\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4480000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\taskcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оснастка обратной совместимости диспетчера задач</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4540000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\ProximityServicePAL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service PAL</Description>
</module>
<module>
<Timestamp>131795775380234927</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\browser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы браузера компьютеров</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4cc0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ProximityCommonPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Common PAL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4dc0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\ProximityCommon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Универсальная реализация близкого взаимодействия</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4ee0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\ProximityService.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proximity Service Implementation</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac5ef0000</BaseAddress>
<Size>868352</Size>
<Path>C:\Windows\System32\MbaeApiPublic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Mobile Broadband Account API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\SYSTEM32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786151642053</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7700000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\CredentialMigrationHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Migration Handler</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac79d0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\sqmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SQM Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795783776936389</Timestamp>
<BaseAddress>0x7ffac7ce0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\usoapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Session Orchestrator API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7d60000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\UpdatePolicy.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Policy Reader</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac7e90000</BaseAddress>
<Size>749568</Size>
<Path>c:\windows\system32\FVEAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows BitLocker Drive Encryption API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac82d0000</BaseAddress>
<Size>643072</Size>
<Path>c:\windows\system32\shsvcs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL служб оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8590000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\LocationWinPalMisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Location Platform Abstraction Layer</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac85c0000</BaseAddress>
<Size>1810432</Size>
<Path>c:\windows\system32\LocationFramework.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа географического положения Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8780000</BaseAddress>
<Size>274432</Size>
<Path>c:\windows\system32\UBPM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL единого диспетчера фоновых процессов</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8b60000</BaseAddress>
<Size>966656</Size>
<Path>c:\windows\system32\schedsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба планировщика заданий</Description>
</module>
<module>
<Timestamp>131795783774133461</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac91c0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\profsvcext.dll</Path>
<Version>10.0.14393.1532 (rs1_release_d.170711-1840)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvcExt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92a0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\sens.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба уведомления о системных событиях (SENS)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92c0000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\themeservice.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы темы оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9420000</BaseAddress>
<Size>380928</Size>
<Path>c:\windows\system32\profsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ProfSvc</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9a70000</BaseAddress>
<Size>1257472</Size>
<Path>c:\windows\system32\gpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca100000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\httpprxc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Proxy Manager Provider RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca1f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\storageusage.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Usage</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca250000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\bi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Broker Infrastructure Client Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca700000</BaseAddress>
<Size>32768</Size>
<Path>c:\windows\system32\DABAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Desktop Activity Broker API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaca720000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\system32\bitsigd.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service IGD Support</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacab70000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\lfsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба географического положения</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac40000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\seclogon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL службы вторичного входа</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacac50000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\bitsperf.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Perfmon Counter Access</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacad70000</BaseAddress>
<Size>278528</Size>
<Path>c:\windows\system32\BrokerLib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Broker Base Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb000000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\SYSNTFY.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Notifications Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\resourcepolicyclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\firewallapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6e0000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\MSWSOCK.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc500000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\EventAggregation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Event Aggregation User Mode Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\WLDAP32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376622</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>25</ProcessIndex>
<ProcessId>372</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776305463443</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>c:\windows\system32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab91f0000</BaseAddress>
<Size>233472</Size>
<Path>c:\windows\system32\sstpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обеспечивает возможность использования SSTP для подключения к удаленным компьютерам с помощью VPN.</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795780812578370</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabc610000</BaseAddress>
<Size>540672</Size>
<Path>c:\windows\system32\w32time.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба времени Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabef00000</BaseAddress>
<Size>499712</Size>
<Path>c:\windows\system32\cdpsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба CDP Майкрософт (R)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf2d0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\system32\ncryptprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft KSP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05e0000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\sbservicetrigger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Socket Broker Service Trigger</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1160000</BaseAddress>
<Size>892928</Size>
<Path>C:\Windows\System32\wuapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Центра обновления Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>c:\windows\system32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795780812550384</Timestamp>
<BaseAddress>0x7ffac3290000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\fthsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль диагностики отказоустойчивой кучи Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>c:\windows\system32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4130000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\fdphost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба размещения поставщиков функций обнаружения</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac41a0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdproxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery Proxy Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4200000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\perftrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Performance PerfTrack</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac5b80000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\AuthBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API WinRT для веб-проверки подлинности</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac66e0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\fdssdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery SSDP Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac6960000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\fdwsd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Function Discovery WS Discovery Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac76d0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\vmictimeprovider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Virtual Machine Integration Component Time Sync Provider Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7a10000</BaseAddress>
<Size>544768</Size>
<Path>c:\windows\system32\netprofmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер списка сетей</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7d20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\msauserext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSA USER Extension DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac7f70000</BaseAddress>
<Size>49152</Size>
<Path>c:\windows\system32\licensemanagersvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManagerSvc</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>c:\windows\system32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90a0000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\nsisvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>RPC-сервер интерфейса сохранения сети</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac91f0000</BaseAddress>
<Size>172032</Size>
<Path>c:\windows\system32\FontProvider.dll</Path>
<Version>10.0.14393.1066 (rs1_release_sec.170327-1835)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Font Provider Library</Description>
</module>
<module>
<Timestamp>131795780812573070</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>c:\windows\system32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>c:\windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9860000</BaseAddress>
<Size>1896448</Size>
<Path>c:\windows\system32\fntcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэша шрифтов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>c:\windows\system32\es.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca130000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\windows.devices.radios.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Radios DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca280000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaca500000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\wups.dll</Path>
<Version>10.0.14393.2122 (rs1_release.180217-2341)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Update client proxy stub</Description>
</module>
<module>
<Timestamp>131795780812567382</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376755</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>26</ProcessIndex>
<ProcessId>360</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311216195</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffabaad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\deviceaccess.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Broker And Policy COM Server</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac7e70000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\coreaudiopolicymanagerext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;coreaudiopolicymanagerext.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac87d0000</BaseAddress>
<Size>237568</Size>
<Path>c:\windows\system32\AUDIOSRVPOLICYMANAGER.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Audio Service Policy Manager</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac90d0000</BaseAddress>
<Size>978944</Size>
<Path>c:\windows\system32\audiosrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба Windows Audio</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>c:\windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\POWRPROF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376855</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>27</ProcessIndex>
<ProcessId>1040</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776311708649</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8820000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SYSTEM32\cmintegrator.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>cmintegrator.dll</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8c50000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\system32\wcmcsp.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Service Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac8fe0000</BaseAddress>
<Size>737280</Size>
<Path>c:\windows\system32\wcmsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы диспетчера подключений Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645376955</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>28</ProcessIndex>
<ProcessId>1068</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776312395030</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkService</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffab1fd0000</BaseAddress>
<Size>2277376</Size>
<Path>C:\Windows\System32\msxml3.dll</Path>
<Version>8.110.14393.1532</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 3.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\system32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>c:\windows\system32\CRYPTNET.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac34c0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\system32\vss_ps.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Service proxy/stub</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6410000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\VssTrace.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека трассировки службы теневого копирования тома Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6430000</BaseAddress>
<Size>1581056</Size>
<Path>C:\Windows\system32\VSSAPI.DLL</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\cryptcatsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Catalog Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac65f0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\crypttpmeksvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic TPM Endorsement Key Services</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6680000</BaseAddress>
<Size>102400</Size>
<Path>c:\windows\system32\cryptsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\DSPARSE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac6f00000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\wkssvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы рабочей станции</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac79e0000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\SYSTEM32\netjoin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL присоединения к домену</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\system32\WlanApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7c00000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\ssdpapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8260000</BaseAddress>
<Size>425984</Size>
<Path>c:\windows\system32\ncsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Индикатор работоспособности сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8370000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\nlasvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба сведений о подключенных сетях 2</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8410000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dnsext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DNS extension DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SYSTEM32\Fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8830000</BaseAddress>
<Size>290816</Size>
<Path>c:\windows\system32\dnsrslvr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба кэширующего сопоставителя DNS</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>c:\windows\system32\WMICLNT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9bb0000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\ES.DLL</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>c:\windows\system32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\JoinUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377076</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>29</ProcessIndex>
<ProcessId>1248</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776322176070</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>spoolsv.exe</ProcessName>
<ImagePath>C:\Windows\System32\spoolsv.exe</ImagePath>
<CommandLine>C:\Windows\System32\spoolsv.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Диспетчер очереди печати</Description>
<modulelist>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ff639680000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\spoolsv.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер очереди печати</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffab8a60000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaba980000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\jscript.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabb7d0000</BaseAddress>
<Size>851968</Size>
<Path>C:\Windows\System32\win32spl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик печати с исполнением на стороне клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\prntvpt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Ticket Services Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabbd70000</BaseAddress>
<Size>3346432</Size>
<Path>C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_53d78f68bc1697cc\Amd64\PrintConfig.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Пользовательский интерфейс PrintConfig</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc0c0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPFILEQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPFILEQ</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc590000</BaseAddress>
<Size>118784</Size>
<Path>C:\Program Files\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc5b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\amsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Anti-Malware Scan Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd040000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\fdPnp.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Pnp Provider Dll</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd060000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\WSDMon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер порта принтера WSD</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd100000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\usbmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Standard Dynamic Printing Port Monitor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd160000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\wsnmp32.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft WinSNMP v2.0 Manager API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabd2a0000</BaseAddress>
<Size>1159168</Size>
<Path>C:\Windows\System32\localspl.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека локального диспетчера очереди</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabde60000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\System32\tcpmon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека монитора портов TCP/IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe3f0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\spool\PRTPROCS\x64\winprint.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Print Processor DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe6c0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\PrintIsolationProxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Print Sandbox COM Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe8a0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\snmpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SNMP Utility Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabe980000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\SPOOLSS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Spooler SubSystem DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac0af0000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f00000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\FXSMON.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft  Fax Print Monitor</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac1f30000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\SPINF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows SPINF</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac4e90000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\wshirda.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Sockets Helper DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac7e00000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\inetpp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Internet Print Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377182</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>30</ProcessIndex>
<ProcessId>1512</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131765776336551242</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffabe9f0000</BaseAddress>
<Size>258048</Size>
<Path>c:\windows\system32\ssdpsrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL службы SSDP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6400000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\HTTPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>HTTP Protocol Stack API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6710000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\FunDisc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>c:\windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69b0000</BaseAddress>
<Size>57344</Size>
<Path>c:\windows\system32\fdrespub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба публикации ресурсов обнаружения функции</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>c:\windows\system32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>c:\windows\system32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>c:\windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377290</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>31</ProcessIndex>
<ProcessId>1556</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776339471770</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k utcsvc</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x272f9bf0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\DEVRTL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabcf50000</BaseAddress>
<Size>921600</Size>
<Path>C:\Windows\System32\drvstore.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Driver Store API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\aepic.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf140000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\CourtesyEngine.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Feedback Courtesy Engine DLL Server</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabfde0000</BaseAddress>
<Size>143360</Size>
<Path>c:\windows\system32\CRYPTXML.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API-интерфейс XML DigSig</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>c:\windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\Netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4070000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\SYSTEM32\DSREG.DLL</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>AD/AAD User Device Registration</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac5fd0000</BaseAddress>
<Size>1056768</Size>
<Path>c:\windows\system32\WindowsPerformanceRecorderControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Performance Recorder Control Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>c:\windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6210000</BaseAddress>
<Size>2007040</Size>
<Path>c:\windows\system32\diagtrack.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диагностическое отслеживание Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786489787144</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>c:\windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795786490911252</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>c:\windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377395</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>32</ProcessIndex>
<ProcessId>1636</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776343009549</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k appmodel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>c:\windows\system32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>c:\windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3c10000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\tileobjserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер моделей данных плиток</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>c:\windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>c:\windows\system32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>c:\windows\system32\windows.staterepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795780599947775</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795780600943570</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377489</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>33</ProcessIndex>
<ProcessId>1744</ProcessId>
<ParentProcessId>4</ParentProcessId>
<ParentProcessIndex>9</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765776348255325</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>MemCompression</ProcessName>
<ImagePath>MemCompression</ImagePath>
<CommandLine></CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
</modulelist>
</process>
<process>
<ProcessIndex>34</ProcessIndex>
<ProcessId>2100</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765776438403561</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffabff90000</BaseAddress>
<Size>409600</Size>
<Path>c:\windows\system32\ipsecsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows IPsec SPD Server DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac1e00000</BaseAddress>
<Size>114688</Size>
<Path>c:\windows\system32\FwRemoteSvr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Firewall Remote APIs Server</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>c:\windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>c:\windows\system32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>c:\windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacb960000</BaseAddress>
<Size>303104</Size>
<Path>c:\windows\system32\AUTHZ.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>Authorization Framework</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377758</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>35</ProcessIndex>
<ProcessId>2648</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777555980720</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>sihost.exe</ProcessName>
<ImagePath>C:\Windows\system32\sihost.exe</ImagePath>
<CommandLine>sihost.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Shell Infrastructure Host</Description>
<modulelist>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ff7bbae0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\sihost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shell Infrastructure Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb910000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\System32\container.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Containers</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabb970000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\daxexec.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>daxexec</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc450000</BaseAddress>
<Size>741376</Size>
<Path>C:\Windows\system32\ShareHost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShareHost</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc570000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\licensemanagerapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;LicenseManagerApi.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc800000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\windowmanagement.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Window Management</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc850000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\AppointmentActivation.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL for AppointmentActivation</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\system32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc8b0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\NotificationPlatformComponent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationPlatformComponent</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\system32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabc9a0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\activationmanager.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Activation Manager</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabca10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\ClipboardServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Modern Clipboard</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcde0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Windows\System32\modernexecserver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Modern Execution</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabcf10000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\system32\desktopshellext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DesktopHost Extensions</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3270000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\FLTLIB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\system32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\Windows.Storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377872</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>36</ProcessIndex>
<ProcessId>840</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777563791648</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\system32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\system32\svchost.exe -k UnistackSvcGroup</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\system32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf6a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\PhoneUtil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Phone utilities</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaaf700000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\System32\PIMSTORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>POOM</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab05d0000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\AccountAccessor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync data model to access accounts</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab0630000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\SyncController.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SyncController for managing sync of mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb20000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\System32\CEMAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>CEMAPI</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcb70000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\System32\cdprt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP Client WinRT API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabcd80000</BaseAddress>
<Size>360448</Size>
<Path>c:\windows\system32\cdpusersvc.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft (R) CDP User Components</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabd630000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\MCCSEngineShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Utilies shared among OneSync engines</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabdde0000</BaseAddress>
<Size>462848</Size>
<Path>c:\windows\system32\SYNCUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Sync utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabed20000</BaseAddress>
<Size>389120</Size>
<Path>c:\windows\system32\aphostservice.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2590000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\FlightSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры цикла тестирования</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>c:\windows\system32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>c:\windows\system32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4100000</BaseAddress>
<Size>151552</Size>
<Path>c:\windows\system32\NetworkHelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network utilities for mail, contacts, calendar</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>c:\windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffac97b0000</BaseAddress>
<Size>81920</Size>
<Path>c:\windows\system32\InprocLogger.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>In-proc Private Event Trace Logger</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca1d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\UserDataTypeHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Type Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca270000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\UserDataLanguageUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Language-related helper functions for user data</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca520000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\APHostClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Accounts Host Service RPC Client </Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacabf0000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\MCCSPal.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform abstraction layer dll for MCCS</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacac20000</BaseAddress>
<Size>86016</Size>
<Path>c:\windows\system32\UserDataPlatformHelperUtil.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform Utilities for data access</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>c:\windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>c:\windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>c:\windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf30000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\system32\NtlmShared.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NTLM Shared Functionality</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacbf40000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\msv1_0.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Authentication Package v1.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc010000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\cryptdll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptography Manager</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>c:\windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>c:\windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>c:\windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>c:\windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>c:\windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645377971</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>37</ProcessIndex>
<ProcessId>528</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777565618284</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\system32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\system32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb440000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\system32\MTFServer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;MTFServer.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb510000</BaseAddress>
<Size>2854912</Size>
<Path>C:\Windows\system32\InputService.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Text InputService Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8c0000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\system32\InputLocaleManager.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;InputLocaleManager.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb8f0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\EditBufferTestHook.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;EditBufferTestHook.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabb9f0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\system32\MSUTB.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека (DLL) сервера MSUTB</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabba70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\MsCtfMonitor.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MsCtfMonitor DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabbc20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\PlaySndSrv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба PlaySound</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\system32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac37d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac4140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\system32\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac7d10000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\KBDUS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>United States Keyboard Layout</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffac97d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca180000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\system32\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\system32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab10000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\WordBreakers.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;WordBreakers.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\system32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378085</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>38</ProcessIndex>
<ProcessId>3632</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765777941176116</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>RuntimeBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\RuntimeBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\RuntimeBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Runtime Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7808b0000</BaseAddress>
<Size>8527872</Size>
<Path>C:\Windows\system32\ntoskrnl.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>NT Kernel &amp; System</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ff7a45f0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\RuntimeBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Runtime Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaac6e0000</BaseAddress>
<Size>13156352</Size>
<Path>C:\Windows\System32\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795780843802542</Timestamp>
<BaseAddress>0x7ffaad3f0000</BaseAddress>
<Size>1826816</Size>
<Path>C:\Windows\System32\Wpc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека параметров родительского контроля</Description>
</module>
<module>
<Timestamp>131795786292112107</Timestamp>
<BaseAddress>0x7ffab08d0000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\LockAppBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL брокера приложения &quot;Блокировка&quot; Windows</Description>
</module>
<module>
<Timestamp>131795786164057245</Timestamp>
<BaseAddress>0x7ffab0b10000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\mssvp.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа Vista MSSearch</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7780000</BaseAddress>
<Size>2576384</Size>
<Path>C:\Windows\system32\mssrch.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Встроенный поиск (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\TQUERY.DLL</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\System32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795780489291214</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab92e0000</BaseAddress>
<Size>827392</Size>
<Path>C:\Windows\system32\Windows.Storage.Search.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Storage.Search</Description>
</module>
<module>
<Timestamp>131795786088780638</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786148630640</Timestamp>
<BaseAddress>0x7ffabaad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\deviceaccess.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Broker And Policy COM Server</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabba80000</BaseAddress>
<Size>995328</Size>
<Path>C:\Windows\System32\twinui.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI.APPCORE</Description>
</module>
<module>
<Timestamp>131795786089047958</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795780613006289</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795780733496994</Timestamp>
<BaseAddress>0x7ffabc6b0000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\AppContracts.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер API Windows AppContracts</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795780611542837</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795786306767518</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786143522657</Timestamp>
<BaseAddress>0x7ffabd220000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\Windows.Devices.Enumeration.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Enumeration</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabdd60000</BaseAddress>
<Size>425984</Size>
<Path>C:\Windows\System32\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe070000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\efswrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Storage Protection Windows Runtime DLL</Description>
</module>
<module>
<Timestamp>131795786165227211</Timestamp>
<BaseAddress>0x7ffabe130000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\mapi32.dll</Path>
<Version>1.0.2536.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенный MAPI 1.0 для Windows NT</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795786089826857</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe880000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\FeClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT File Encryption Client Interfaces</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabe8c0000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\system32\windows.cortana.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.Desktop</Description>
</module>
<module>
<Timestamp>131795786151786571</Timestamp>
<BaseAddress>0x7ffabf030000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\LocationFrameworkInternalPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework Internal PS</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780443980999</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf8c0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\system32\Windows.Internal.Shell.Broker.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Broker</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabf9c0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\system32\windows.cortana.onecore.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.OneCore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795786445101159</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac05f0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\wwapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>WWAN API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac09d0000</BaseAddress>
<Size>884736</Size>
<Path>C:\Windows\System32\wpnapps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Приложения для push-уведомлений Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795779561161209</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786075081206</Timestamp>
<BaseAddress>0x7ffac15d0000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Core.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Model Core API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\RMCLIENT.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\system32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780447369522</Timestamp>
<BaseAddress>0x7ffac37b0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\system32\ESENT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795771234179313</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\ShellCommonCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ShellCommon Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795780489961900</Timestamp>
<BaseAddress>0x7ffac4df0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\provsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Домашняя группа Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac4f60000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\wcmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Connection Manager Client API</Description>
</module>
<module>
<Timestamp>131795780846908833</Timestamp>
<BaseAddress>0x7ffac4fd0000</BaseAddress>
<Size>618496</Size>
<Path>C:\Windows\System32\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\System32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac5ca0000</BaseAddress>
<Size>200704</Size>
<Path>C:\Windows\System32\AppExtension.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API AppExtension</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786144114651</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795786145514308</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6a90000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\LocationFrameworkPS.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Geolocation Framework PS</Description>
</module>
<module>
<Timestamp>131795786287854312</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ba0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac6ec0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786448623381</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7aa0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Windows\SYSTEM32\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac7d00000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SYSTEM32\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795780849625720</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786090201282</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\samlib.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795780611842861</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\system32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\system32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645378207</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>39</ProcessIndex>
<ProcessId>3164</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778119045372</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ShellExperienceHost.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe&quot; -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Description>Windows Shell Experience Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ff697570000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Shell Experience Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffa9f760000</BaseAddress>
<Size>3796992</Size>
<Path>C:\Windows\System32\MFMediaEngine.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Media Engine DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaabad0000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\mfsrcsnk.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Source and Sink DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaafe70000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\System32\mfcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Core DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab0be0000</BaseAddress>
<Size>1421312</Size>
<Path>C:\Windows\ShellExperiences\NetworkUX.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab4af0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SYSTEM32\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffab9eb0000</BaseAddress>
<Size>2899968</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.ActionCenter.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActionCenter Experience</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaba180000</BaseAddress>
<Size>7880704</Size>
<Path>C:\Windows\ShellExperiences\StartUI.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Start UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabab30000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\System32\NotificationObjFactory.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Notifications Object Factory</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SYSTEM32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd420000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\RTMediaFrame.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime MediaFrame DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe410000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\SYSTEM32\globcollationhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GlobCollationHost</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795780594734370</Timestamp>
<BaseAddress>0x7ffabfb00000</BaseAddress>
<Size>626688</Size>
<Path>C:\Windows\System32\ContentDeliveryManager.Utilities.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>ContentDeliveryManager.Utilities</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0080000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\System32\resampledmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Resampler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0110000</BaseAddress>
<Size>290816</Size>
<Path>C:\Windows\SYSTEM32\QuickActionsDataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>QuickActionsDataModel</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0160000</BaseAddress>
<Size>491520</Size>
<Path>C:\Windows\ShellExperiences\QuickActions.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac40f0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac4eb0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\SYSTEM32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5b20000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SYSTEM32\CompPkgSup.DLL</Path>
<Version>10.0.14393.969 (rs1_release_inmarket.170315-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Component Package Support DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac5e90000</BaseAddress>
<Size>380928</Size>
<Path>C:\Windows\System32\Windows.Media.MediaControl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL сервера MediaControl среды выполнения Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84e0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\NotificationControllerPS.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NotificationController Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8f90000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения мультимедиа в реальном времени</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\System32\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca550000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\winsta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379346</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>40</ProcessIndex>
<ProcessId>4856</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778391112136</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MSASCuiL.exe</ProcessName>
<ImagePath>C:\Program Files\Windows Defender\MSASCuiL.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Windows Defender\MSASCuiL.exe&quot; </CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Description>Windows Defender notification icon</Description>
<modulelist>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x23622c70000</BaseAddress>
<Size>733184</Size>
<Path>C:\Program Files\Windows Defender\EppManifest.dll</Path>
<Version>4.10.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль ресурсов настройки пользовательского интерфейса</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ff63bef0000</BaseAddress>
<Size>651264</Size>
<Path>C:\Program Files\Windows Defender\MSASCuiL.exe</Path>
<Version>4.10.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Defender notification icon</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4560000</BaseAddress>
<Size>950272</Size>
<Path>C:\Program Files\Windows Defender\mpclient.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>Client Interface</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\SYSTEM32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379462</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>41</ProcessIndex>
<ProcessId>4928</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778406250112</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>uTorrent.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe&quot;  /MINIMIZED</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>3.5.4.44498</Version>
<Description>µTorrent</Description>
<modulelist>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>5406720</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe</Path>
<Version>3.5.4.44498</Version>
<Company>BitTorrent Inc.</Company>
<Description>µTorrent</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e140000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\SysWOW64\upnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API контрольной точки UPnP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\ATL.DLL</Path>
<Version>3.05.2284</Version>
<Company>Microsoft Corporation</Company>
<Description>ATL Module for Windows XP (Unicode)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6e1c0000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\SysWOW64\hnetcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигурации домашней сети</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6ef20000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70af0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fc0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fd0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73fe0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379614</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>42</ProcessIndex>
<ProcessId>3608</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778496229053</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>ApplicationFrameHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\ApplicationFrameHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\ApplicationFrameHost.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Application Frame Host</Description>
<modulelist>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ff6aa270000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\system32\ApplicationFrameHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Frame Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\TWINAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5240000</BaseAddress>
<Size>1114112</Size>
<Path>C:\Windows\System32\ApplicationFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фрейм приложения</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\system32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795786034558955</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\system32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\system32\D3D10Warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\system32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCORE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379722</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>43</ProcessIndex>
<ProcessId>5952</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765778883326814</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54150_1240996307 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645379833</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>44</ProcessIndex>
<ProcessId>5800</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765779120650795</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\SYSTEM32\esent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\system32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645379938</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>45</ProcessIndex>
<ProcessId>340</ProcessId>
<ParentProcessId>4928</ParentProcessId>
<ParentProcessIndex>41</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131765800389528045</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>1</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>utorrentie.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe&quot; uTorrent_4928_02D54870_1839591030 µTorrent4823DF041B09 uTorrent</CommandLine>
<CompanyName>BitTorrent Inc.</CompanyName>
<Version>1.0.0</Version>
<Description>WebHelper</Description>
<modulelist>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x1180000</BaseAddress>
<Size>417792</Size>
<Path>C:\Users\User\AppData\Roaming\uTorrent\updates\3.5.4_44498\utorrentie.exe</Path>
<Version>1.0.0</Version>
<Company>BitTorrent Inc.</Company>
<Description>WebHelper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63490000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\dinput8.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectInput</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x634d0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\DSOUND.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectSound</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x63560000</BaseAddress>
<Size>23334912</Size>
<Path>C:\Windows\SysWOW64\Macromed\Flash\Flash.ocx</Path>
<Version>29,0,0,140</Version>
<Company>Adobe Systems, Inc.</Company>
<Description>Adobe Flash Player 29.0 r0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\AUDIOSES.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70c50000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\Ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645380038</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>46</ProcessIndex>
<ProcessId>2736</ProcessId>
<ParentProcessId>3976</ParentProcessId>
<ParentProcessIndex>47</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765800903010156</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Taskmgr.exe</ProcessName>
<ImagePath>C:\Windows\System32\Taskmgr.exe</ImagePath>
<CommandLine>&quot;C:\Windows\System32\Taskmgr.exe&quot; /2 </CommandLine>
<CompanyName>Microsoft® Windows® Operating System</CompanyName>
<Version>1, 0, 0, 1</Version>
<Description>Task Manager</Description>
<modulelist>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ff7c2a70000</BaseAddress>
<Size>1286144</Size>
<Path>C:\Windows\System32\Taskmgr.exe</Path>
<Version>1, 0, 0, 1</Version>
<Company>Microsoft® Windows® Operating System</Company>
<Description>Task Manager</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\DUser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\System32\TwinUI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\DUI70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabdfa0000</BaseAddress>
<Size>393216</Size>
<Path>C:\Windows\System32\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac21b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\srumapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Resource Usage Monitor API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\System32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\system32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacac60000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\System32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645380149</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>49</ProcessIndex>
<ProcessId>6724</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803507001117</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHActiveDefense.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe&quot;</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1008</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795778431738530</Timestamp>
<BaseAddress>0x10000</BaseAddress>
<Size>413696</Size>
<Path>C:\ProgramData\Package Cache\{b8e12890-118d-4721-8e54-05d978086712}\VC_redist.x64.exe</Path>
<Version>14.0.24516.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24516</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0xd0000</BaseAddress>
<Size>983040</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe</Path>
<Version>10,0,0,1008</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795778469924367</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files\Wireshark\WinPcap_4_1_3.exe</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>WinPcap 4.1.3 installer</Description>
</module>
<module>
<Timestamp>131795778203065490</Timestamp>
<BaseAddress>0x840000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files\Wireshark\vcredist_x64.exe</Path>
<Version>14.12.25810.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810</Description>
</module>
<module>
<Timestamp>131795786058722021</Timestamp>
<BaseAddress>0x34c0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\browser_broker.exe</Path>
<Version>11.00.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>Browser_Broker</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x3c80000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795780944214585</Timestamp>
<BaseAddress>0x40a0000</BaseAddress>
<Size>438272</Size>
<Path>C:\Program Files\Wireshark\dumpcap.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community</Company>
<Description>Dumpcap</Description>
</module>
<module>
<Timestamp>131795780231568066</Timestamp>
<BaseAddress>0x4630000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SysWOW64\net1.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Command</Description>
</module>
<module>
<Timestamp>131795778389953959</Timestamp>
<BaseAddress>0xa8e0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786140191230</Timestamp>
<BaseAddress>0xe830000</BaseAddress>
<Size>2416640</Size>
<Path>C:\Windows\System32\smartscreen.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreen</Description>
</module>
<module>
<Timestamp>131795780691287613</Timestamp>
<BaseAddress>0xf730000</BaseAddress>
<Size>8298496</Size>
<Path>C:\Program Files\Wireshark\Wireshark.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark</Description>
</module>
<module>
<Timestamp>131795780222197886</Timestamp>
<BaseAddress>0x10000000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fb90000</BaseAddress>
<Size>2736128</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\deepscan.dll</Path>
<Version>3, 5, 1, 2130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60190000</BaseAddress>
<Size>475136</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360SafeCamera.tpi</Path>
<Version>2, 0, 0, 1031</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60210000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\jcloudscan.dll</Path>
<Version>1, 0, 0, 1012</Version>
<Company>360.cn</Company>
<Description>360安全卫士 移动云查询模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604a0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appdext.dll</Path>
<Version>1, 0, 0, 1483</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x604e0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\DrvUtility.dll</Path>
<Version>1, 0, 0, 1081</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60510000</BaseAddress>
<Size>409600</Size>
<Path>C:\Program Files (x86)\360\Total Security\SafeScan.dll</Path>
<Version>1, 0, 0, 1074</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60580000</BaseAddress>
<Size>204800</Size>
<Path>C:\Program Files (x86)\360\Total Security\ScanStub.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Scan Util Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x605c0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360gameidentify.dll</Path>
<Version>1, 0, 1, 1050</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏识别模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60640000</BaseAddress>
<Size>430080</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\Netgm.dll</Path>
<Version>9,0,0,1005</Version>
<Company>360.cn</Company>
<Description>360流量防火墙 游戏模式判断模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60a50000</BaseAddress>
<Size>479232</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\DsSysRepair.dll</Path>
<Version>1, 0, 0, 1062</Version>
<Company>QIHU360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security System Repair Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61000000</BaseAddress>
<Size>184320</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\qutmipc.dll</Path>
<Version>7, 3, 0, 1267</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61030000</BaseAddress>
<Size>262144</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg.dll</Path>
<Version>3, 0, 0, 1160</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x610d0000</BaseAddress>
<Size>1097728</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\SomAdvUtils.dll</Path>
<Version>3, 1, 1, 2020</Version>
<Company>360.cn</Company>
<Description>360 Safeguard PC Boost</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61480000</BaseAddress>
<Size>2191360</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qex\qex.dll</Path>
<Version>4.1.13.3366</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2017 Antivirus</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x616a0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SelfProtectAPI2.dll</Path>
<Version>7, 1, 1, 1033</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61700000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360procmon.dll</Path>
<Version>7, 1, 1, 1221</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61780000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\netdefender.dll</Path>
<Version>1, 0, 0, 1129</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x617e0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\appd.dll</Path>
<Version>7, 3, 6, 3113</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360HipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61ab0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\fileMgr.dll</Path>
<Version>7, 3, 0, 1963</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x621a0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\yhregd.dll</Path>
<Version>7, 2, 0, 1903</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62280000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files (x86)\360\Total Security\SoftMgr\360SoftMgrS.dll</Path>
<Version>2, 1, 6, 1490</Version>
<Company>360.cn</Company>
<Description>360软件管家 服务模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62470000</BaseAddress>
<Size>405504</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll</Path>
<Version>7, 2, 1, 1279</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x624e0000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\360box.dll</Path>
<Version>2, 0, 0, 1043</Version>
<Company>360.cn</Company>
<Description>360隔离沙箱模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\deepscan\DsRes.dll</Path>
<Version>1,0,0,1012</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security Resource</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x62b70000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\gamemode.tpi</Path>
<Version>9,0,0,1001</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security Game Mode Control</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67130000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\devenum.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Перечисление устройств.</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x676b0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\fltlib.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека фильтров</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6c0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\msdmo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DMO Runtime</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6ea80000</BaseAddress>
<Size>860160</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\QVM\360QVM.dll</Path>
<Version>5.0.2.1003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security QVM Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70210000</BaseAddress>
<Size>966656</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEngine.dll</Path>
<Version>1, 0, 0, 2016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70300000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\ave\AVEI.dll</Path>
<Version>1, 0, 0, 2003</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 AntiVirus Engine</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381706</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>50</ProcessIndex>
<ProcessId>6340</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765803510844292</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>QHSafeTray.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</ImagePath>
<CommandLine>/showtrayicon</CommandLine>
<CompanyName>Qihoo 360 Technology Co. Ltd.</CompanyName>
<Version>10,0,0,1024</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0xec0000</BaseAddress>
<Size>2351104</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe</Path>
<Version>10,0,0,1024</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x68f0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5c480000</BaseAddress>
<Size>245760</Size>
<Path>C:\Program Files (x86)\360\Total Security\PDown.dll</Path>
<Version>1, 3, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Security Center Network Module </Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x5fe30000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll</Path>
<Version>9,6,0,1001</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60020000</BaseAddress>
<Size>413696</Size>
<Path>C:\Program Files (x86)\360\Total Security\netmon\360netctrl.dll</Path>
<Version>5, 3, 15, 2232</Version>
<Company>360.cn</Company>
<Description>360 Total Security NetwokrMonCtrl</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60090000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\netmon.tpi</Path>
<Version>5, 1, 1, 3157</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360安全卫士 流量防火墙模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60350000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Program Files (x86)\360\Total Security\ToolBox.dll</Path>
<Version>1, 0, 0, 1094</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60600000</BaseAddress>
<Size>200704</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll</Path>
<Version>1, 0, 1, 1130</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x606b0000</BaseAddress>
<Size>598016</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe.dll</Path>
<Version>1, 0, 0, 1120</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x608d0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemonhlp.dll</Path>
<Version>1, 0, 0, 1265</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x609b0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360GuardBase.dll</Path>
<Version>3, 1, 0, 1060</Version>
<Company>360.cn</Company>
<Description>360保镖</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ad0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\360Common.dll</Path>
<Version>7, 3, 0, 3233</Version>
<Company>360.cn</Company>
<Description>360安全衛士 基礎模塊</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60b30000</BaseAddress>
<Size>1712128</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi</Path>
<Version>3, 1, 1, 3140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x60ce0000</BaseAddress>
<Size>581632</Size>
<Path>C:\Program Files (x86)\360\Total Security\dynlenv.dll</Path>
<Version>1, 1, 0, 1016</Version>
<Company>360.cn</Company>
<Description>dynlenv Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61070000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SomProxy.dll</Path>
<Version>1, 0, 0, 1900</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x611e0000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360connect.tpi</Path>
<Version>9,2,0,1030</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Connect</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61380000</BaseAddress>
<Size>315392</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360bsmon.tpi</Path>
<Version>6, 8, 0, 1248</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Active Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\MSVCR90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x618c0000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Program Files (x86)\360\Total Security\sites.dll</Path>
<Version>11, 1, 0, 1212</Version>
<Company>360.cn</Company>
<Description>360安全卫士</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61a30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\360hipsPopWnd.dll</Path>
<Version>7,3,2,1211</Version>
<Company>Qihoo 360 Technology Co. Ltd.</Company>
<Description>360 Internet Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61b30000</BaseAddress>
<Size>3350528</Size>
<Path>C:\Program Files (x86)\360\Total Security\softmgr\somkernl.dll</Path>
<Version>2, 1, 0, 1130</Version>
<Company>360.cn</Company>
<Description>360软件管家</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61e70000</BaseAddress>
<Size>614400</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\ipcservice.dll</Path>
<Version>7, 1, 2, 1643</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Proactive Defense</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x61f10000</BaseAddress>
<Size>1458176</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\Cloudcom2.dll</Path>
<Version>3, 3, 10, 1288</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62210000</BaseAddress>
<Size>446464</Size>
<Path>C:\Program Files (x86)\360\Total Security\360TSCommon.dll</Path>
<Version>9, 0, 0, 1016</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62370000</BaseAddress>
<Size>602112</Size>
<Path>C:\Program Files (x86)\360\Total Security\360util.dll</Path>
<Version>1.0.0.1485</Version>
<Company>360.cn</Company>
<Description>360安全卫士 公共模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62410000</BaseAddress>
<Size>352256</Size>
<Path>C:\Program Files (x86)\360\Total Security\CrashReport.dll</Path>
<Version>7, 0, 0, 1000</Version>
<Company>360.cn</Company>
<Description>360杀毒 异常捕获程序</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62540000</BaseAddress>
<Size>278528</Size>
<Path>C:\Program Files (x86)\360\Total Security\360conf.dll</Path>
<Version>1, 0, 0, 1014</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62590000</BaseAddress>
<Size>987136</Size>
<Path>C:\Program Files (x86)\360\Total Security\360base.dll</Path>
<Version>1, 0, 0, 1165</Version>
<Company>360.cn</Company>
<Description>360安全卫士 基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62690000</BaseAddress>
<Size>266240</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll</Path>
<Version>2.0.0.1191</Version>
<Company>360.cn</Company>
<Description>BAPI</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62960000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\CleanPlusCache.tpi</Path>
<Version>1, 0, 0, 1004</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>CleanPlusCache</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x676a0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files (x86)\360\Total Security\ipc\x64for32lib.dll</Path>
<Version>6, 8, 0, 1059</Version>
<Company>360.cn</Company>
<Description>360安全卫士 木马防火墙模块</Description>
</module>
<module>
<Timestamp>131795771279916892</Timestamp>
<BaseAddress>0x68850000</BaseAddress>
<Size>2764800</Size>
<Path>C:\Windows\SysWOW64\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\i18n.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e6e0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6e770000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SysWOW64\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c00000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\SysWOW64\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c10000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\napinsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71170000</BaseAddress>
<Size>466944</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\CQhCltHttpW.dll</Path>
<Version>1, 4, 0, 1030</Version>
<Company>QIHU 360 SOFTWARE  CO. LIMITED</Company>
<Description>360 Internet Security Base Module</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ef0000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\MSIMG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDIEXT Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381850</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>51</ProcessIndex>
<ProcessId>6860</ProcessId>
<ParentProcessId>6724</ParentProcessId>
<ParentProcessIndex>49</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131765803555957830</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>QHWatchdog.exe</ProcessName>
<ImagePath>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</ImagePath>
<CommandLine>&quot;C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe&quot; /watch</CommandLine>
<CompanyName>QIHU 360 SOFTWARE CO. LIMITED</CompanyName>
<Version>8,2,0,1000</Version>
<Description>360 Total Security</Description>
<modulelist>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0xdf0000</BaseAddress>
<Size>139264</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe</Path>
<Version>8,2,0,1000</Version>
<Company>QIHU 360 SOFTWARE CO. LIMITED</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645381936</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>52</ProcessIndex>
<ProcessId>5924</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:000003e4</AuthenticationId>
<CreateTime>131765805232900810</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\NETWORK SERVICE</Owner>
<ProcessName>wmiprvse.exe</ProcessName>
<ImagePath>C:\Windows\sysWOW64\wbem\wmiprvse.exe</ImagePath>
<CommandLine>C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Description>WMI Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x950000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\sysWOW64\wbem\wmiprvse.exe</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Provider Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\FastProx.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\storagewmi_passthru.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60140000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\wbem\wmiutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x60160000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\NCObjAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x604d0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\delegatorprovider.dll</Path>
<Version>10.0.14393.103 (rs1_release_inmarket.160819-1924)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI PassThru Provider for Storage Management</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x755e0000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382027</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>54</ProcessIndex>
<ProcessId>4408</ProcessId>
<ParentProcessId>348</ParentProcessId>
<ParentProcessIndex>24</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131765812380694767</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>taskhostw.exe</ProcessName>
<ImagePath>C:\Windows\system32\taskhostw.exe</ImagePath>
<CommandLine>taskhostw.exe</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для задач Windows</Description>
<modulelist>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x17826230000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ff794e10000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\system32\taskhostw.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для задач Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1140000</BaseAddress>
<Size>1134592</Size>
<Path>C:\Windows\System32\ReAgent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab1c40000</BaseAddress>
<Size>1302528</Size>
<Path>C:\Windows\System32\LicenseManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>LicenseManager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffab93b0000</BaseAddress>
<Size>897024</Size>
<Path>C:\Windows\System32\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\system32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\system32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabbd20000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\settingsyncpolicy.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SettingSync Policy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe000000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\system32\WinSATAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Assessment Tool API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\system32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf050000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\System32\sdiageng.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема выполнения сценариев диагностики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabfbe0000</BaseAddress>
<Size>1011712</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime OnlineId Authentication DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2750000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\bcd.dll</Path>
<Version>10.0.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCD DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\CLIPC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4050000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\System32\wdi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура диагностики Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4ae0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sdiagschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запланированная задача сценариев проверки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac4b00000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\MemoryDiagnostic.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач средства проверки памяти Windows (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac5c80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\TempSignedLicenseExchangeTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TempSignedLicenseExchangeTask Task</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795790155731176</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795790158890250</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\system32\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\system32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca200000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\ReAgentTask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Обработчик задач агента восстановления Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca210000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\RstrtMgr.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер перезапуска</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacac00000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\radarrs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>программа устранения нехватки системных ресурсов Microsoft Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\system32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\system32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\system32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\system32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382224</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>55</ProcessIndex>
<ProcessId>6944</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131767576301455145</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SkypeHost.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe&quot; -ServerName:SkypeHost.ServerServer</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>12.1815.210.0</Version>
<Description>Microsoft Skype</Description>
<modulelist>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ff7e8670000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaae130000</BaseAddress>
<Size>22437888</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkyWrap.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabc530000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.HostName.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking.HostName DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabe150000</BaseAddress>
<Size>2691072</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\skypert.dll</Path>
<Version>2018.15.01.31</Version>
<Company></Company>
<Description>SkypeRT shared library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1a80000</BaseAddress>
<Size>978944</Size>
<Path>C:\Windows\SYSTEM32\Windows.Networking.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Networking DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2b30000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\usermgrproxy.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgrProxy</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7c80000</BaseAddress>
<Size>208896</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll</Path>
<Version>12.1815.210.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Skype</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\SYSTEM32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>56</ProcessIndex>
<ProcessId>1048</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131768729449405953</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>sedsvc.exe</ProcessName>
<ImagePath>C:\Program Files\rempl\sedsvc.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\rempl\sedsvc.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Description>sedsvc</Description>
<modulelist>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ff751430000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\rempl\sedsvc.exe</Path>
<Version>10.0.16299.10000 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>sedsvc</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffac8cf0000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\System32\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SYSTEM32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382485</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>57</ProcessIndex>
<ProcessId>7744</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081112364684</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; </CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x11330000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x60900000</BaseAddress>
<Size>720896</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\urlproc.dll</Path>
<Version>2, 9, 5, 1260</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security 2013 Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x622f0000</BaseAddress>
<Size>520192</Size>
<Path>C:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll</Path>
<Version>3, 8, 11, 1</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security Cloud Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x62980000</BaseAddress>
<Size>376832</Size>
<Path>C:\Program Files (x86)\360\Total Security\360NetBase.dll</Path>
<Version>7, 25, 0, 76</Version>
<Company>360.cn</Company>
<Description>360安全卫士 网络基础模块</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x68b00000</BaseAddress>
<Size>44998656</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6b6d0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6bf00000</BaseAddress>
<Size>3715072</Size>
<Path>C:\Windows\SysWOW64\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ce30000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6dc80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files (x86)\Windows Defender\MpOav.dll</Path>
<Version>4.10.14393.1794 (rs1_release.171008-1615)</Version>
<Company>Microsoft Corporation</Company>
<Description>IOfficeAntiVirus Module</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6df70000</BaseAddress>
<Size>245760</Size>
<Path>C:\Windows\SysWOW64\shdocvw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека объектов документов и элементов управления оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e070000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SysWOW64\MSACM32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Фильтр диспетчера аудиосжатия Microsoft</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e090000</BaseAddress>
<Size>233472</Size>
<Path>C:\Windows\SysWOW64\wdmaud.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системный звуковой драйвер Winmm</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e110000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\midimap.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MIDI Mapper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e120000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\msacm32.drv</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Программа переназначения звуковых устройств</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e130000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\AVRT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multimedia Realtime Runtime</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e2a0000</BaseAddress>
<Size>4440064</Size>
<Path>C:\Windows\SysWOW64\explorerframe.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb60000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\ksuser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User CSA Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eb70000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ec40000</BaseAddress>
<Size>442368</Size>
<Path>C:\Windows\SysWOW64\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6eed0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fc70000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SysWOW64\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd00000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\SysWOW64\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd20000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fd60000</BaseAddress>
<Size>360448</Size>
<Path>C:\Windows\SysWOW64\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fdc0000</BaseAddress>
<Size>507904</Size>
<Path>C:\Windows\SysWOW64\audioses.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сеанс обработки звука</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe40000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\BitsProxy.dll</Path>
<Version>7.8.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Background Intelligent Transfer Service Proxy</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe50000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SysWOW64\mstask.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека интерфейса планировщика заданий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6fe90000</BaseAddress>
<Size>544768</Size>
<Path>C:\Windows\SysWOW64\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ff90000</BaseAddress>
<Size>323584</Size>
<Path>C:\Windows\SysWOW64\wlanapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WLAN AutoConfig Client Side API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x6ffe0000</BaseAddress>
<Size>303104</Size>
<Path>C:\Windows\SysWOW64\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70140000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SysWOW64\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70190000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\LINKINFO.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x701a0000</BaseAddress>
<Size>401408</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\dllyupdate.dll</Path>
<Version>1.2.0.1831</Version>
<Company>Yandex LLC</Company>
<Description>Yandex updater (CU)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70a40000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\NLAapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b30000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\WINUSB.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows USB Driver User Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b60000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\HID.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека пользователя HID</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ba0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70bd0000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x711f0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\IconCodecService.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Converts a PNG part of the icon to a legacy bmp icon</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74040000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b40000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SysWOW64\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c30000</BaseAddress>
<Size>372736</Size>
<Path>C:\Windows\SysWOW64\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382623</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>58</ProcessIndex>
<ProcessId>5696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081114193232</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe --type=crashpad-handler &quot;--user-data-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler &quot;--database=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data\Crashpad&quot; &quot;--metrics-dir=C:\Users\User\AppData\Local\Yandex\YandexBrowser\User Data&quot; --url=https://crash-reports.browser.yandex.net/submit --annotation=machine_id=c46245ef0fec9d5c44d2fa20241f2070 --annotation=main_process_pid=7744 --annotation=metrics_client_id=520f4dd3247d4cdfb744f32b1130b1bf --annotation=plat=Win32 --annotation=prod=Yandex --annotation=ver=18.6.1.770 --initial-client-data=0x1c4,0x1cc,0x1d0,0x1c0,0x1d4,0x700b800c,0x700b7ffc,0x700b7fe0,0x1c8</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\WKSCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382726</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>59</ProcessIndex>
<ProcessId>4664</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081123844756</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=gpu-process --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --service-request-channel-token=CC1AC8FA9C8EFF1EEBC2375FE4F704C6 --mojo-platform-channel-handle=1588 --ignored=&quot; --type=renderer &quot; /prefetch:2</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ecb0000</BaseAddress>
<Size>2228224</Size>
<Path>C:\Windows\SysWOW64\mfh264enc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation H264 Encoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f250000</BaseAddress>
<Size>970752</Size>
<Path>C:\Windows\SysWOW64\ddraw.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectDraw</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f340000</BaseAddress>
<Size>3784704</Size>
<Path>C:\Windows\SysWOW64\D3DCompiler_47.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D HLSL Compiler</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f6e0000</BaseAddress>
<Size>688128</Size>
<Path>C:\Windows\SysWOW64\msvproc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Video Processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fbe0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\mf.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6fd30000</BaseAddress>
<Size>139264</Size>
<Path>C:\Windows\SysWOW64\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff20000</BaseAddress>
<Size>118784</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\swiftshader\libegl.dll</Path>
<Version>4.0.0.3</Version>
<Company></Company>
<Description>SwiftShader libEGL 32-bit Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dxva2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Video Acceleration 2.0 DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x705d0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\DCIMAN32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DCI Manager</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\SETUPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382836</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>60</ProcessIndex>
<ProcessId>8968</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081206363215</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=183F52B8A6577BFD721F95F3A9641348 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=183F52B8A6577BFD721F95F3A9641348 --renderer-client-id=4 --mojo-platform-channel-handle=2640 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645382953</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>61</ProcessIndex>
<ProcessId>4992</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131769081244357280</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --service-pipe-token=7E8A8199C364F4B0114F2A163B757250 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E8A8199C364F4B0114F2A163B757250 --renderer-client-id=10 --mojo-platform-channel-handle=3904 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645383069</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>63</ProcessIndex>
<ProcessId>9504</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956266598229</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgent.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgent.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgent.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>InstallAgent</Description>
<modulelist>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ff63d380000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\InstallAgent.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffabea60000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\VEStoreEventHandlers.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>TDL Store Event Handlers</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4450000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\usermgrcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>UserMgr API DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4ad0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\EAMProgressHandler.dll</Path>
<Version>10.0.14393.479 (rs1_release.161110-2025)</Version>
<Company>Microsoft Corporation</Company>
<Description>EAMProgressHandler</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\Bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383260</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>64</ProcessIndex>
<ProcessId>8768</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956321853179</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>InstallAgentUserBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\InstallAgentUserBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\InstallAgentUserBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>InstallAgentUserBroker</Description>
<modulelist>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x22530450000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ff74f890000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\System32\InstallAgentUserBroker.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>InstallAgentUserBroker</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\SYSTEM32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\sfc_os.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabefd0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\AEPIC.dll</Path>
<Version>10.0.17060.1029 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Application Experience Program Cache</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\system32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\System32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\system32\schannel.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\SYSTEM32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\OLE32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383355</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>65</ProcessIndex>
<ProcessId>9636</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956424585250</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettingsBroker.exe</ProcessName>
<ImagePath>C:\Windows\System32\SystemSettingsBroker.exe</ImagePath>
<CommandLine>C:\Windows\System32\SystemSettingsBroker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>System Settings Broker</Description>
<modulelist>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ff6015f0000</BaseAddress>
<Size>196608</Size>
<Path>C:\Windows\System32\SystemSettingsBroker.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Broker</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383490</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>66</ProcessIndex>
<ProcessId>10592</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794956519902643</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SystemSettings.exe</ProcessName>
<ImagePath>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</ImagePath>
<CommandLine>&quot;C:\Windows\ImmersiveControlPanel\SystemSettings.exe&quot; -ServerName:microsoft.windows.immersivecontrolpanel</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Параметры</Description>
<modulelist>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x18099ef0000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SYSTEM32\WMI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI DC and DP functionality</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ff7937a0000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Параметры</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaabce0000</BaseAddress>
<Size>2535424</Size>
<Path>C:\Windows\System32\NetworkMobileSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System settings network mobile handlers group</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaac220000</BaseAddress>
<Size>4952064</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettings.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Application</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaadd90000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\NetworkDesktopSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Группа обработчиков системных параметров сетевого рабочего стола</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaaf920000</BaseAddress>
<Size>905216</Size>
<Path>C:\Windows\ImmersiveControlPanel\SystemSettingsViewModel.Desktop.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings View Model Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0970000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\system32\credprovhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост инфраструктуры поставщика учетных данных</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab0a70000</BaseAddress>
<Size>454656</Size>
<Path>C:\Windows\System32\fhcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Диспетчер конфигураций истории файлов</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab1d80000</BaseAddress>
<Size>262144</Size>
<Path>C:\Windows\SYSTEM32\eappcfg.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Eap Peer Config</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab7d80000</BaseAddress>
<Size>753664</Size>
<Path>C:\Windows\SYSTEM32\RASAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API удаленного доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab8190000</BaseAddress>
<Size>9191424</Size>
<Path>C:\Windows\system32\twinui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>TWINUI</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab91d0000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\ImmersiveControlPanel\Telemetry.Desktop.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>System Settings Telemetry Desktop</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffab9a40000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\RasMediaManager.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ras Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaba950000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\EthernetMediaManager.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ethernet Media Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaa50000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\NetworkUXBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>NetworkUXBroker DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\system32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcc60000</BaseAddress>
<Size>1122304</Size>
<Path>C:\Windows\System32\MiracastReceiver.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API приемника Miracast</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SRVCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\SYSTEM32\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2a20000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SYSTEM32\rtutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Routing Utilities</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac2bf0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\EFSUTIL.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>EFS Utility Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac4e70000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\SYSTEM32\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac5c50000</BaseAddress>
<Size>131072</Size>
<Path>C:\Windows\SYSTEM32\rasman.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access Connection Manager</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\Comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\SYSTEM32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac76a0000</BaseAddress>
<Size>159744</Size>
<Path>C:\Windows\SYSTEM32\sppc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7990000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\SLC.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Software Licensing Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac8880000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SYSTEM32\wmiclnt.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Client API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9220000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wevtapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API настройки и использования событий</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9290000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\DSROLE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DS Setup Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca4e0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SYSTEM32\WTSAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca560000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\NcaApi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Network Connectivity Assistant API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SYSTEM32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc5c0000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SYSTEM32\WINSTA.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Winstation Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>67</ProcessIndex>
<ProcessId>10964</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794956837373387</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>DllHost.exe</ProcessName>
<ImagePath>C:\Windows\system32\DllHost.exe</ImagePath>
<CommandLine>C:\Windows\system32\DllHost.exe /Processid:{BA126F01-2166-11D1-B1D0-00805FC1270E}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>COM Surrogate</Description>
<modulelist>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ff7a2280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\system32\DllHost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM Surrogate</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffab2460000</BaseAddress>
<Size>2822144</Size>
<Path>C:\Windows\system32\netshell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Оболочка сетевых подключений</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\system32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\SHLWAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645383742</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>76</ProcessIndex>
<ProcessId>11496</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131794958406617238</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>SearchUI.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe&quot; -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Description>Search and Cortana application</Description>
<modulelist>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ff79c3c0000</BaseAddress>
<Size>10706944</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Search and Cortana application</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\SYSTEM32\chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\SYSTEM32\MLANG.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\SYSTEM32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab4c70000</BaseAddress>
<Size>4874240</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab52c0000</BaseAddress>
<Size>2445312</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\SYSTEM32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5840000</BaseAddress>
<Size>3108864</Size>
<Path>C:\Windows\System32\Speech_OneCore\Common\sapi_onecore.dll</Path>
<Version>5.3.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Speech API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab5db0000</BaseAddress>
<Size>9781248</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab7a00000</BaseAddress>
<Size>3424256</Size>
<Path>C:\Windows\system32\tquery.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Запросы Microsoft Tripoli</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffab9d50000</BaseAddress>
<Size>1429504</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabae40000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SYSTEM32\capauthz.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API авторизации возможностей</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\SYSTEM32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb200000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;CortanaApi.ProxyStub.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SYSTEM32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe770000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabea90000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background System Events Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabefa0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\system32\Cortana.Persona.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana.Persona</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\SYSTEM32\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabf8a0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\Windows.Cortana.ProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.ProxyStub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\SYSTEM32\wincorlib.DLL</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac10b0000</BaseAddress>
<Size>217088</Size>
<Path>C:\Windows\system32\PersonaX.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>PersonaX</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac1c40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\SystemSettings.DataModel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SystemSettings.Datamodel private API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\SYSTEM32\NInput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2c30000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SYSTEM32\clipc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент платформы лицензирования клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac2d80000</BaseAddress>
<Size>5140480</Size>
<Path>C:\Windows\SYSTEM32\cdp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API клиента Microsoft (R) CDP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SYSTEM32\Cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\system32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3bf0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionMgr.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cortana Action Manager</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\SYSTEM32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5070000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\Windows.Web.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL веб-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\SYSTEM32\UIAutomationCore.DLL</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SYSTEM32\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\SYSTEM32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bb0000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\system32\windows.cortana.pal.desktop.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Cortana.PAL.Desktop</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\SYSTEM32\OLEACC.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\system32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7c50000</BaseAddress>
<Size>118784</Size>
<Path>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\BingConfigurationClient.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Bing Configuration Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7d80000</BaseAddress>
<Size>49152</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Background.TimeBroker.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Time Broker API Server</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9480000</BaseAddress>
<Size>462848</Size>
<Path>C:\Windows\SYSTEM32\MMDevAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MMDevice API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca260000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\SystemEventsBrokerClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>system Events Broker Client Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\SYSTEM32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\SYSTEM32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SYSTEM32\DEVOBJ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\SYSTEM32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\SYSTEM32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\SYSTEM32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SYSTEM32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\SYSTEM32\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780654647361</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385613</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>79</ProcessIndex>
<ProcessId>5612</ProcessId>
<ParentProcessId>904</ParentProcessId>
<ParentProcessIndex>22</ParentProcessIndex>
<AuthenticationId>00000000:000003e5</AuthenticationId>
<CreateTime>131794965205293998</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\LOCAL SERVICE</Owner>
<ProcessName>dashost.exe</ProcessName>
<ImagePath>C:\Windows\system32\dashost.exe</ImagePath>
<CommandLine>dashost.exe {609e1ffd-7b4d-4dbc-a36f725917d81f2d}</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Description>Device Association Framework Provider Host</Description>
<modulelist>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ff6559c0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\system32\dashost.exe</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Framework Provider Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabb1a0000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\system32\DAFWSD.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF WSD Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffabc970000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\system32\dafupnp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DAF UPnP Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\system32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac3f60000</BaseAddress>
<Size>225280</Size>
<Path>C:\Windows\system32\FWPolicyIOMgr.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>FwPolicyIoMgr DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\system32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wship6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника Winsock2 (TL/IPv6)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac66d0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\system32\wshtcpip.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы Winsock2 (TL/IPv4)</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6700000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\system32\wshqos.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL помощника службы QoS Winsock2</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6750000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\system32\webservices.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Среда выполнения веб-служб Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac68b0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\system32\wsdapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-службы для библиотек DLL API-интерфейсов устройств</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\system32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\system32\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac7e50000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\system32\SSDPAPI.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>SSDP Client API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SYSTEM32\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\system32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\system32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\system32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\system32\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\system32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\system32\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\system32\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\system32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\system32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645385987</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>80</ProcessIndex>
<ProcessId>9720</ProcessId>
<ParentProcessId>9180</ParentProcessId>
<ParentProcessIndex>81</ParentProcessIndex>
<AuthenticationId>00000000:0031f1ab</AuthenticationId>
<CreateTime>131794969418818027</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Высокий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Windows10UpgraderApp.exe</ProcessName>
<ImagePath>C:\Windows10Upgrade\Windows10UpgraderApp.exe</ImagePath>
<CommandLine>&quot;C:\Windows10Upgrade\Windows10UpgraderApp.exe&quot;  /Install /ClientID Win10Upgrade:VNL:NHV18:{} /SkipEULA /PostEosUi</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>1.4.9200.22452</Version>
<Description>Помощник по обновлению Windows 10</Description>
<modulelist>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0xb30000</BaseAddress>
<Size>1875968</Size>
<Path>C:\Windows10Upgrade\Windows10UpgraderApp.exe</Path>
<Version>1.4.9200.22452</Version>
<Company>Microsoft Corporation</Company>
<Description>Помощник по обновлению Windows 10</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5fec0000</BaseAddress>
<Size>794624</Size>
<Path>C:\Windows\SysWOW64\wbem\fastprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI Custom Marshaller</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x5ffa0000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SysWOW64\wbemcomn.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60010000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\wbem\wbemprox.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WMI</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x627d0000</BaseAddress>
<Size>249856</Size>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\mshtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c720000</BaseAddress>
<Size>2318336</Size>
<Path>C:\Windows\SysWOW64\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\WLDP.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d6e0000</BaseAddress>
<Size>634880</Size>
<Path>C:\Windows\SysWOW64\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d780000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\SysWOW64\mrmcorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6d860000</BaseAddress>
<Size>1245184</Size>
<Path>C:\Windows\SysWOW64\MFC42u.dll</Path>
<Version>6.06.8063.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека MFCDLL - розничная версия</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6ded0000</BaseAddress>
<Size>630784</Size>
<Path>C:\Windows\SysWOW64\ODBC32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ODBC Driver Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfc0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6dfd0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SysWOW64\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e010000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows10Upgrade\Downloader.dll</Path>
<Version>1.4.9200.22452 (win8_ldr.180426-0600)</Version>
<Company>Microsoft Corporation</Company>
<Description>Downloader</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e050000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x6e710000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\SysWOW64\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x705e0000</BaseAddress>
<Size>344064</Size>
<Path>C:\Windows\SysWOW64\OLEACC.DLL</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70640000</BaseAddress>
<Size>1499136</Size>
<Path>C:\Windows\SysWOW64\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70b70000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\SysWOW64\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645386103</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>82</ProcessIndex>
<ProcessId>8944</ProcessId>
<ParentProcessId>520</ParentProcessId>
<ParentProcessIndex>18</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795005508439638</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>fontdrvhost.exe</ProcessName>
<ImagePath>C:\Windows\system32\fontdrvhost.exe</ImagePath>
<CommandLine>&quot;fontdrvhost.exe&quot;</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Usermode Font Driver Host</Description>
<modulelist>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ff654db0000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\system32\fontdrvhost.exe</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Usermode Font Driver Host</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645386388</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>83</ProcessIndex>
<ProcessId>6684</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795006053748558</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Microsoft.Photos.exe</ProcessName>
<ImagePath>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe&quot; -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca</CommandLine>
<CompanyName></CompanyName>
<Version></Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ff705e40000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bb10000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bc70000</BaseAddress>
<Size>3158016</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9bf80000</BaseAddress>
<Size>2994176</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9c260000</BaseAddress>
<Size>20144128</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9d5a0000</BaseAddress>
<Size>29011968</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9f150000</BaseAddress>
<Size>6311936</Size>
<Path>C:\Windows\System32\Windows.Media.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Media Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffa9fb20000</BaseAddress>
<Size>7950336</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.3_1.3.24201.0_x64__8wekyb3d8bbwe\SharedLibrary.dll</Path>
<Version></Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Shared Framework</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa03f0000</BaseAddress>
<Size>4546560</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\FaceSdkStoreWrapper.dll</Path>
<Version>16.425.0.0</Version>
<Company>Microsoft Corporation</Company>
<Description>FaceSdkStoreWrapper</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaa0850000</BaseAddress>
<Size>2371584</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\MediaEngine.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab270000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\System32\Windows.AccountsControl.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Accounts Control</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaab750000</BaseAddress>
<Size>876544</Size>
<Path>C:\Windows\System32\Windows.Media.Import.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Photo Import API (WinRT/COM)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaac0c0000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.Phone.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows UI XAML Phone API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\SYSTEM32\dwrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f40000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\Windows.System.Diagnostics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows System Diagnostics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab8f60000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\CryptoWinRT.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto WinRT Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9270000</BaseAddress>
<Size>454656</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffab9b40000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x64__8wekyb3d8bbwe\mrt100_app.dll</Path>
<Version>1.4.24201.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\SYSTEM32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\system32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc5c0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SYSTEM32\MFSENSORGROUP.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Sensor Group DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\execmodelclient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabd8e0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_0d5aa7fbb6d35646\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\system32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabea30000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\Windows.Energy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Energy Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffabfe10000</BaseAddress>
<Size>237568</Size>
<Path>C:\Windows\SYSTEM32\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SYSTEM32\windows.ui.core.textinput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0470000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\SYSTEM32\MFPlat.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0910000</BaseAddress>
<Size>724992</Size>
<Path>C:\Windows\System32\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac0fa0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1b90000</BaseAddress>
<Size>630784</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\MSVCP140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1c70000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCOMP140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C/C++ OpenMP Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac1e50000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SYSTEM32\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2c00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35063.44410.0_x64__8wekyb3d8bbwe\clrcompression.dll</Path>
<Version>1.0.23123.00 built by: PROJECTKREL</Version>
<Company>Microsoft Corporation</Company>
<Description>ClrCompression</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac2cb0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SYSTEM32\winsqlite3.dll</Path>
<Version>3.12.2</Version>
<Company>SQLite Development Team</Company>
<Description>SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3280000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SYSTEM32\mrt100.dll</Path>
<Version>1.0.24120.0 built by: PROJECTNREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft .NET Native Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\SYSTEM32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\SYSTEM32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4b10000</BaseAddress>
<Size>307200</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\CONCRT140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Concurrency Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac4c60000</BaseAddress>
<Size>385024</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\vccorlib140_app.DLL</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® VC WinRT core library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SYSTEM32\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\SYSTEM32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SYSTEM32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\SYSTEM32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\system32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8540000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\vaultcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека хранилища учетных данных</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\SYSTEM32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac8fa0000</BaseAddress>
<Size>253952</Size>
<Path>C:\Windows\SYSTEM32\logoncli.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Logon Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\SYSTEM32\wintypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\system32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\system32\windowscodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\SYSTEM32\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\SYSTEM32\Bcp47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\SYSTEM32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\SYSTEM32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\SYSTEM32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacab80000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\WindowsApps\Microsoft.VCLibs.140.00_14.0.25426.0_x64__8wekyb3d8bbwe\VCRUNTIME140_APP.dll</Path>
<Version>14.11.25426.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\system32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\system32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\SYSTEM32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\SYSTEM32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SYSTEM32\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SYSTEM32\CRYPTBASE.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\SYSTEM32\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SYSTEM32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\OleAut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\KERNEL32.DLL</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\GDI32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660438</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>84</ProcessIndex>
<ProcessId>6208</ProcessId>
<ParentProcessId>12140</ParentProcessId>
<ParentProcessIndex>85</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795181740423780</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>OneDrive.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</ImagePath>
<CommandLine> /updateInstalled /background</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>18.131.0701.0007</Version>
<Description>Microsoft OneDrive</Description>
<modulelist>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x11f0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x55a0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSync.Resources.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x64d00000</BaseAddress>
<Size>5079040</Size>
<Path>C:\Windows\SysWOW64\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x651e0000</BaseAddress>
<Size>20537344</Size>
<Path>C:\Windows\SysWOW64\MSHTML.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Средство просмотра HTML Microsoft®</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x66580000</BaseAddress>
<Size>12247040</Size>
<Path>C:\Windows\SysWOW64\ieframe.dll</Path>
<Version>11.00.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Браузер</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67200000</BaseAddress>
<Size>1978368</Size>
<Path>C:\Windows\SysWOW64\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\ActXPrxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b670000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\SysWOW64\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6b6b0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6bab0000</BaseAddress>
<Size>4472832</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Widgets.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\dataexchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c540000</BaseAddress>
<Size>483328</Size>
<Path>C:\Windows\SysWOW64\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c5c0000</BaseAddress>
<Size>1384448</Size>
<Path>C:\Windows\SysWOW64\uiautomationcore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c960000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6c970000</BaseAddress>
<Size>3698688</Size>
<Path>C:\Windows\SysWOW64\jscript9.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® JScript</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd20000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\SysWOW64\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cd50000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\SAMLIB.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6cf60000</BaseAddress>
<Size>569344</Size>
<Path>C:\Windows\SysWOW64\taskschd.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Task Scheduler COM API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d080000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d0b0000</BaseAddress>
<Size>847872</Size>
<Path>C:\Windows\SysWOW64\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6d210000</BaseAddress>
<Size>4993024</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Gui.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x6fcd0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\dbgcore.DLL</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707b0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70a80000</BaseAddress>
<Size>409600</Size>
<Path>C:\Windows\SysWOW64\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b00000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\Wscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API центра обеспечения безопасности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\SysWOW64\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70cc0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\ondemandconnroutehelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70ce0000</BaseAddress>
<Size>1519616</Size>
<Path>C:\Windows\SysWOW64\wpc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека параметров родительского контроля</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70e60000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\NTASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70f00000</BaseAddress>
<Size>815104</Size>
<Path>C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71200000</BaseAddress>
<Size>708608</Size>
<Path>C:\Windows\SysWOW64\TokenBroker.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x712b0000</BaseAddress>
<Size>602112</Size>
<Path>C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71350000</BaseAddress>
<Size>2867200</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Quick.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71610000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc6.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71630000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\wlidprov.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x716b0000</BaseAddress>
<Size>1294336</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LIBEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x717f0000</BaseAddress>
<Size>2637824</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Qml.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71a80000</BaseAddress>
<Size>4796416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Core.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x71f20000</BaseAddress>
<Size>6033408</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SyncEngine.DLL</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Sync Engine</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x724f0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\credui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Credential Manager User Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72530000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72550000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Networking Connectivity Runtime DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72810000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\familysafetyext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>FamilySafety ChildAccount Extensions</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72820000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\SysWOW64\MicrosoftAccountTokenProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Token Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72850000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\SysWOW64\AppXDeploymentClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека клиента развертывания AppX</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728b0000</BaseAddress>
<Size>135168</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncFAL.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDriveFile Sync FAL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a30000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\SysWOW64\XmlLite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72a60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\SysWOW64\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72bb0000</BaseAddress>
<Size>1105920</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\platforms\qwindows.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\rometadata.dll</Path>
<Version>4.6.1586.0 built by: NETFXREL2</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft MetaData Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72e90000</BaseAddress>
<Size>299008</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\SSLEAY32.dll</Path>
<Version>1.0.2k</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ee0000</BaseAddress>
<Size>950272</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5Network.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72fd0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\loadperf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Загрузка и выгрузка счетчиков производительности</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x72ff0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\pdh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Модуль поддержки данных производительности Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73040000</BaseAddress>
<Size>253952</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Qt5WinExtras.dll</Path>
<Version>5.9.1.0</Version>
<Company>The Qt Company Ltd</Company>
<Description>C++ application development framework.</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73080000</BaseAddress>
<Size>880640</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ADAL.dll</Path>
<Version>1.0.2110.0526</Version>
<Company>Microsoft</Company>
<Description>ADAL.Native</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73160000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WSOCK32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73170000</BaseAddress>
<Size>352256</Size>
<Path>C:\Windows\SysWOW64\faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x731d0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\WnsClientApi.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive WNS Client Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73240000</BaseAddress>
<Size>520192</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LogUploader.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>OneDrive Sync LogUploader Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x732c0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncViews.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Qt Components</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73400000</BaseAddress>
<Size>159744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\UpdateRingSettings.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Update Ring Settings</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73430000</BaseAddress>
<Size>1748992</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncSessions.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>P2P Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x735e0000</BaseAddress>
<Size>671744</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\RemoteAccess.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73690000</BaseAddress>
<Size>188416</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\Telemetry.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Telemetry Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736c0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ETWLog.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>ETW Session Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x736d0000</BaseAddress>
<Size>3600384</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\FileSyncClient.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Client</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a40000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\WINNSI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\fwpuclnt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73aa0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\DPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73af0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\LoggingPlatform.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Logging Platform</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73c50000</BaseAddress>
<Size>1478656</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_f67438d2f2547a00\gdiplus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73dc0000</BaseAddress>
<Size>1171456</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\ucrtbase.dll</Path>
<Version>10.0.17134.12 (WinBuild.160101.0800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ee0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\wtsapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Remote Desktop Session Host Server SDK APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\DNSAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73fb0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\SysWOW64\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\MSWSOCK.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74090000</BaseAddress>
<Size>462848</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\MSVCP140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\UxTheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\CRYPTSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\VCRUNTIME140.dll</Path>
<Version>14.13.26020.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74220000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\TOKENBINDING.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74260000</BaseAddress>
<Size>2514944</Size>
<Path>C:\Windows\SysWOW64\WININET.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\MPR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\MSCTF.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660654</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>86</ProcessIndex>
<ProcessId>6140</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795747339404666</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=764E64A4EA650A23B18EB059FF0B4B51 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=764E64A4EA650A23B18EB059FF0B4B51 --renderer-client-id=106 --mojo-platform-channel-handle=6612 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660799</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>87</ProcessIndex>
<ProcessId>11432</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755605761168</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=9DD318D38190D474A9A0F5AFD262A449 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=9DD318D38190D474A9A0F5AFD262A449 --renderer-client-id=109 --mojo-platform-channel-handle=4152 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645660929</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>88</ProcessIndex>
<ProcessId>10384</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795755746873891</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=7E669976FFDCEE94D9B90B02CADE1179 --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=7E669976FFDCEE94D9B90B02CADE1179 --renderer-client-id=112 --mojo-platform-channel-handle=5412 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661053</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>90</ProcessIndex>
<ProcessId>6936</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795756360200321</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Ненадежный обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=73B8CB09F7D184AD1D3DDBFE4AFC07BA --renderer-client-id=116 --mojo-platform-channel-handle=4024 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\msauddecmft.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\WINSPOOL.DRV</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\SAMCLI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\USP10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\NETUTILS.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\NETAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\PROPSYS.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\WINHTTP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\Secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\WINMMBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\WINMM.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\COMCTL32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\VERSION.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\USERENV.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\CRYPTBASE.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\SspiCli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\IMM32.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\RPCRT4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\PSAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\shcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\WINTRUST.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\WS2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\MSASN1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KERNELBASE.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\CRYPT32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\ADVAPI32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\SHELL32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\USER32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptPrimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\OLEAUT32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\GDI32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\COMDLG32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\NSI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795770645661289</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\SYSTEM32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>98</ProcessIndex>
<ProcessId>6080</ProcessId>
<ParentProcessId>84</ParentProcessId>
<ParentProcessIndex>97</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795771125310655</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MCLauncher.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe&quot; </CommandLine>
<CompanyName></CompanyName>
<Version>1.0</Version>
<Description></Description>
<modulelist>
<module>
<Timestamp>131795771127806606</Timestamp>
<BaseAddress>0x400000</BaseAddress>
<Size>2830336</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Version>1.0</Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795771129292604</Timestamp>
<BaseAddress>0x750000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771335510731</Timestamp>
<BaseAddress>0x11000000</BaseAddress>
<Size>1396736</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771334241016</Timestamp>
<BaseAddress>0x12000000</BaseAddress>
<Size>360448</Size>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Version>1.0.2o</Version>
<Company>The OpenSSL Project, http://www.openssl.org/</Company>
<Description>OpenSSL Shared Library</Description>
</module>
<module>
<Timestamp>131795771129285523</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795771129286235</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795771129295328</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795771135408057</Timestamp>
<BaseAddress>0x60750000</BaseAddress>
<Size>1556480</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Version>8, 4, 0, 1420</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795771129575672</Timestamp>
<BaseAddress>0x613d0000</BaseAddress>
<Size>667648</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129398434</Timestamp>
<BaseAddress>0x66680000</BaseAddress>
<Size>12288</Size>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771136825814</Timestamp>
<BaseAddress>0x67500000</BaseAddress>
<Size>1597440</Size>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795771129423112</Timestamp>
<BaseAddress>0x67690000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795771129349562</Timestamp>
<BaseAddress>0x6b830000</BaseAddress>
<Size>2584576</Size>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Compatibility DLL</Description>
</module>
<module>
<Timestamp>131795771329638947</Timestamp>
<BaseAddress>0x6c290000</BaseAddress>
<Size>987136</Size>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795771329610149</Timestamp>
<BaseAddress>0x6c390000</BaseAddress>
<Size>1126400</Size>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795771329592759</Timestamp>
<BaseAddress>0x6c4b0000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795771136045859</Timestamp>
<BaseAddress>0x6cda0000</BaseAddress>
<Size>528384</Size>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795771131298623</Timestamp>
<BaseAddress>0x6d180000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Version>9.00.30729.9247</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795771136082794</Timestamp>
<BaseAddress>0x6dca0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Script Runtime</Description>
</module>
<module>
<Timestamp>131795771133718253</Timestamp>
<BaseAddress>0x6dcd0000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795771129406131</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795771329618480</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795771329601483</Timestamp>
<BaseAddress>0x707f0000</BaseAddress>
<Size>2293760</Size>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795771336447829</Timestamp>
<BaseAddress>0x70c30000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771135435621</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795771135446667</Timestamp>
<BaseAddress>0x70cb0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795771136073867</Timestamp>
<BaseAddress>0x70e90000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Version>5.812.10240.16384</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Script Host Runtime Library</Description>
</module>
<module>
<Timestamp>131795771135423397</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795771135552456</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795771136181434</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771328759427</Timestamp>
<BaseAddress>0x72b90000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795771135541570</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795771347140137</Timestamp>
<BaseAddress>0x73a50000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795771347110306</Timestamp>
<BaseAddress>0x73ab0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795771135314174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771347090516</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795771347075776</Timestamp>
<BaseAddress>0x73f30000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795771328179609</Timestamp>
<BaseAddress>0x73ff0000</BaseAddress>
<Size>319488</Size>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795771130913562</Timestamp>
<BaseAddress>0x74060000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795771135359123</Timestamp>
<BaseAddress>0x74110000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795771129415027</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795771130899582</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795771133098293</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795771132990161</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795771131765102</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795771129389543</Timestamp>
<BaseAddress>0x74710000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795771129317462</Timestamp>
<BaseAddress>0x74730000</BaseAddress>
<Size>598016</Size>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795771129360685</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795771129360034</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795771129496759</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795771129358136</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129357408</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795771129365891</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795771129359203</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795771129353720</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771135412052</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795771129350362</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795771129366695</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795771136054082</Timestamp>
<BaseAddress>0x74ef0000</BaseAddress>
<Size>540672</Size>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795771131750596</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795771129363162</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795771328737550</Timestamp>
<BaseAddress>0x75090000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795771135228888</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795771129301509</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795771129362062</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795771135227735</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795771129363985</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795771129356607</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795771129364960</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795771129354665</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795771129370252</Timestamp>
<BaseAddress>0x770c0000</BaseAddress>
<Size>4239360</Size>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795771129352041</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795771129367584</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795771129351257</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795771129361361</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795771129369244</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795771129368545</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795771131168008</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795771129352931</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795771133704572</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795771129355632</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795771347076821</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795771127807387</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795771127807116</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>104</ProcessIndex>
<ProcessId>12696</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777567759490</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=E83DB721798C8A70C76CD26F6F4EE1BC --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=E83DB721798C8A70C76CD26F6F4EE1BC --renderer-client-id=119 --mojo-platform-channel-handle=7052 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777567991690</Timestamp>
<BaseAddress>0xc00000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777567961139</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777569452751</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777567980184</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777567981270</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777567994943</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777570994535</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777570968696</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777570908362</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777570920904</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777570943637</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777570874151</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777570891841</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777568100773</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777570569484</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777570619251</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777570607590</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777570676211</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777570557202</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777570691164</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777570539079</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777569494420</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777570658737</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777569526517</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777569154123</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777570594964</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777570630821</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777570523174</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777570582120</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777570646486</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777570953652</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777569213807</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777568156054</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777569481011</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777568142933</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777568179155</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777568043561</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777568042430</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777569239058</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777568075566</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777568073430</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777568086784</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777568041126</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777568081914</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777568046844</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777568038347</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777568088134</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777569468247</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777569466798</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777568077279</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777569469408</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777568024100</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777568039823</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777569470854</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777568036731</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777568054568</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777568078714</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777568050811</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777568084892</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777568089486</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777568083413</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777568044758</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777569464930</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777569463567</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777568116745</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777568080182</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777569457550</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777568052363</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777570632192</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777567961904</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777567961630</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>106</ProcessIndex>
<ProcessId>5556</ProcessId>
<ParentProcessId>7744</ParentProcessId>
<ParentProcessIndex>57</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777595302537</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>0</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser.exe</ProcessName>
<ImagePath>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</ImagePath>
<CommandLine>&quot;C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe&quot; --type=renderer --enable-in-process-wmf-demuxer --field-trial-handle=1292,9555382311565764851,7120838982649204725,131072 --enable-ignition --disable-gpu-compositing --service-pipe-token=3ADFA2396247AD5E547F61590603D06D --lang=ru --user-id=32B2E0A1-3039-4C67-86BE-75A88EF21B54 --brand-id=yandex --partner-id=7924 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --translate-security-origin=https://translate.yandex.net --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-instaserp --device-scale-factor=1 --num-raster-threads=1 --enable-compositor-image-animations --service-request-channel-token=3ADFA2396247AD5E547F61590603D06D --renderer-client-id=121 --mojo-platform-channel-handle=6636 /prefetch:1</CommandLine>
<CompanyName>YANDEX LLC</CompanyName>
<Version>18.6.1.770</Version>
<Description>Yandex</Description>
<modulelist>
<module>
<Timestamp>131795777595490187</Timestamp>
<BaseAddress>0x1020000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595475498</Timestamp>
<BaseAddress>0x10e0000</BaseAddress>
<Size>2519040</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595491301</Timestamp>
<BaseAddress>0x5550000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777596381097</Timestamp>
<BaseAddress>0x58720000</BaseAddress>
<Size>59748352</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_child.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777595481485</Timestamp>
<BaseAddress>0x5c020000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\wow64.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 Emulation on NT64</Description>
</module>
<module>
<Timestamp>131795777595482474</Timestamp>
<BaseAddress>0x5c080000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Version>10.0.14393.1884 (rs1_release.171101-1233)</Version>
<Company>Microsoft Corporation</Company>
<Description>Wow64 Console and Win32 API Logging</Description>
</module>
<module>
<Timestamp>131795777595494304</Timestamp>
<BaseAddress>0x5c100000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>AMD64 Wow64 CPU </Description>
</module>
<module>
<Timestamp>131795777597543015</Timestamp>
<BaseAddress>0x6e8b0000</BaseAddress>
<Size>1859584</Size>
<Path>C:\Windows\SysWOW64\mfmp4srcsnk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL источника и приемника MPEG4 Media Foundation</Description>
</module>
<module>
<Timestamp>131795777597521210</Timestamp>
<BaseAddress>0x6ef30000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\SysWOW64\evr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека DLL средства отображения видео</Description>
</module>
<module>
<Timestamp>131795777597472595</Timestamp>
<BaseAddress>0x6efd0000</BaseAddress>
<Size>458752</Size>
<Path>C:\Windows\SysWOW64\MSAudDecMFT.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Audio Decoders</Description>
</module>
<module>
<Timestamp>131795777597484525</Timestamp>
<BaseAddress>0x6f790000</BaseAddress>
<Size>1085440</Size>
<Path>C:\Windows\SysWOW64\mfperfhelper.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MFPerf DLL</Description>
</module>
<module>
<Timestamp>131795777597497517</Timestamp>
<BaseAddress>0x6f8a0000</BaseAddress>
<Size>2220032</Size>
<Path>C:\Windows\SysWOW64\msmpeg2vdec.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DTV-DVD Video Decoder</Description>
</module>
<module>
<Timestamp>131795777597428793</Timestamp>
<BaseAddress>0x6fac0000</BaseAddress>
<Size>1130496</Size>
<Path>C:\Windows\SysWOW64\mfplat.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Media Foundation Platform DLL</Description>
</module>
<module>
<Timestamp>131795777597448444</Timestamp>
<BaseAddress>0x6ff60000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\SysWOW64\RTWorkQ.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL для WorkQueue реального времени</Description>
</module>
<module>
<Timestamp>131795777595565558</Timestamp>
<BaseAddress>0x70030000</BaseAddress>
<Size>593920</Size>
<Path>C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\18.6.1.770\browser_elf.dll</Path>
<Version>18.6.1.770</Version>
<Company>YANDEX LLC</Company>
<Description>Yandex</Description>
</module>
<module>
<Timestamp>131795777597103476</Timestamp>
<BaseAddress>0x700d0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795777597165296</Timestamp>
<BaseAddress>0x70340000</BaseAddress>
<Size>536576</Size>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777597153510</Timestamp>
<BaseAddress>0x703d0000</BaseAddress>
<Size>2056192</Size>
<Path>C:\Windows\SysWOW64\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795777597221087</Timestamp>
<BaseAddress>0x707d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\samcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Accounts Manager Client DLL</Description>
</module>
<module>
<Timestamp>131795777597072535</Timestamp>
<BaseAddress>0x70a20000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\SysWOW64\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795777597233493</Timestamp>
<BaseAddress>0x70ca0000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777597059294</Timestamp>
<BaseAddress>0x70fd0000</BaseAddress>
<Size>1331200</Size>
<Path>C:\Windows\SysWOW64\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795777596424202</Timestamp>
<BaseAddress>0x71140000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777597205195</Timestamp>
<BaseAddress>0x725e0000</BaseAddress>
<Size>2273280</Size>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777596436120</Timestamp>
<BaseAddress>0x728e0000</BaseAddress>
<Size>1372160</Size>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777596128973</Timestamp>
<BaseAddress>0x72af0000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\SysWOW64\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795777597128037</Timestamp>
<BaseAddress>0x72cc0000</BaseAddress>
<Size>1658880</Size>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777597177209</Timestamp>
<BaseAddress>0x73ac0000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\SysWOW64\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795777597044137</Timestamp>
<BaseAddress>0x73ae0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777597116160</Timestamp>
<BaseAddress>0x73f00000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795777597192860</Timestamp>
<BaseAddress>0x74190000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777597506812</Timestamp>
<BaseAddress>0x741b0000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777596148547</Timestamp>
<BaseAddress>0x741f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777595627397</Timestamp>
<BaseAddress>0x74230000</BaseAddress>
<Size>147456</Size>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777596410831</Timestamp>
<BaseAddress>0x744d0000</BaseAddress>
<Size>2138112</Size>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777595610560</Timestamp>
<BaseAddress>0x746e0000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777595638942</Timestamp>
<BaseAddress>0x746f0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SysWOW64\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777595529014</Timestamp>
<BaseAddress>0x747d0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795777595527983</Timestamp>
<BaseAddress>0x747e0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777596182171</Timestamp>
<BaseAddress>0x74800000</BaseAddress>
<Size>151552</Size>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777595541526</Timestamp>
<BaseAddress>0x74830000</BaseAddress>
<Size>917504</Size>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777595540326</Timestamp>
<BaseAddress>0x74910000</BaseAddress>
<Size>2170880</Size>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777595551866</Timestamp>
<BaseAddress>0x74b30000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777595526606</Timestamp>
<BaseAddress>0x74b60000</BaseAddress>
<Size>790528</Size>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777595547732</Timestamp>
<BaseAddress>0x74c30000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777595531563</Timestamp>
<BaseAddress>0x74d90000</BaseAddress>
<Size>24576</Size>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795777595524005</Timestamp>
<BaseAddress>0x74da0000</BaseAddress>
<Size>778240</Size>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777595553384</Timestamp>
<BaseAddress>0x74e60000</BaseAddress>
<Size>557056</Size>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777596396507</Timestamp>
<BaseAddress>0x74f80000</BaseAddress>
<Size>278528</Size>
<Path>C:\Windows\SysWOW64\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795777596394953</Timestamp>
<BaseAddress>0x74fd0000</BaseAddress>
<Size>405504</Size>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777595543299</Timestamp>
<BaseAddress>0x75040000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777596397607</Timestamp>
<BaseAddress>0x751d0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777595508927</Timestamp>
<BaseAddress>0x751e0000</BaseAddress>
<Size>1708032</Size>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777595525398</Timestamp>
<BaseAddress>0x75390000</BaseAddress>
<Size>266240</Size>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777596398892</Timestamp>
<BaseAddress>0x753e0000</BaseAddress>
<Size>1560576</Size>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777595522182</Timestamp>
<BaseAddress>0x75560000</BaseAddress>
<Size>487424</Size>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777595538927</Timestamp>
<BaseAddress>0x756c0000</BaseAddress>
<Size>5693440</Size>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777595544568</Timestamp>
<BaseAddress>0x75c90000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777595535397</Timestamp>
<BaseAddress>0x75ce0000</BaseAddress>
<Size>20811776</Size>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777595550455</Timestamp>
<BaseAddress>0x774d0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777595554628</Timestamp>
<BaseAddress>0x774f0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777595549128</Timestamp>
<BaseAddress>0x77560000</BaseAddress>
<Size>1437696</Size>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777595530150</Timestamp>
<BaseAddress>0x776c0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777596393437</Timestamp>
<BaseAddress>0x77780000</BaseAddress>
<Size>503808</Size>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777596392132</Timestamp>
<BaseAddress>0x77800000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777595583766</Timestamp>
<BaseAddress>0x77ac0000</BaseAddress>
<Size>966656</Size>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777595545878</Timestamp>
<BaseAddress>0x77bb0000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777596385979</Timestamp>
<BaseAddress>0x77be0000</BaseAddress>
<Size>937984</Size>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795777595536930</Timestamp>
<BaseAddress>0x77cd0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777597178434</Timestamp>
<BaseAddress>0x77d10000</BaseAddress>
<Size>28672</Size>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795777595476066</Timestamp>
<BaseAddress>0x77d20000</BaseAddress>
<Size>1585152</Size>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
<module>
<Timestamp>131795777595475814</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>111</ProcessIndex>
<ProcessId>9032</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795777895284069</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>explorer.exe</ProcessName>
<ImagePath>C:\Windows\explorer.exe</ImagePath>
<CommandLine>C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Проводник</Description>
<modulelist>
<module>
<Timestamp>131795777911330291</Timestamp>
<BaseAddress>0x4d80000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\UIRibbonRes.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Ribbon Framework Resources</Description>
</module>
<module>
<Timestamp>131795777920515787</Timestamp>
<BaseAddress>0x6530000</BaseAddress>
<Size>8937472</Size>
<Path>C:\Program Files\Microsoft Office\Office16\1049\GrooveIntlResource.dll</Path>
<Version>16.0.4266.1001</Version>
<Company>Корпорация Майкрософт</Company>
<Description>Модуль международных ресурсов для Microsoft OneDrive для бизнеса</Description>
</module>
<module>
<Timestamp>131795777903881315</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795777903867506</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795777895813346</Timestamp>
<BaseAddress>0x7ff6a5b30000</BaseAddress>
<Size>4665344</Size>
<Path>C:\Windows\explorer.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Проводник</Description>
</module>
<module>
<Timestamp>131795777906005639</Timestamp>
<BaseAddress>0x7ffab2720000</BaseAddress>
<Size>606208</Size>
<Path>C:\Windows\System32\duser.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows DirectUser Engine</Description>
</module>
<module>
<Timestamp>131795777922060868</Timestamp>
<BaseAddress>0x7ffab28d0000</BaseAddress>
<Size>802816</Size>
<Path>C:\Windows\System32\cscui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс кэширования на стороне клиента</Description>
</module>
<module>
<Timestamp>131795777918507242</Timestamp>
<BaseAddress>0x7ffab4b90000</BaseAddress>
<Size>655360</Size>
<Path>C:\Windows\System32\StructuredQuery.dll</Path>
<Version>7.0.14393.2068 (rs1_release.180209-1727)</Version>
<Company>Microsoft Corporation</Company>
<Description>Structured Query</Description>
</module>
<module>
<Timestamp>131795777907532495</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\System32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795777910997447</Timestamp>
<BaseAddress>0x7ffab8da0000</BaseAddress>
<Size>1675264</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.1715_none_aec701fbddd850fa\GdiPlus.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft GDI+</Description>
</module>
<module>
<Timestamp>131795777915260331</Timestamp>
<BaseAddress>0x7ffab9490000</BaseAddress>
<Size>860160</Size>
<Path>C:\Windows\System32\ntshrui.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения оболочки, обеспечивающие общий доступ</Description>
</module>
<module>
<Timestamp>131795777910978745</Timestamp>
<BaseAddress>0x7ffab95c0000</BaseAddress>
<Size>4091904</Size>
<Path>C:\Windows\System32\UIRibbon.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Платформа ленты Windows</Description>
</module>
<module>
<Timestamp>131795778008622616</Timestamp>
<BaseAddress>0x7ffabacc0000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\SharedStartModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Shared Start Model InProc Server</Description>
</module>
<module>
<Timestamp>131795778007235790</Timestamp>
<BaseAddress>0x7ffabae60000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\devrtl.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Management Run Time Library</Description>
</module>
<module>
<Timestamp>131795777909146457</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795777902950088</Timestamp>
<BaseAddress>0x7ffabb2b0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Windows\System32\SettingSyncCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Setting Synchronization Core</Description>
</module>
<module>
<Timestamp>131795778007048279</Timestamp>
<BaseAddress>0x7ffabb430000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\pcacli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Program Compatibility Assistant Client Module</Description>
</module>
<module>
<Timestamp>131795777902932644</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795777909802797</Timestamp>
<BaseAddress>0x7ffabbc40000</BaseAddress>
<Size>643072</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777909791020</Timestamp>
<BaseAddress>0x7ffabbce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.10.24516.0 built by: VCTOOLSRELESC</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777917395017</Timestamp>
<BaseAddress>0x7ffabc0b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\linkinfo.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Volume Tracking</Description>
</module>
<module>
<Timestamp>131795777918158137</Timestamp>
<BaseAddress>0x7ffabc880000</BaseAddress>
<Size>73728</Size>
<Path>C:\Windows\System32\cscapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Offline Files Win32 API</Description>
</module>
<module>
<Timestamp>131795777966565943</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795777908125051</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795777905900322</Timestamp>
<BaseAddress>0x7ffabdbb0000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\dui70.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Подсистема DirectUI Windows</Description>
</module>
<module>
<Timestamp>131795777908270107</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795777922014669</Timestamp>
<BaseAddress>0x7ffabebf0000</BaseAddress>
<Size>1208320</Size>
<Path>C:\Windows\System32\networkexplorer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сетевой проводник</Description>
</module>
<module>
<Timestamp>131795778007216762</Timestamp>
<BaseAddress>0x7ffabef80000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\sfc_os.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows File Protection</Description>
</module>
<module>
<Timestamp>131795777919764442</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795777915281766</Timestamp>
<BaseAddress>0x7ffabff10000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srvcli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Server Service Client DLL</Description>
</module>
<module>
<Timestamp>131795777909775471</Timestamp>
<BaseAddress>0x7ffac0250000</BaseAddress>
<Size>2179072</Size>
<Path>C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL</Path>
<Version>16.0.4266.1001</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive for Business Extensions</Description>
</module>
<module>
<Timestamp>131795777910387599</Timestamp>
<BaseAddress>0x7ffac0610000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\msi.dll</Path>
<Version>5.0.14393.2155</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Installer</Description>
</module>
<module>
<Timestamp>131795777905243222</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795777919412503</Timestamp>
<BaseAddress>0x7ffac1710000</BaseAddress>
<Size>1642496</Size>
<Path>C:\Users\User\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\amd64\FileSyncShell64.dll</Path>
<Version>18.131.0701.0007</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OneDrive Shell Extension</Description>
</module>
<module>
<Timestamp>131795777904716802</Timestamp>
<BaseAddress>0x7ffac18b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safehmpg64.dll</Path>
<Version>1, 0, 0, 1140</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Browser HomePage Protection</Description>
</module>
<module>
<Timestamp>131795777944562485</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795777903915791</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795777922001525</Timestamp>
<BaseAddress>0x7ffac2960000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\mssprxy.dll</Path>
<Version>7.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Search Proxy</Description>
</module>
<module>
<Timestamp>131795777903903305</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795777909321798</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795777909330655</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795777906462233</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795777910949757</Timestamp>
<BaseAddress>0x7ffac4ea0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\atlthunk.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>atlthunk.dll</Description>
</module>
<module>
<Timestamp>131795777920555307</Timestamp>
<BaseAddress>0x7ffac4f90000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\EhStorShell.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL расширения оболочки Windows Enhanced Storage</Description>
</module>
<module>
<Timestamp>131795777906356495</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795777905097743</Timestamp>
<BaseAddress>0x7ffac5690000</BaseAddress>
<Size>4734976</Size>
<Path>C:\Windows\System32\ExplorerFrame.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExplorerFrame</Description>
</module>
<module>
<Timestamp>131795777908567233</Timestamp>
<BaseAddress>0x7ffac5bb0000</BaseAddress>
<Size>622592</Size>
<Path>C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Инфраструктура текстовых служб сенсорной клавиатуры и панели рукописного ввода</Description>
</module>
<module>
<Timestamp>131795777911007559</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795777914831974</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795777905390625</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795777902894862</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795777906986296</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795777906995835</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795777903975733</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795777906257948</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795777919424461</Timestamp>
<BaseAddress>0x7ffaca170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\ktmw32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows KTM Win32 Client DLL</Description>
</module>
<module>
<Timestamp>131795777902880674</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795777908138610</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795777902921260</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795778008641775</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795777907005063</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795777918659102</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795777918649579</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795777909306748</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795777902905939</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795777906474194</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902941219</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795778008632518</Timestamp>
<BaseAddress>0x7ffacb300000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\VEEventDispatcher.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Visual Element Event dispatcher</Description>
</module>
<module>
<Timestamp>131795777918171528</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795777907014508</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795777903933947</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795777902985171</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795777903008375</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795777902974089</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795777905657867</Timestamp>
<BaseAddress>0x7ffacc520000</BaseAddress>
<Size>622592</Size>
<Path>C:\Windows\System32\sxs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fusion 2.5</Description>
</module>
<module>
<Timestamp>131795777902999880</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795777902852334</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795777902849489</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795777902853126</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795777902855116</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795777902843222</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777902836309</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902838974</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795777902841617</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795777902844144</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795777902848566</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795777902824318</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777902854301</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795777902835470</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795777902847555</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795777902846521</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795777902834719</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795777916996283</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795777902838016</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795777902833378</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795777904879129</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795777902823359</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795777905449820</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795777920556415</Timestamp>
<BaseAddress>0x7ffacf340000</BaseAddress>
<Size>4362240</Size>
<Path>C:\Windows\System32\setupapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Setup API</Description>
</module>
<module>
<Timestamp>131795777902842396</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795777903888252</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795777903413262</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795777902840664</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795777902837229</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795777903887407</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795777902850328</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795777903886124</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795777902845086</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795777902851375</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795777895813598</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>144</ProcessIndex>
<ProcessId>12892</ProcessId>
<ParentProcessId>3108</ParentProcessId>
<ParentProcessIndex>11</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795780695167004</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Wireshark.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\Wireshark.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\Wireshark.exe&quot; </CommandLine>
<CompanyName>The Wireshark developer community, http://www.wireshark.org/</CompanyName>
<Version>2.6.2</Version>
<Description>Wireshark</Description>
<modulelist>
<module>
<Timestamp>131795780706141890</Timestamp>
<BaseAddress>0xbd0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\libwinpthread-1.dll</Path>
<Version>1, 0, 0, 0</Version>
<Company>MingW-W64 Project. All rights reserved.</Company>
<Description>POSIX WinThreads for Windows</Description>
</module>
<module>
<Timestamp>131795780721765742</Timestamp>
<BaseAddress>0xbf0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\k5sprt64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>Kerberos v5 support - internal support code for MIT Kerberos v5 /GSS distribution</Description>
</module>
<module>
<Timestamp>131795780722106261</Timestamp>
<BaseAddress>0xc00000</BaseAddress>
<Size>45056</Size>
<Path>C:\Program Files\Wireshark\comerr64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>COM_ERR - Common Error Handler for MIT Kerberos v5 / GSS distribution</Description>
</module>
<module>
<Timestamp>131795780719731475</Timestamp>
<BaseAddress>0x1c000000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\krb5_64.dll</Path>
<Version>1.6-kfw-3.2.2</Version>
<Company>Massachusetts Institute of Technology.</Company>
<Description>Kerberos v5 - MIT GSS / Kerberos v5 distribution</Description>
</module>
<module>
<Timestamp>131795780773060331</Timestamp>
<BaseAddress>0x5af30000</BaseAddress>
<Size>348160</Size>
<Path>C:\Program Files\Wireshark\Qt5Svg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780721210805</Timestamp>
<BaseAddress>0x5af90000</BaseAddress>
<Size>1286144</Size>
<Path>C:\Program Files\Wireshark\libxml2-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780696840198</Timestamp>
<BaseAddress>0x5b0d0000</BaseAddress>
<Size>5865472</Size>
<Path>C:\Program Files\Wireshark\Qt5Core.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780696801039</Timestamp>
<BaseAddress>0x5b670000</BaseAddress>
<Size>5619712</Size>
<Path>C:\Program Files\Wireshark\Qt5Widgets.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780721068755</Timestamp>
<BaseAddress>0x5bcf0000</BaseAddress>
<Size>733184</Size>
<Path>C:\Program Files\Wireshark\libsmi-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720701584</Timestamp>
<BaseAddress>0x5bdb0000</BaseAddress>
<Size>204800</Size>
<Path>C:\Program Files\Wireshark\liblz4.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720048995</Timestamp>
<BaseAddress>0x5bdf0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Program Files\Wireshark\libcares-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780701085625</Timestamp>
<BaseAddress>0x5be10000</BaseAddress>
<Size>122880</Size>
<Path>C:\Program Files\Wireshark\libbcg729.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700086118</Timestamp>
<BaseAddress>0x5be30000</BaseAddress>
<Size>1261568</Size>
<Path>C:\Program Files\Wireshark\Qt5Network.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780701499544</Timestamp>
<BaseAddress>0x61cc0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Wireshark\libintl-8.dll</Path>
<Version>0.18.1</Version>
<Company>Free Software Foundation</Company>
<Description>LGPLed libintl for Windows NT/2000/XP/Vista/7 and Windows 95/98/ME</Description>
</module>
<module>
<Timestamp>131795780704834900</Timestamp>
<BaseAddress>0x646c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libgpg-error6-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780703191110</Timestamp>
<BaseAddress>0x64840000</BaseAddress>
<Size>1220608</Size>
<Path>C:\Program Files\Wireshark\libgnutls-30.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720700188</Timestamp>
<BaseAddress>0x64a00000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\lua52.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780702785552</Timestamp>
<BaseAddress>0x653c0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\libgcrypt-20.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780706408972</Timestamp>
<BaseAddress>0x65f00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Program Files\Wireshark\libtasn1-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705520711</Timestamp>
<BaseAddress>0x66f00000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Wireshark\libhogweed-4-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780696518462</Timestamp>
<BaseAddress>0x685c0000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Program Files\Wireshark\libglib-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GLib</Description>
</module>
<module>
<Timestamp>131795780706610973</Timestamp>
<BaseAddress>0x68ec0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\Wireshark\libp11-kit-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720967901</Timestamp>
<BaseAddress>0x69340000</BaseAddress>
<Size>815104</Size>
<Path>C:\Program Files\Wireshark\libsnappy-1.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705423287</Timestamp>
<BaseAddress>0x69c80000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\libnettle-6-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700701891</Timestamp>
<BaseAddress>0x6a680000</BaseAddress>
<Size>122880</Size>
<Path>C:\Program Files\Wireshark\libsbc-1.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780705248323</Timestamp>
<BaseAddress>0x6acc0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files\Wireshark\libgmp-10.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780707311684</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\libffi-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780700957949</Timestamp>
<BaseAddress>0x6d7c0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Program Files\Wireshark\libspandsp-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780720746780</Timestamp>
<BaseAddress>0x6dc80000</BaseAddress>
<Size>167936</Size>
<Path>C:\Program Files\Wireshark\libnghttp2-14.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795780698864675</Timestamp>
<BaseAddress>0x6dd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\Wireshark\libgmodule-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GModule</Description>
</module>
<module>
<Timestamp>131795780759720376</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\wpcap.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008)</Description>
</module>
<module>
<Timestamp>131795780760417804</Timestamp>
<BaseAddress>0x190ac770000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795780695991379</Timestamp>
<BaseAddress>0x7ff7f1130000</BaseAddress>
<Size>8298496</Size>
<Path>C:\Program Files\Wireshark\Wireshark.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark</Description>
</module>
<module>
<Timestamp>131795780718751145</Timestamp>
<BaseAddress>0x7ffaa6f50000</BaseAddress>
<Size>64282624</Size>
<Path>C:\Program Files\Wireshark\libwireshark.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark dissector library</Description>
</module>
<module>
<Timestamp>131795780697272337</Timestamp>
<BaseAddress>0x7ffaaaca0000</BaseAddress>
<Size>6094848</Size>
<Path>C:\Program Files\Wireshark\Qt5Gui.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896758694</Timestamp>
<BaseAddress>0x7ffab1e90000</BaseAddress>
<Size>593920</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimax.dll</Path>
<Version>1.2.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimax dissector</Description>
</module>
<module>
<Timestamp>131795780766458881</Timestamp>
<BaseAddress>0x7ffab1f30000</BaseAddress>
<Size>614400</Size>
<Path>C:\Windows\System32\riched20.dll</Path>
<Version>5.31.23.1231</Version>
<Company>Microsoft Corporation</Company>
<Description>Rich Text Edit Control, v3.1</Description>
</module>
<module>
<Timestamp>131795780699399720</Timestamp>
<BaseAddress>0x7ffab2280000</BaseAddress>
<Size>1916928</Size>
<Path>C:\Program Files\Wireshark\WinSparkle.dll</Path>
<Version>0.5.7</Version>
<Company>winsparkle.org</Company>
<Description>WinSparkle updater</Description>
</module>
<module>
<Timestamp>131795780771263589</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795780765326722</Timestamp>
<BaseAddress>0x7ffab9010000</BaseAddress>
<Size>1388544</Size>
<Path>C:\Program Files\Wireshark\platforms\qwindows.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896746168</Timestamp>
<BaseAddress>0x7ffab9b10000</BaseAddress>
<Size>135168</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\unistim.dll</Path>
<Version>0.0.2.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>unistim dissector</Description>
</module>
<module>
<Timestamp>131795780896708383</Timestamp>
<BaseAddress>0x7ffabaef0000</BaseAddress>
<Size>462848</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\profinet.dll</Path>
<Version>0.2.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>profinet dissector</Description>
</module>
<module>
<Timestamp>131795780773615377</Timestamp>
<BaseAddress>0x7ffabb070000</BaseAddress>
<Size>512000</Size>
<Path>C:\Program Files\Wireshark\imageformats\qwebp.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780702318544</Timestamp>
<BaseAddress>0x7ffabb0f0000</BaseAddress>
<Size>696320</Size>
<Path>C:\Windows\System32\msvcp140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780773096445</Timestamp>
<BaseAddress>0x7ffabb250000</BaseAddress>
<Size>393216</Size>
<Path>C:\Program Files\Wireshark\imageformats\qtiff.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896696149</Timestamp>
<BaseAddress>0x7ffabc110000</BaseAddress>
<Size>237568</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\opcua.dll</Path>
<Version>1.0.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>opcua dissector</Description>
</module>
<module>
<Timestamp>131795780696290907</Timestamp>
<BaseAddress>0x7ffabc150000</BaseAddress>
<Size>729088</Size>
<Path>C:\Program Files\Wireshark\Qt5Multimedia.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780699299849</Timestamp>
<BaseAddress>0x7ffabcbb0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Program Files\Wireshark\libwiretap.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark capture file library</Description>
</module>
<module>
<Timestamp>131795780702235327</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795780699512168</Timestamp>
<BaseAddress>0x7ffabd180000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\winspool.drv</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Драйвер диспетчера очереди Windows</Description>
</module>
<module>
<Timestamp>131795780773039075</Timestamp>
<BaseAddress>0x7ffabe940000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\imageformats\qjpeg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896684027</Timestamp>
<BaseAddress>0x7ffabeb80000</BaseAddress>
<Size>163840</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\mate.dll</Path>
<Version>1.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>mate dissector</Description>
</module>
<module>
<Timestamp>131795780767100288</Timestamp>
<BaseAddress>0x7ffabebb0000</BaseAddress>
<Size>233472</Size>
<Path>C:\Windows\System32\msls31.dll</Path>
<Version>3.10.349.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Line Services library file</Description>
</module>
<module>
<Timestamp>131795780967804060</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795780703722010</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795780896660120</Timestamp>
<BaseAddress>0x7ffabf990000</BaseAddress>
<Size>135168</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\gryphon.dll</Path>
<Version>0.0.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>gryphon dissector</Description>
</module>
<module>
<Timestamp>131795781117544658</Timestamp>
<BaseAddress>0x7ffabfd60000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\NapiNSP.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик оболочки совместимости для имен электронной почты</Description>
</module>
<module>
<Timestamp>131795781117680972</Timestamp>
<BaseAddress>0x7ffabfef0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\pnrpnsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик пространства имен PNRP</Description>
</module>
<module>
<Timestamp>131795780896781202</Timestamp>
<BaseAddress>0x7ffabff40000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimaxmacphy.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimaxmacphy dissector</Description>
</module>
<module>
<Timestamp>131795780975772674</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795781117813782</Timestamp>
<BaseAddress>0x7ffac0ab0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\winrnr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>LDAP RnR Provider DLL</Description>
</module>
<module>
<Timestamp>131795780967709675</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780896602379</Timestamp>
<BaseAddress>0x7ffac0b10000</BaseAddress>
<Size>180224</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\ethercat.dll</Path>
<Version>0.1.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>ethercat dissector</Description>
</module>
<module>
<Timestamp>131795780696305369</Timestamp>
<BaseAddress>0x7ffac12f0000</BaseAddress>
<Size>585728</Size>
<Path>C:\Program Files\Wireshark\Qt5WinExtras.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780696268510</Timestamp>
<BaseAddress>0x7ffac1380000</BaseAddress>
<Size>335872</Size>
<Path>C:\Program Files\Wireshark\Qt5PrintSupport.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780896769846</Timestamp>
<BaseAddress>0x7ffac1640000</BaseAddress>
<Size>81920</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\wimaxasncp.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>wimaxasncp dissector</Description>
</module>
<module>
<Timestamp>131795780703633136</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\zlib1.dll</Path>
<Version>1.2.11</Version>
<Company></Company>
<Description>zlib data compression library</Description>
</module>
<module>
<Timestamp>131795780968289847</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795780896672499</Timestamp>
<BaseAddress>0x7ffac21f0000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\irda.dll</Path>
<Version>0.0.6.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>irda dissector</Description>
</module>
<module>
<Timestamp>131795780943468609</Timestamp>
<BaseAddress>0x7ffac2950000</BaseAddress>
<Size>32768</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\codecs\l16mono.dll</Path>
<Version>0.1.0.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>l16mono dissector</Description>
</module>
<module>
<Timestamp>131795780696778265</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795780698025500</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libwsutil.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark utility library</Description>
</module>
<module>
<Timestamp>131795780964290332</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795780896734845</Timestamp>
<BaseAddress>0x7ffac3730000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\transum.dll</Path>
<Version>2.0.4.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>transum dissector</Description>
</module>
<module>
<Timestamp>131795780962958391</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795780891504201</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795780896719593</Timestamp>
<BaseAddress>0x7ffac4b60000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\epan\stats_tree.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>stats_tree dissector</Description>
</module>
<module>
<Timestamp>131795780893701095</Timestamp>
<BaseAddress>0x7ffac4c50000</BaseAddress>
<Size>36864</Size>
<Path>C:\Program Files\Wireshark\plugins\2.6\wiretap\usbdump.dll</Path>
<Version>0.0.1.0</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>usbdump dissector</Description>
</module>
<module>
<Timestamp>131795780891269455</Timestamp>
<BaseAddress>0x7ffac5630000</BaseAddress>
<Size>339968</Size>
<Path>C:\Windows\System32\thumbcache.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Кэш эскизов Майкрософт</Description>
</module>
<module>
<Timestamp>131795780965552062</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795780963571749</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795780963646684</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795780773109195</Timestamp>
<BaseAddress>0x7ffac6aa0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qwbmp.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773083338</Timestamp>
<BaseAddress>0x7ffac6ab0000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qtga.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780700311672</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795780700270884</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780773051219</Timestamp>
<BaseAddress>0x7ffac7710000</BaseAddress>
<Size>49152</Size>
<Path>C:\Program Files\Wireshark\imageformats\qsvg.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773027062</Timestamp>
<BaseAddress>0x7ffac7c70000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\imageformats\qico.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773014999</Timestamp>
<BaseAddress>0x7ffac7cc0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Program Files\Wireshark\imageformats\qicns.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780773002354</Timestamp>
<BaseAddress>0x7ffac7e80000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\imageformats\qgif.dll</Path>
<Version>5.9.5.0</Version>
<Company>The Qt Company Ltd.</Company>
<Description>C++ Application Development Framework</Description>
</module>
<module>
<Timestamp>131795780968266724</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795780968255503</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795780966275544</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795780892525330</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795780963686201</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795780892534590</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795781117718740</Timestamp>
<BaseAddress>0x7ffac9790000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\nlaapi.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Location Awareness 2</Description>
</module>
<module>
<Timestamp>131795780698877286</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wsock32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795780891204535</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795780696645603</Timestamp>
<BaseAddress>0x7ffaca540000</BaseAddress>
<Size>53248</Size>
<Path>C:\Program Files\Wireshark\libwscodecs.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark codecs library</Description>
</module>
<module>
<Timestamp>131795780700298298</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795780892543743</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795780766486586</Timestamp>
<BaseAddress>0x7ffacab20000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\usp10.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Uniscribe Unicode script processor</Description>
</module>
<module>
<Timestamp>131795780704258643</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795780702045466</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795780946467813</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795780696789076</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795780891516231</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795780892568770</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795780892552823</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795780966945740</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795780735395573</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795780967734879</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795780699490686</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795780703368899</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795780963669913</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795780735383654</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795780725077080</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795780735352973</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795780735341669</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795780963187802</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795780703358385</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795780696324267</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795780696320774</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795780696326027</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795780700094061</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795780696281753</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780696314418</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795780696011047</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795780967736295</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795780696325096</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795780696319762</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795780696000095</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780700093105</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795780700405929</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795780696318427</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795780719380090</Timestamp>
<BaseAddress>0x7ffacd800000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\psapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Process Status Helper</Description>
</module>
<module>
<Timestamp>131795780696316518</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795780700405056</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795780696313332</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795780703813608</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795780696317482</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795780891250440</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795780695999112</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795780892432004</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795780696011842</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795780696829366</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795780722304611</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795780696010125</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795780696013618</Timestamp>
<BaseAddress>0x7ffacfa30000</BaseAddress>
<Size>1024000</Size>
<Path>C:\Windows\System32\comdlg32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека общих диалоговых окон</Description>
</module>
<module>
<Timestamp>131795780696312465</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795780696321680</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795780696311589</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795780696323259</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795780696315318</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795780695991736</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>154</ProcessIndex>
<ProcessId>10368</ProcessId>
<ParentProcessId>12892</ParentProcessId>
<ParentProcessIndex>144</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795781110701520</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>dumpcap.exe</ProcessName>
<ImagePath>C:\Program Files\Wireshark\dumpcap.exe</ImagePath>
<CommandLine>&quot;C:\Program Files\Wireshark\dumpcap.exe&quot; -n -i \Device\NPF_{8742EB38-E176-4D94-AB83-DB4440CD90E6} -y EN10MB -Z 12892</CommandLine>
<CompanyName>The Wireshark developer community</CompanyName>
<Version>2.6.2</Version>
<Description>Dumpcap</Description>
<modulelist>
<module>
<Timestamp>131795781112729961</Timestamp>
<BaseAddress>0xe30000</BaseAddress>
<Size>90112</Size>
<Path>C:\Program Files\Wireshark\libwinpthread-1.dll</Path>
<Version>1, 0, 0, 0</Version>
<Company>MingW-W64 Project. All rights reserved.</Company>
<Description>POSIX WinThreads for Windows</Description>
</module>
<module>
<Timestamp>131795781112668516</Timestamp>
<BaseAddress>0x61cc0000</BaseAddress>
<Size>151552</Size>
<Path>C:\Program Files\Wireshark\libintl-8.dll</Path>
<Version>0.18.1</Version>
<Company>Free Software Foundation</Company>
<Description>LGPLed libintl for Windows NT/2000/XP/Vista/7 and Windows 95/98/ME</Description>
</module>
<module>
<Timestamp>131795781112689838</Timestamp>
<BaseAddress>0x646c0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libgpg-error6-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112636826</Timestamp>
<BaseAddress>0x64840000</BaseAddress>
<Size>1220608</Size>
<Path>C:\Program Files\Wireshark\libgnutls-30.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112629190</Timestamp>
<BaseAddress>0x653c0000</BaseAddress>
<Size>1089536</Size>
<Path>C:\Program Files\Wireshark\libgcrypt-20.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112737406</Timestamp>
<BaseAddress>0x65f00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Program Files\Wireshark\libtasn1-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112705672</Timestamp>
<BaseAddress>0x66f00000</BaseAddress>
<Size>233472</Size>
<Path>C:\Program Files\Wireshark\libhogweed-4-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112573973</Timestamp>
<BaseAddress>0x685c0000</BaseAddress>
<Size>1265664</Size>
<Path>C:\Program Files\Wireshark\libglib-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GLib</Description>
</module>
<module>
<Timestamp>131795781112722622</Timestamp>
<BaseAddress>0x68ec0000</BaseAddress>
<Size>389120</Size>
<Path>C:\Program Files\Wireshark\libp11-kit-0.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112715396</Timestamp>
<BaseAddress>0x69c80000</BaseAddress>
<Size>253952</Size>
<Path>C:\Program Files\Wireshark\libnettle-6-2.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112698255</Timestamp>
<BaseAddress>0x6acc0000</BaseAddress>
<Size>483328</Size>
<Path>C:\Program Files\Wireshark\libgmp-10.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112775160</Timestamp>
<BaseAddress>0x6b740000</BaseAddress>
<Size>73728</Size>
<Path>C:\Program Files\Wireshark\libffi-6.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795781112582576</Timestamp>
<BaseAddress>0x6dd00000</BaseAddress>
<Size>69632</Size>
<Path>C:\Program Files\Wireshark\libgmodule-2.0-0.dll</Path>
<Version>2.42.0.0</Version>
<Company>The GLib developer community</Company>
<Description>GModule</Description>
</module>
<module>
<Timestamp>131795781112962306</Timestamp>
<BaseAddress>0x180000000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\wpcap.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>wpcap.dll Dynamic Link Library - based on libpcap 1.0rel0b branch (20091008)</Description>
</module>
<module>
<Timestamp>131795781112975613</Timestamp>
<BaseAddress>0x2203d070000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\Packet.dll</Path>
<Version>4.1.0.2980</Version>
<Company>Riverbed Technology, Inc.</Company>
<Description>packet.dll (Vista) Dynamic Link Library</Description>
</module>
<module>
<Timestamp>131795781110777700</Timestamp>
<BaseAddress>0x7ff79b530000</BaseAddress>
<Size>438272</Size>
<Path>C:\Program Files\Wireshark\dumpcap.exe</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community</Company>
<Description>Dumpcap</Description>
</module>
<module>
<Timestamp>131795781112745027</Timestamp>
<BaseAddress>0x7ffac1c90000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\zlib1.dll</Path>
<Version>1.2.11</Version>
<Company></Company>
<Description>zlib data compression library</Description>
</module>
<module>
<Timestamp>131795781112991873</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795781112551689</Timestamp>
<BaseAddress>0x7ffac32b0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Program Files\Wireshark\libwsutil.dll</Path>
<Version>2.6.2</Version>
<Company>The Wireshark developer community, http://www.wireshark.org/</Company>
<Description>Wireshark utility library</Description>
</module>
<module>
<Timestamp>131795781112616429</Timestamp>
<BaseAddress>0x7ffac76e0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\vcruntime140.dll</Path>
<Version>14.12.25810.0 built by: VCTOOLSREL</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781113081556</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795781113068402</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795781112593287</Timestamp>
<BaseAddress>0x7ffac97e0000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\wsock32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Socket 32-Bit DLL</Description>
</module>
<module>
<Timestamp>131795781112764136</Timestamp>
<BaseAddress>0x7ffacab40000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\winmmbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base Multimedia Extension API DLL</Description>
</module>
<module>
<Timestamp>131795781112680590</Timestamp>
<BaseAddress>0x7ffacaba0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\winmm.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>MCI API DLL</Description>
</module>
<module>
<Timestamp>131795781112901553</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795781112603842</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795781112889933</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795781112922216</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795781112873689</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795781112851456</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795781112862535</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795781112564185</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795781112558680</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795781112565891</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795781112638400</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795781112561378</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781112543433</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781112557787</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795781112563121</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795781112564994</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795781112555945</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795781111306780</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781112637496</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795781112554892</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795781112553795</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795781112541505</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795781113056743</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795781112539956</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795781111305815</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781112560555</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781112552568</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795781112797169</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795781112562317</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795781112556862</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795781112538759</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795781112574716</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795781112559630</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795781112540782</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795781110778043</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>155</ProcessIndex>
<ProcessId>10656</ProcessId>
<ParentProcessId>10368</ParentProcessId>
<ParentProcessIndex>154</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795781111864203</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>Conhost.exe</ProcessName>
<ImagePath>C:\Windows\System32\Conhost.exe</ImagePath>
<CommandLine>\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Console Window Host</Description>
<modulelist>
<module>
<Timestamp>131795781111913743</Timestamp>
<BaseAddress>0x7ff768b40000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\conhost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Console Window Host</Description>
</module>
<module>
<Timestamp>131795781111943590</Timestamp>
<BaseAddress>0x7ffac16b0000</BaseAddress>
<Size>368640</Size>
<Path>C:\Windows\System32\ConhostV2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост окна консоли</Description>
</module>
<module>
<Timestamp>131795781112487631</Timestamp>
<BaseAddress>0x7ffac6c40000</BaseAddress>
<Size>2596864</Size>
<Path>C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b\comctl32.dll</Path>
<Version>6.10 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека элементов управления взаимодействия с пользователем</Description>
</module>
<module>
<Timestamp>131795781111973094</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795781112447250</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795781112288506</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795781112268292</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795781112265698</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795781112269042</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795781111955891</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781111952093</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781111953761</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795781111957462</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795781111974737</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795781112264787</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795781111919763</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781111959779</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795781112263740</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795781112262565</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795781111959111</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795781111952833</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795781111927637</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795781111918688</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795781112429009</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795781111954501</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795781111958338</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795781111956778</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795781111951234</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795781112266518</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795781112267424</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795781111973936</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795781111913976</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>162</ProcessIndex>
<ProcessId>4760</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786042098193</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>MicrosoftEdge.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe&quot; -ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Microsoft Edge</Description>
<modulelist>
<module>
<Timestamp>131795786042630177</Timestamp>
<BaseAddress>0x7ff782940000</BaseAddress>
<Size>7663616</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786057154585</Timestamp>
<BaseAddress>0x7ffaad380000</BaseAddress>
<Size>5730304</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\eView.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge View</Description>
</module>
<module>
<Timestamp>131795786054805787</Timestamp>
<BaseAddress>0x7ffaad900000</BaseAddress>
<Size>4730880</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\eModel.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Model</Description>
</module>
<module>
<Timestamp>131795786066907553</Timestamp>
<BaseAddress>0x7ffab0430000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\System32\ieapfltr.dll</Path>
<Version>11.00.14393.2189</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SmartScreen Filter</Description>
</module>
<module>
<Timestamp>131795786128228596</Timestamp>
<BaseAddress>0x7ffab1df0000</BaseAddress>
<Size>602112</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\eData.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Data Store API Module</Description>
</module>
<module>
<Timestamp>131795786065479748</Timestamp>
<BaseAddress>0x7ffab5520000</BaseAddress>
<Size>3231744</Size>
<Path>C:\Windows\System32\msftedit.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Элемент управления &quot;Поле ввода форматированного текста&quot;, версия 8.5</Description>
</module>
<module>
<Timestamp>131795786063895095</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795786054266392</Timestamp>
<BaseAddress>0x7ffab6710000</BaseAddress>
<Size>17231872</Size>
<Path>C:\Windows\System32\Windows.UI.Xaml.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Xaml dll</Description>
</module>
<module>
<Timestamp>131795786230757616</Timestamp>
<BaseAddress>0x7ffab8fd0000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\MicrosoftAccountTokenProvider.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Account Token Provider</Description>
</module>
<module>
<Timestamp>131795786063975264</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786144818989</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795786059649322</Timestamp>
<BaseAddress>0x7ffabb3c0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\TextInputFramework.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>&quot;TextInputFramework.DYNLINK&quot;</Description>
</module>
<module>
<Timestamp>131795786067415829</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786288759665</Timestamp>
<BaseAddress>0x7ffabbb80000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\dsclient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Sharing Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786288473868</Timestamp>
<BaseAddress>0x7ffabbb90000</BaseAddress>
<Size>581632</Size>
<Path>C:\Windows\System32\Windows.System.Launcher.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Launcher</Description>
</module>
<module>
<Timestamp>131795786288676720</Timestamp>
<BaseAddress>0x7ffabbd00000</BaseAddress>
<Size>36864</Size>
<Path>C:\Windows\System32\WpPortingLibrary.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>&lt;d&gt; DLL</Description>
</module>
<module>
<Timestamp>131795786065177710</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795786066322832</Timestamp>
<BaseAddress>0x7ffabc510000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\execmodelproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelProxy</Description>
</module>
<module>
<Timestamp>131795786072876141</Timestamp>
<BaseAddress>0x7ffabc920000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\ExecModelClient.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>ExecModelClient</Description>
</module>
<module>
<Timestamp>131795786088399099</Timestamp>
<BaseAddress>0x7ffabca50000</BaseAddress>
<Size>819200</Size>
<Path>C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Broker WinRT API</Description>
</module>
<module>
<Timestamp>131795786065841979</Timestamp>
<BaseAddress>0x7ffabcef0000</BaseAddress>
<Size>102400</Size>
<Path>C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Shell.ServiceHostBuilder</Description>
</module>
<module>
<Timestamp>131795786055069007</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786147341523</Timestamp>
<BaseAddress>0x7ffabd220000</BaseAddress>
<Size>479232</Size>
<Path>C:\Windows\System32\Windows.Devices.Enumeration.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.Devices.Enumeration</Description>
</module>
<module>
<Timestamp>131795786063327247</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795786125346246</Timestamp>
<BaseAddress>0x7ffabe4d0000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\MSWB7.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>MSWB7 DLL</Description>
</module>
<module>
<Timestamp>131795786068479711</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\System32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795786065629245</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795786100800557</Timestamp>
<BaseAddress>0x7ffabeac0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\Windows.Storage.ApplicationData.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Data API Server</Description>
</module>
<module>
<Timestamp>131795786057138366</Timestamp>
<BaseAddress>0x7ffabeb20000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows ApplicationModel API Server</Description>
</module>
<module>
<Timestamp>131795786088259759</Timestamp>
<BaseAddress>0x7ffabf090000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Platform Diagnostics and Usage Settings DLL</Description>
</module>
<module>
<Timestamp>131795786241271463</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786064506043</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786066155936</Timestamp>
<BaseAddress>0x7ffabfce0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\Windows.Globalization.Fontgroups.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Fonts Mapping API</Description>
</module>
<module>
<Timestamp>131795786063962359</Timestamp>
<BaseAddress>0x7ffabfd00000</BaseAddress>
<Size>356352</Size>
<Path>C:\Windows\System32\Windows.Graphics.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WinRT Windows Graphics DLL</Description>
</module>
<module>
<Timestamp>131795786069984086</Timestamp>
<BaseAddress>0x7ffabfd80000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\threadpoolwinrt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows WinRT Threadpool</Description>
</module>
<module>
<Timestamp>131795786241104861</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786059637885</Timestamp>
<BaseAddress>0x7ffac00c0000</BaseAddress>
<Size>282624</Size>
<Path>C:\Windows\System32\Windows.UI.Core.TextInput.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.UI.Core.TextInput dll</Description>
</module>
<module>
<Timestamp>131795786053932620</Timestamp>
<BaseAddress>0x7ffac01e0000</BaseAddress>
<Size>397312</Size>
<Path>C:\Windows\System32\wincorlib.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows ® WinRT core library</Description>
</module>
<module>
<Timestamp>131795786241083669</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786056074983</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786100125856</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786075280874</Timestamp>
<BaseAddress>0x7ffac15d0000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Windows.ApplicationModel.Core.dll</Path>
<Version>10.0.14393.2155 (rs1_release_1.180305-1842)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Application Model Core API</Description>
</module>
<module>
<Timestamp>131795786070406699</Timestamp>
<BaseAddress>0x7ffac1600000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\mdmregistration.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>MDM Registration DLL</Description>
</module>
<module>
<Timestamp>131795786062579941</Timestamp>
<BaseAddress>0x7ffac1940000</BaseAddress>
<Size>172032</Size>
<Path>C:\Windows\System32\Windows.System.Profile.RetailInfo.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows.System.Profile.RetailInfo Runtime DLL</Description>
</module>
<module>
<Timestamp>131795786070419915</Timestamp>
<BaseAddress>0x7ffac1f10000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\dmcmnutils.dll</Path>
<Version>10.0.14393.1737 (rs1_release_inmarket.170914-1249)</Version>
<Company>Microsoft Corporation</Company>
<Description>dmcmnutils</Description>
</module>
<module>
<Timestamp>131795786068039488</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795786089075107</Timestamp>
<BaseAddress>0x7ffac23c0000</BaseAddress>
<Size>331776</Size>
<Path>C:\Windows\System32\OneCoreCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCore Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786065677921</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795786065270981</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786128841302</Timestamp>
<BaseAddress>0x7ffac3840000</BaseAddress>
<Size>3088384</Size>
<Path>C:\Windows\System32\esent.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширяемая подсистема хранения данных ESE для Microsoft(R) Windows(R)</Description>
</module>
<module>
<Timestamp>131795786054294330</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786063368609</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786202359997</Timestamp>
<BaseAddress>0x7ffac42a0000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\StateRepository.Core.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StateRepository Core</Description>
</module>
<module>
<Timestamp>131795786200068117</Timestamp>
<BaseAddress>0x7ffac46d0000</BaseAddress>
<Size>4161536</Size>
<Path>C:\Windows\System32\Windows.StateRepository.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Сервер Windows StateRepository API Server</Description>
</module>
<module>
<Timestamp>131795786055042484</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\eShims.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Compatibility Shims</Description>
</module>
<module>
<Timestamp>131795786089712128</Timestamp>
<BaseAddress>0x7ffac4b90000</BaseAddress>
<Size>774144</Size>
<Path>C:\Windows\System32\StoreAgent.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>StoreAgent</Description>
</module>
<module>
<Timestamp>131795786059830786</Timestamp>
<BaseAddress>0x7ffac5350000</BaseAddress>
<Size>1765376</Size>
<Path>C:\Windows\System32\Windows.UI.Immersive.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>WINDOWS.UI.IMMERSIVE</Description>
</module>
<module>
<Timestamp>131795786150797625</Timestamp>
<BaseAddress>0x7ffac5500000</BaseAddress>
<Size>438272</Size>
<Path>C:\Windows\System32\PhotoMetadataHandler.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Photo Metadata Handler</Description>
</module>
<module>
<Timestamp>131795786453454285</Timestamp>
<BaseAddress>0x7ffac5ce0000</BaseAddress>
<Size>1744896</Size>
<Path>C:\Windows\System32\UIAutomationCore.dll</Path>
<Version>7.2.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Основные автоматические компоненты Microsoft UI</Description>
</module>
<module>
<Timestamp>131795786067621067</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786092263039</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786147367807</Timestamp>
<BaseAddress>0x7ffac6620000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\biwinrt.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Background Broker Infrastructure</Description>
</module>
<module>
<Timestamp>131795786065223183</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786147382918</Timestamp>
<BaseAddress>0x7ffac6990000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\deviceassociation.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Association Client DLL</Description>
</module>
<module>
<Timestamp>131795786065248448</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786055777229</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795786453657664</Timestamp>
<BaseAddress>0x7ffac6bd0000</BaseAddress>
<Size>413696</Size>
<Path>C:\Windows\System32\oleacc.dll</Path>
<Version>7.2.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Accessibility Core Component</Description>
</module>
<module>
<Timestamp>131795786057001398</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795786057773467</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795786060164250</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786068353332</Timestamp>
<BaseAddress>0x7ffac79c0000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\npmproxy.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager Proxy</Description>
</module>
<module>
<Timestamp>131795786070260699</Timestamp>
<BaseAddress>0x7ffac79e0000</BaseAddress>
<Size>184320</Size>
<Path>C:\Windows\System32\netjoin.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL присоединения к домену</Description>
</module>
<module>
<Timestamp>131795786066493970</Timestamp>
<BaseAddress>0x7ffac7e30000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\fontgroupsoverride.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>fontgroupsoverride.dll</Description>
</module>
<module>
<Timestamp>131795786056922456</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\System32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795786092912724</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786060129754</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795786065322940</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786056749751</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795786070245572</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786054670572</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786056291342</Timestamp>
<BaseAddress>0x7ffac9500000</BaseAddress>
<Size>2682880</Size>
<Path>C:\Windows\System32\CoreUIComponents.dll</Path>
<Version></Version>
<Company></Company>
<Description></Description>
</module>
<module>
<Timestamp>131795786068265491</Timestamp>
<BaseAddress>0x7ffac9f10000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\netprofm.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network List Manager</Description>
</module>
<module>
<Timestamp>131795786082912516</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795786063291141</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786054280400</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786056308035</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786054309397</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795786060143604</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795786053885709</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795786056099190</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786063385911</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786054634364</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786064476035</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795786056663398</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795786070433601</Timestamp>
<BaseAddress>0x7ffacb3f0000</BaseAddress>
<Size>163840</Size>
<Path>C:\Windows\System32\devobj.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Device Information Set DLL</Description>
</module>
<module>
<Timestamp>131795786054821679</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786064343854</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795786741705319</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795786056649628</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795786240387843</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786241189729</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786241130378</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786065234326</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786070099854</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786070392550</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786055055520</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786065299260</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786067045090</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786061034021</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786070369175</Timestamp>
<BaseAddress>0x7ffacc1b0000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\joinutil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Join Utility DLL</Description>
</module>
<module>
<Timestamp>131795786070463748</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786070448934</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786064523489</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786054651608</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786054249334</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786054809092</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786054683095</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786057003667</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795786053916113</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786053913423</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786053914306</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786053917903</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786241132060</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786054295713</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786054808089</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786053867639</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786057002708</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786053934160</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786054810350</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786072535568</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786053933393</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786070371970</Timestamp>
<BaseAddress>0x7ffacede0000</BaseAddress>
<Size>450560</Size>
<Path>C:\Windows\System32\coml2.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM for Windows</Description>
</module>
<module>
<Timestamp>131795786053910705</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786065324109</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786053908868</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786053866675</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786058760529</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795786053915276</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786065183195</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786053988560</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786053916977</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786053912669</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786053907976</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786053911866</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786054806876</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786053909990</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786042630465</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>163</ProcessIndex>
<ProcessId>11628</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786060723216</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>browser_broker.exe</ProcessName>
<ImagePath>C:\Windows\system32\browser_broker.exe</ImagePath>
<CommandLine>C:\Windows\system32\browser_broker.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.1613 (rs1_release_d.170807-1806)</Version>
<Description>Browser_Broker</Description>
<modulelist>
<module>
<Timestamp>131795786060746750</Timestamp>
<BaseAddress>0x7ff7b0a20000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\browser_broker.exe</Path>
<Version>11.00.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>Browser_Broker</Description>
</module>
<module>
<Timestamp>131795786168836722</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786168862865</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786168827250</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\System32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786282574098</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786062630515</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786377997340</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786062639680</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786379114346</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786377416821</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786174396342</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786063237345</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786062620047</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786062594364</Timestamp>
<BaseAddress>0x7ffac37b0000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\browserbroker.dll</Path>
<Version>11.00.14393.1613 (rs1_release_d.170807-1806)</Version>
<Company>Microsoft Corporation</Company>
<Description>BrowserBroker</Description>
</module>
<module>
<Timestamp>131795786062611592</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786373086635</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786062648299</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786374469208</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786169923245</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786169944900</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786375051635</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786170132533</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786168854180</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786372529204</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786060981181</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786373096703</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786062656563</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786376235194</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786377463635</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786062672588</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786169932479</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786372992934</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786282563295</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786170115721</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786168845591</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786377475058</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786377435415</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786377426421</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786065020552</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786168896935</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786060963845</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786065028759</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786065029803</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786062602748</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795786060771823</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786060765038</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786060766797</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786060769366</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786377447217</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786062597872</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786065027623</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786060754491</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786062601823</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786062599820</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786174124589</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786174123329</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786062599041</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786060765825</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786170133242</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786060762708</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786062743817</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786060753543</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786060770964</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786169882199</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786060799279</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786060768413</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786060764068</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786062600875</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786063238473</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786062621206</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786060767532</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786060746988</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>164</ProcessIndex>
<ProcessId>9260</ProcessId>
<ParentProcessId>3632</ParentProcessId>
<ParentProcessIndex>38</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786076559956</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Низкий обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>microsoftedgecp.exe</ProcessName>
<ImagePath>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</ImagePath>
<CommandLine>&quot;C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe&quot; SCODEF:4760 CREDAT:140545 /prefetch:2</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Description>Microsoft Edge Content Process</Description>
<modulelist>
<module>
<Timestamp>131795786082343149</Timestamp>
<BaseAddress>0x5bbd0000</BaseAddress>
<Size>1101824</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll</Path>
<Version>1, 0, 0, 1190</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786082139934</Timestamp>
<BaseAddress>0x5bce0000</BaseAddress>
<Size>28672</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\SafeWrapper.dll</Path>
<Version>2, 0, 0, 1060</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786076857473</Timestamp>
<BaseAddress>0x7ff6405a0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content Process</Description>
</module>
<module>
<Timestamp>131795786340825586</Timestamp>
<BaseAddress>0x7ffaa65e0000</BaseAddress>
<Size>4526080</Size>
<Path>C:\Windows\System32\D3DCompiler_47.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D HLSL Compiler</Description>
</module>
<module>
<Timestamp>131795786083247759</Timestamp>
<BaseAddress>0x7ffaafb30000</BaseAddress>
<Size>3379200</Size>
<Path>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\EdgeContent.dll</Path>
<Version>11.00.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Content</Description>
</module>
<module>
<Timestamp>131795786086088180</Timestamp>
<BaseAddress>0x7ffab0430000</BaseAddress>
<Size>1662976</Size>
<Path>C:\Windows\System32\ieapfltr.dll</Path>
<Version>11.00.14393.2189</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SmartScreen Filter</Description>
</module>
<module>
<Timestamp>131795786159084433</Timestamp>
<BaseAddress>0x7ffab0d50000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\mscms.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL-библиотека системы сопоставления цветов Майкрософт</Description>
</module>
<module>
<Timestamp>131795786202624192</Timestamp>
<BaseAddress>0x7ffab2230000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\elshyph.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ELS Hyphenation Service</Description>
</module>
<module>
<Timestamp>131795786084579233</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786084609324</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786084567131</Timestamp>
<BaseAddress>0x7ffab3540000</BaseAddress>
<Size>22740992</Size>
<Path>C:\Windows\System32\edgehtml.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Веб-платформа Microsoft Edge</Description>
</module>
<module>
<Timestamp>131795786088444599</Timestamp>
<BaseAddress>0x7ffab5b40000</BaseAddress>
<Size>2527232</Size>
<Path>C:\Windows\System32\DWrite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы Microsoft DirectX Typography</Description>
</module>
<module>
<Timestamp>131795786084123182</Timestamp>
<BaseAddress>0x7ffabaab0000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\profext.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>profext</Description>
</module>
<module>
<Timestamp>131795786160557742</Timestamp>
<BaseAddress>0x7ffababa0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\icm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Color Management Module (CMM)</Description>
</module>
<module>
<Timestamp>131795786082878183</Timestamp>
<BaseAddress>0x7ffababf0000</BaseAddress>
<Size>806912</Size>
<Path>C:\Program Files (x86)\360\Total Security\safemon\spsafe64.dll</Path>
<Version>1, 0, 0, 1150</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Internet Security Internet Protection</Description>
</module>
<module>
<Timestamp>131795786390382274</Timestamp>
<BaseAddress>0x7ffabaf70000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\edputil.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа EDP</Description>
</module>
<module>
<Timestamp>131795786086580284</Timestamp>
<BaseAddress>0x7ffabb490000</BaseAddress>
<Size>512000</Size>
<Path>C:\Windows\System32\twinapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi</Description>
</module>
<module>
<Timestamp>131795786085595890</Timestamp>
<BaseAddress>0x7ffabbd10000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\tokenbinding.dll</Path>
<Version>10.0.14393.1593 (rs1_release.170731-1934)</Version>
<Company>Microsoft Corporation</Company>
<Description>Token Binding Protocol</Description>
</module>
<module>
<Timestamp>131795786083370196</Timestamp>
<BaseAddress>0x7ffabcf30000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\mpr.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека маршрутизации для нескольких служб доступа</Description>
</module>
<module>
<Timestamp>131795786137282976</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795786244144116</Timestamp>
<BaseAddress>0x7ffabe110000</BaseAddress>
<Size>69632</Size>
<Path>C:\Windows\System32\imgutil.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE plugin image decoder support DLL</Description>
</module>
<module>
<Timestamp>131795786154004846</Timestamp>
<BaseAddress>0x7ffabe530000</BaseAddress>
<Size>307200</Size>
<Path>C:\Windows\System32\WindowsCodecsExt.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Extended Library</Description>
</module>
<module>
<Timestamp>131795786089791507</Timestamp>
<BaseAddress>0x7ffabe6e0000</BaseAddress>
<Size>561152</Size>
<Path>C:\Windows\System32\directmanipulation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Direct Manipulation Component</Description>
</module>
<module>
<Timestamp>131795786155347443</Timestamp>
<BaseAddress>0x7ffabe830000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\smartscreenps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreenPS</Description>
</module>
<module>
<Timestamp>131795786389154702</Timestamp>
<BaseAddress>0x7ffabe9c0000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\globinputhost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization Extension API for Input</Description>
</module>
<module>
<Timestamp>131795786114772856</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786296880485</Timestamp>
<BaseAddress>0x7ffabf330000</BaseAddress>
<Size>2457600</Size>
<Path>C:\Windows\System32\msxml6.dll</Path>
<Version>6.30.14393.2156</Version>
<Company>Microsoft Corporation</Company>
<Description>MSXML 6.0</Description>
</module>
<module>
<Timestamp>131795786085297567</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786112051091</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786107069509</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786241015463</Timestamp>
<BaseAddress>0x7ffac0bf0000</BaseAddress>
<Size>3559424</Size>
<Path>C:\Windows\System32\actxprxy.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786083065977</Timestamp>
<BaseAddress>0x7ffac1090000</BaseAddress>
<Size>126976</Size>
<Path>C:\Program Files (x86)\360\Total Security\I18N64.dll</Path>
<Version>1, 0, 0, 1016</Version>
<Company>Qihu 360 Software Co., Ltd.</Company>
<Description>360 Total Security</Description>
</module>
<module>
<Timestamp>131795786100196624</Timestamp>
<BaseAddress>0x7ffac1470000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\ieproxy.dll</Path>
<Version>11.00.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>IE ActiveX Interface Marshaling Library</Description>
</module>
<module>
<Timestamp>131795786271419198</Timestamp>
<BaseAddress>0x7ffac1d60000</BaseAddress>
<Size>589824</Size>
<Path>C:\Windows\System32\webio.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API протоколов передачи по Веб</Description>
</module>
<module>
<Timestamp>131795786086130048</Timestamp>
<BaseAddress>0x7ffac20d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\rmclient.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Manager Client</Description>
</module>
<module>
<Timestamp>131795786082410441</Timestamp>
<BaseAddress>0x7ffac2700000</BaseAddress>
<Size>98304</Size>
<Path>C:\Windows\System32\netapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API DLL</Description>
</module>
<module>
<Timestamp>131795786087301397</Timestamp>
<BaseAddress>0x7ffac2990000</BaseAddress>
<Size>385024</Size>
<Path>C:\Windows\System32\ninput.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Pen and Touch Input Component</Description>
</module>
<module>
<Timestamp>131795786082393485</Timestamp>
<BaseAddress>0x7ffac2b80000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\version.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Version Checking and File Installation Libraries</Description>
</module>
<module>
<Timestamp>131795786086032569</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786321446812</Timestamp>
<BaseAddress>0x7ffac3810000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\cabinet.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® Cabinet File API</Description>
</module>
<module>
<Timestamp>131795786282318342</Timestamp>
<BaseAddress>0x7ffac3b80000</BaseAddress>
<Size>286720</Size>
<Path>C:\Windows\System32\indexeddbserver.dll</Path>
<Version>10.0.14393.2189 (rs1_release.180329-1711)</Version>
<Company>Microsoft Corporation</Company>
<Description>IndexedDb host</Description>
</module>
<module>
<Timestamp>131795786082097229</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786085965984</Timestamp>
<BaseAddress>0x7ffac4000000</BaseAddress>
<Size>274432</Size>
<Path>C:\Windows\System32\policymanager.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Policy Manager DLL</Description>
</module>
<module>
<Timestamp>131795786083356981</Timestamp>
<BaseAddress>0x7ffac4b70000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\eShims.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Edge Compatibility Shims</Description>
</module>
<module>
<Timestamp>131795786210171775</Timestamp>
<BaseAddress>0x7ffac60e0000</BaseAddress>
<Size>221184</Size>
<Path>C:\Windows\System32\xmllite.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft XmlLite Library</Description>
</module>
<module>
<Timestamp>131795786104739299</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786085635138</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786085676901</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786089609753</Timestamp>
<BaseAddress>0x7ffac6ac0000</BaseAddress>
<Size>835584</Size>
<Path>C:\Windows\System32\Windows.UI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Runtime UI Foundation DLL</Description>
</module>
<module>
<Timestamp>131795786087107447</Timestamp>
<BaseAddress>0x7ffac6ed0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\srpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL программных интерфейсов (API) поставщика общих ресурсов</Description>
</module>
<module>
<Timestamp>131795786088421856</Timestamp>
<BaseAddress>0x7ffac6f50000</BaseAddress>
<Size>5632000</Size>
<Path>C:\Windows\System32\d2d1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека Microsoft D2D</Description>
</module>
<module>
<Timestamp>131795786092153446</Timestamp>
<BaseAddress>0x7ffac7580000</BaseAddress>
<Size>1077248</Size>
<Path>C:\Windows\System32\MrmCoreR.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows MRM</Description>
</module>
<module>
<Timestamp>131795786100849928</Timestamp>
<BaseAddress>0x7ffac7720000</BaseAddress>
<Size>1601536</Size>
<Path>C:\Windows\System32\OneCoreUAPCommonProxyStub.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>OneCoreUAP Common Proxy Stub</Description>
</module>
<module>
<Timestamp>131795786089750406</Timestamp>
<BaseAddress>0x7ffac78b0000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msimtf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active IMM Server DLL</Description>
</module>
<module>
<Timestamp>131795786088584854</Timestamp>
<BaseAddress>0x7ffac7fc0000</BaseAddress>
<Size>2674688</Size>
<Path>C:\Windows\System32\d3d10warp.dll</Path>
<Version>10.0.14393.576 (rs1_release_inmarket.161208-2252)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 10 Rasterizer</Description>
</module>
<module>
<Timestamp>131795786270943858</Timestamp>
<BaseAddress>0x7ffac83d0000</BaseAddress>
<Size>106496</Size>
<Path>C:\Windows\System32\dhcpcsvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба DHCP-клиента</Description>
</module>
<module>
<Timestamp>131795786270495097</Timestamp>
<BaseAddress>0x7ffac83f0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\dhcpcsvc6.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент DHCPv6</Description>
</module>
<module>
<Timestamp>131795786104726596</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786086442135</Timestamp>
<BaseAddress>0x7ffac84f0000</BaseAddress>
<Size>299008</Size>
<Path>C:\Windows\System32\DataExchange.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data exchange</Description>
</module>
<module>
<Timestamp>131795786085717720</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786086457038</Timestamp>
<BaseAddress>0x7ffac88a0000</BaseAddress>
<Size>2842624</Size>
<Path>C:\Windows\System32\d3d11.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>Direct3D 11 Runtime</Description>
</module>
<module>
<Timestamp>131795786082439684</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786084597848</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786184150347</Timestamp>
<BaseAddress>0x7ffac9ec0000</BaseAddress>
<Size>294912</Size>
<Path>C:\Windows\System32\UIAnimation.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Animation Manager</Description>
</module>
<module>
<Timestamp>131795786141307846</Timestamp>
<BaseAddress>0x7ffac9f50000</BaseAddress>
<Size>1736704</Size>
<Path>C:\Windows\System32\WindowsCodecs.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Windows Codecs Library</Description>
</module>
<module>
<Timestamp>131795786240298598</Timestamp>
<BaseAddress>0x7ffaca340000</BaseAddress>
<Size>1593344</Size>
<Path>C:\Windows\System32\propsys.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Система страниц свойств (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786092224838</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786086057183</Timestamp>
<BaseAddress>0x7ffaca5e0000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\dwmapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Интерфейс API диспетчера окон рабочего стола (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786089629599</Timestamp>
<BaseAddress>0x7ffaca640000</BaseAddress>
<Size>770048</Size>
<Path>C:\Windows\System32\CoreMessaging.dll</Path>
<Version>10.0.14393.0</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft CoreMessaging Dll</Description>
</module>
<module>
<Timestamp>131795786086481184</Timestamp>
<BaseAddress>0x7ffaca770000</BaseAddress>
<Size>1380352</Size>
<Path>C:\Windows\System32\dcomp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft DirectComposition Library</Description>
</module>
<module>
<Timestamp>131795786082048569</Timestamp>
<BaseAddress>0x7ffacadf0000</BaseAddress>
<Size>499712</Size>
<Path>C:\Windows\System32\apphelp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентская библиотека совместимости приложений</Description>
</module>
<module>
<Timestamp>131795786084078182</Timestamp>
<BaseAddress>0x7ffacaf00000</BaseAddress>
<Size>610304</Size>
<Path>C:\Windows\System32\uxtheme.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека тем UxTheme (Microsoft)</Description>
</module>
<module>
<Timestamp>131795786086008568</Timestamp>
<BaseAddress>0x7ffacb140000</BaseAddress>
<Size>593920</Size>
<Path>C:\Windows\System32\msvcp110_win.dll</Path>
<Version>10.0.14393.2007 (rs1_release.171231-1800)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® STL110 C++ Runtime Library</Description>
</module>
<module>
<Timestamp>131795786083279286</Timestamp>
<BaseAddress>0x7ffacb1e0000</BaseAddress>
<Size>1163264</Size>
<Path>C:\Windows\System32\twinapi.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>twinapi.appcore</Description>
</module>
<module>
<Timestamp>131795786088520571</Timestamp>
<BaseAddress>0x7ffacb3d0000</BaseAddress>
<Size>110592</Size>
<Path>C:\Windows\System32\ResourcePolicyClient.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Resource Policy Client</Description>
</module>
<module>
<Timestamp>131795786083257346</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795786086544984</Timestamp>
<BaseAddress>0x7ffacb780000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\dxgi.dll</Path>
<Version>10.0.14393.953 (rs1_release_inmarket.170303-1614)</Version>
<Company>Microsoft Corporation</Company>
<Description>DirectX Graphics Infrastructure</Description>
</module>
<module>
<Timestamp>131795786105438151</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786098058671</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786098091830</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786085647065</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786093150053</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786082425895</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786083270628</Timestamp>
<BaseAddress>0x7ffacbe40000</BaseAddress>
<Size>126976</Size>
<Path>C:\Windows\System32\userenv.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Userenv</Description>
</module>
<module>
<Timestamp>131795786085695835</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786084588700</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786098076226</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786112038692</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786112026610</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786085316210</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786082453168</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786082355351</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786082352777</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786082356404</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786082346599</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786082076458</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786082077405</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786082344914</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786082078287</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786082074829</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786082351486</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786082030503</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786082079752</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786082360385</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786082350101</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786082348521</Timestamp>
<BaseAddress>0x7ffacd810000</BaseAddress>
<Size>22056960</Size>
<Path>C:\Windows\System32\shell32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Общая библиотека оболочки Windows</Description>
</module>
<module>
<Timestamp>131795786082359321</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786082073607</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786085718659</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786082071659</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786082029525</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786086063062</Timestamp>
<BaseAddress>0x7ffacf1e0000</BaseAddress>
<Size>1417216</Size>
<Path>C:\Windows\System32\msctf.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Серверная библиотека MSCTF</Description>
</module>
<module>
<Timestamp>131795786082345765</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786082362660</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786082465073</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786082343975</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786082075682</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786082361662</Timestamp>
<BaseAddress>0x7ffacfe00000</BaseAddress>
<Size>114688</Size>
<Path>C:\Windows\System32\imagehlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT Image Helper</Description>
</module>
<module>
<Timestamp>131795786082070778</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786082357670</Timestamp>
<BaseAddress>0x7ffad0070000</BaseAddress>
<Size>1277952</Size>
<Path>C:\Windows\System32\ole32.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft OLE для Windows</Description>
</module>
<module>
<Timestamp>131795786082354079</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786082072862</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786076857714</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>167</ProcessIndex>
<ProcessId>8360</ProcessId>
<ParentProcessId>664</ParentProcessId>
<ParentProcessIndex>6</ParentProcessIndex>
<AuthenticationId>00000000:0031f1da</AuthenticationId>
<CreateTime>131795786145545826</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Средний обязательный уровень</Integrity>
<Owner>WIN-0UOTFKKVN1S\User</Owner>
<ProcessName>smartscreen.exe</ProcessName>
<ImagePath>C:\Windows\System32\smartscreen.exe</ImagePath>
<CommandLine>C:\Windows\System32\smartscreen.exe -Embedding</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>SmartScreen</Description>
<modulelist>
<module>
<Timestamp>131795786149935538</Timestamp>
<BaseAddress>0x7ff75abc0000</BaseAddress>
<Size>2416640</Size>
<Path>C:\Windows\System32\smartscreen.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreen</Description>
</module>
<module>
<Timestamp>131795786314242815</Timestamp>
<BaseAddress>0x7ffaa6a40000</BaseAddress>
<Size>2936832</Size>
<Path>C:\Windows\System32\CertEnroll.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиент регистрации служб сертификатов Active Directory Microsoft®</Description>
</module>
<module>
<Timestamp>131795786321983797</Timestamp>
<BaseAddress>0x7ffab0360000</BaseAddress>
<Size>798720</Size>
<Path>C:\Windows\System32\certca.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ЦС служб сертификации Microsoft® Active Directory</Description>
</module>
<module>
<Timestamp>131795786150398418</Timestamp>
<BaseAddress>0x7ffab2c00000</BaseAddress>
<Size>8179712</Size>
<Path>C:\Windows\System32\Chakra.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ® Chakra (Private)</Description>
</module>
<module>
<Timestamp>131795786338506430</Timestamp>
<BaseAddress>0x7ffab33d0000</BaseAddress>
<Size>258048</Size>
<Path>C:\Windows\System32\mlang.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL многоязыковой поддержки</Description>
</module>
<module>
<Timestamp>131795786156130630</Timestamp>
<BaseAddress>0x7ffab9c00000</BaseAddress>
<Size>1343488</Size>
<Path>C:\Windows\System32\Windows.Web.Http.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL Windows.Web.Http</Description>
</module>
<module>
<Timestamp>131795786162891895</Timestamp>
<BaseAddress>0x7ffabd4a0000</BaseAddress>
<Size>1613824</Size>
<Path>C:\Windows\System32\Windows.Globalization.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Globalization</Description>
</module>
<module>
<Timestamp>131795786155325960</Timestamp>
<BaseAddress>0x7ffabe830000</BaseAddress>
<Size>77824</Size>
<Path>C:\Windows\System32\smartscreenps.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SmartScreenPS</Description>
</module>
<module>
<Timestamp>131795786290626130</Timestamp>
<BaseAddress>0x7ffabe850000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\IDStore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Identity Store</Description>
</module>
<module>
<Timestamp>131795786303817642</Timestamp>
<BaseAddress>0x7ffabf1d0000</BaseAddress>
<Size>192512</Size>
<Path>C:\Windows\System32\cryptnet.dll</Path>
<Version>10.0.14393.2035 (rs1_release_inmarket.180110-1910)</Version>
<Company>Microsoft Corporation</Company>
<Description>Crypto Network Related API</Description>
</module>
<module>
<Timestamp>131795786292777426</Timestamp>
<BaseAddress>0x7ffabf5d0000</BaseAddress>
<Size>2924544</Size>
<Path>C:\Windows\System32\wininet.dll</Path>
<Version>11.00.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения Интернета для Win32</Description>
</module>
<module>
<Timestamp>131795786308881957</Timestamp>
<BaseAddress>0x7ffabff60000</BaseAddress>
<Size>135168</Size>
<Path>C:\Windows\System32\ncryptsslp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft SChannel Provider</Description>
</module>
<module>
<Timestamp>131795786291185460</Timestamp>
<BaseAddress>0x7ffac0ac0000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\tbs.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>TBS</Description>
</module>
<module>
<Timestamp>131795786303729142</Timestamp>
<BaseAddress>0x7ffac0ad0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\mskeyprotect.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик защиты ключей (Майкрософт)</Description>
</module>
<module>
<Timestamp>131795786295084336</Timestamp>
<BaseAddress>0x7ffac34e0000</BaseAddress>
<Size>1843200</Size>
<Path>C:\Windows\System32\urlmon.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширения OLE32 для Win32</Description>
</module>
<module>
<Timestamp>131795786150377395</Timestamp>
<BaseAddress>0x7ffac36b0000</BaseAddress>
<Size>524288</Size>
<Path>C:\Windows\System32\msdelta.dll</Path>
<Version>5.00 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Patch Engine</Description>
</module>
<module>
<Timestamp>131795786150443503</Timestamp>
<BaseAddress>0x7ffac3cb0000</BaseAddress>
<Size>2772992</Size>
<Path>C:\Windows\System32\iertutil.dll</Path>
<Version>11.00.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служебная программа времени выполнения для Internet Explorer</Description>
</module>
<module>
<Timestamp>131795786295137905</Timestamp>
<BaseAddress>0x7ffac6610000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\rasadhlp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Remote Access AutoDial Helper</Description>
</module>
<module>
<Timestamp>131795786293100161</Timestamp>
<BaseAddress>0x7ffac66a0000</BaseAddress>
<Size>86016</Size>
<Path>C:\Windows\System32\OnDemandConnRouteHelper.dll</Path>
<Version>10.0.14393.351 (rs1_release_inmarket.161014-1755)</Version>
<Company>Microsoft Corporation</Company>
<Description>On Demand Connctiond Route Helper</Description>
</module>
<module>
<Timestamp>131795786293113418</Timestamp>
<BaseAddress>0x7ffac69c0000</BaseAddress>
<Size>839680</Size>
<Path>C:\Windows\System32\winhttp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Службы HTTP Windows</Description>
</module>
<module>
<Timestamp>131795786317286245</Timestamp>
<BaseAddress>0x7ffac6b90000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\dsparse.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Active Directory Domain Services API</Description>
</module>
<module>
<Timestamp>131795786296541369</Timestamp>
<BaseAddress>0x7ffac8420000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\FWPUCLNT.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API пользовательского режима FWP/IPsec</Description>
</module>
<module>
<Timestamp>131795786294026752</Timestamp>
<BaseAddress>0x7ffac8810000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\winnsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Network Store Information RPC interface</Description>
</module>
<module>
<Timestamp>131795786150415925</Timestamp>
<BaseAddress>0x7ffac90b0000</BaseAddress>
<Size>90112</Size>
<Path>C:\Windows\System32\wkscli.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Workstation Service Client DLL</Description>
</module>
<module>
<Timestamp>131795786150432150</Timestamp>
<BaseAddress>0x7ffac92e0000</BaseAddress>
<Size>1269760</Size>
<Path>C:\Windows\System32\WinTypes.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека DLL основных типов Windows</Description>
</module>
<module>
<Timestamp>131795786162900766</Timestamp>
<BaseAddress>0x7ffaca570000</BaseAddress>
<Size>421888</Size>
<Path>C:\Windows\System32\BCP47Langs.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>BCP47 Language Classes</Description>
</module>
<module>
<Timestamp>131795786290836325</Timestamp>
<BaseAddress>0x7ffaca610000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\samlib.dll</Path>
<Version>10.0.14393.82 (rs1_release.160805-1735)</Version>
<Company>Microsoft Corporation</Company>
<Description>SAM Library DLL</Description>
</module>
<module>
<Timestamp>131795786293555790</Timestamp>
<BaseAddress>0x7ffacb360000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\fwbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Firewall Base DLL</Description>
</module>
<module>
<Timestamp>131795786293160744</Timestamp>
<BaseAddress>0x7ffacb460000</BaseAddress>
<Size>548864</Size>
<Path>C:\Windows\System32\FirewallAPI.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API брандмауэра Windows</Description>
</module>
<module>
<Timestamp>131795786340507243</Timestamp>
<BaseAddress>0x7ffacb6f0000</BaseAddress>
<Size>143360</Size>
<Path>C:\Windows\System32\gpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Клиентские функции API групповой политики</Description>
</module>
<module>
<Timestamp>131795786297745460</Timestamp>
<BaseAddress>0x7ffacbaf0000</BaseAddress>
<Size>495616</Size>
<Path>C:\Windows\System32\schannel.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик безопасности TLS/SSL</Description>
</module>
<module>
<Timestamp>131795786155834219</Timestamp>
<BaseAddress>0x7ffacbbb0000</BaseAddress>
<Size>208896</Size>
<Path>C:\Windows\System32\rsaenh.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Enhanced Cryptographic Provider</Description>
</module>
<module>
<Timestamp>131795786303757002</Timestamp>
<BaseAddress>0x7ffacbbf0000</BaseAddress>
<Size>40960</Size>
<Path>C:\Windows\System32\dpapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Data Protection API</Description>
</module>
<module>
<Timestamp>131795786167890086</Timestamp>
<BaseAddress>0x7ffacbd30000</BaseAddress>
<Size>229376</Size>
<Path>C:\Windows\System32\IPHLPAPI.DLL</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API вспомогательного приложения IP</Description>
</module>
<module>
<Timestamp>131795786167870284</Timestamp>
<BaseAddress>0x7ffacbd70000</BaseAddress>
<Size>659456</Size>
<Path>C:\Windows\System32\dnsapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Динамическая библиотека API DNS-клиента</Description>
</module>
<module>
<Timestamp>131795786150424134</Timestamp>
<BaseAddress>0x7ffacbe20000</BaseAddress>
<Size>53248</Size>
<Path>C:\Windows\System32\netutils.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Net Win32 API Helpers DLL</Description>
</module>
<module>
<Timestamp>131795786294009833</Timestamp>
<BaseAddress>0x7ffacbfb0000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\mswsock.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширение поставщика службы API Microsoft Windows Sockets 2.0</Description>
</module>
<module>
<Timestamp>131795786150385959</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795786155846861</Timestamp>
<BaseAddress>0x7ffacc170000</BaseAddress>
<Size>45056</Size>
<Path>C:\Windows\System32\cryptbase.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Base cryptographic API DLL</Description>
</module>
<module>
<Timestamp>131795786303746521</Timestamp>
<BaseAddress>0x7ffacc1f0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\ntasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft ASN.1 API</Description>
</module>
<module>
<Timestamp>131795786303737722</Timestamp>
<BaseAddress>0x7ffacc230000</BaseAddress>
<Size>155648</Size>
<Path>C:\Windows\System32\ncrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Маршрутизатор Windows NCrypt</Description>
</module>
<module>
<Timestamp>131795786292790345</Timestamp>
<BaseAddress>0x7ffacc350000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\sspicli.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>Security Support Provider Interface</Description>
</module>
<module>
<Timestamp>131795786150407736</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795786149962132</Timestamp>
<BaseAddress>0x7ffacc6e0000</BaseAddress>
<Size>61440</Size>
<Path>C:\Windows\System32\kernel.appcore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>AppModel API Host</Description>
</module>
<module>
<Timestamp>131795786149968291</Timestamp>
<BaseAddress>0x7ffacc6f0000</BaseAddress>
<Size>311296</Size>
<Path>C:\Windows\System32\powrprof.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>DLL модуля поддержки профиля управления питанием</Description>
</module>
<module>
<Timestamp>131795786149971001</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795786149965440</Timestamp>
<BaseAddress>0x7ffacc770000</BaseAddress>
<Size>1572864</Size>
<Path>C:\Windows\System32\gdi32full.dll</Path>
<Version>10.0.14393.1770 (rs1_release.170917-1700)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786149952992</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786149956475</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795786149963670</Timestamp>
<BaseAddress>0x7ffacca60000</BaseAddress>
<Size>122880</Size>
<Path>C:\Windows\System32\win32u.dll</Path>
<Version>10.0.14393.51 (rs1_release_inmarket.160801-1836)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32u</Description>
</module>
<module>
<Timestamp>131795786149971757</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795786149957278</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795786149967388</Timestamp>
<BaseAddress>0x7ffaccb90000</BaseAddress>
<Size>7180288</Size>
<Path>C:\Windows\System32\windows.storage.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API хранения Microsoft WinRT</Description>
</module>
<module>
<Timestamp>131795786149943620</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786149960523</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795786149952242</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795786155995189</Timestamp>
<BaseAddress>0x7ffacd7b0000</BaseAddress>
<Size>270336</Size>
<Path>C:\Windows\System32\cfgmgr32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Configuration Manager DLL</Description>
</module>
<module>
<Timestamp>131795786157141835</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795786149955480</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795786167871961</Timestamp>
<BaseAddress>0x7ffacef80000</BaseAddress>
<Size>32768</Size>
<Path>C:\Windows\System32\nsi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>NSI User-mode interface DLL</Description>
</module>
<module>
<Timestamp>131795786149957990</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795786154314206</Timestamp>
<BaseAddress>0x7ffacf030000</BaseAddress>
<Size>651264</Size>
<Path>C:\Windows\System32\clbcatq.dll</Path>
<Version>2001.12.10941.16384 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>COM+ Configuration Catalog</Description>
</module>
<module>
<Timestamp>131795786149942691</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795786322132523</Timestamp>
<BaseAddress>0x7ffacf180000</BaseAddress>
<Size>376832</Size>
<Path>C:\Windows\System32\Wldap32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Win32 LDAP API DLL</Description>
</module>
<module>
<Timestamp>131795786149964615</Timestamp>
<BaseAddress>0x7ffacf770000</BaseAddress>
<Size>212992</Size>
<Path>C:\Windows\System32\gdi32.dll</Path>
<Version>10.0.14393.206 (rs1_release.160915-0644)</Version>
<Company>Microsoft Corporation</Company>
<Description>GDI Client DLL</Description>
</module>
<module>
<Timestamp>131795786149966457</Timestamp>
<BaseAddress>0x7ffacf820000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\ws2_32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>32-разрядная библиотека Windows Socket 2.0</Description>
</module>
<module>
<Timestamp>131795786151032932</Timestamp>
<BaseAddress>0x7ffacf890000</BaseAddress>
<Size>188416</Size>
<Path>C:\Windows\System32\imm32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Multi-User Windows IMM32 API Client DLL</Description>
</module>
<module>
<Timestamp>131795786149962916</Timestamp>
<BaseAddress>0x7ffacf8c0000</BaseAddress>
<Size>1462272</Size>
<Path>C:\Windows\System32\user32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Многопользовательская библиотека клиента USER API Windows</Description>
</module>
<module>
<Timestamp>131795786149954350</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795786149969125</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795786149970065</Timestamp>
<BaseAddress>0x7ffad01b0000</BaseAddress>
<Size>335872</Size>
<Path>C:\Windows\System32\shlwapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека небольших программ оболочки</Description>
</module>
<module>
<Timestamp>131795786149959703</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795786149935879</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
<process>
<ProcessIndex>180</ProcessIndex>
<ProcessId>4244</ProcessId>
<ParentProcessId>580</ParentProcessId>
<ParentProcessIndex>4</ParentProcessIndex>
<AuthenticationId>00000000:000003e7</AuthenticationId>
<CreateTime>131795790147954241</CreateTime>
<FinishTime>0</FinishTime>
<IsVirtualized>0</IsVirtualized>
<Is64bit>1</Is64bit>
<Integrity>Обязательная метка\Обязательный уровень системы</Integrity>
<Owner>NT AUTHORITY\СИСТЕМА</Owner>
<ProcessName>svchost.exe</ProcessName>
<ImagePath>C:\Windows\System32\svchost.exe</ImagePath>
<CommandLine>C:\Windows\System32\svchost.exe -k WerSvcGroup</CommandLine>
<CompanyName>Microsoft Corporation</CompanyName>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Description>Хост-процесс для служб Windows</Description>
<modulelist>
<module>
<Timestamp>131795790148018919</Timestamp>
<BaseAddress>0x7ff718c20000</BaseAddress>
<Size>57344</Size>
<Path>C:\Windows\System32\svchost.exe</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Хост-процесс для служб Windows</Description>
</module>
<module>
<Timestamp>131795790149736107</Timestamp>
<BaseAddress>0x7ffab8fd0000</BaseAddress>
<Size>241664</Size>
<Path>C:\Windows\System32\weretw.dll</Path>
<Version>10.0.14393.447 (rs1_release_inmarket.161102-0100)</Version>
<Company>Microsoft Corporation</Company>
<Description>WERETW.DLL</Description>
</module>
<module>
<Timestamp>131795790149730286</Timestamp>
<BaseAddress>0x7ffabafc0000</BaseAddress>
<Size>700416</Size>
<Path>C:\Windows\System32\wer.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека сообщений об ошибках Windows</Description>
</module>
<module>
<Timestamp>131795790149723654</Timestamp>
<BaseAddress>0x7ffabdfa0000</BaseAddress>
<Size>393216</Size>
<Path>C:\Windows\System32\Faultrep.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека отчетов о сбоях в пользовательском режиме Windows</Description>
</module>
<module>
<Timestamp>131795790149698015</Timestamp>
<BaseAddress>0x7ffac15d0000</BaseAddress>
<Size>180224</Size>
<Path>C:\Windows\System32\wersvc.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Служба регистрации ошибок Windows</Description>
</module>
<module>
<Timestamp>131795790149758280</Timestamp>
<BaseAddress>0x7ffac8dc0000</BaseAddress>
<Size>167936</Size>
<Path>C:\Windows\System32\dbgcore.dll</Path>
<Version>10.0.14321.1024 (debuggers(dbg).160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Core Debugging Helpers</Description>
</module>
<module>
<Timestamp>131795790149743981</Timestamp>
<BaseAddress>0x7ffac8df0000</BaseAddress>
<Size>1646592</Size>
<Path>C:\Windows\System32\dbghelp.dll</Path>
<Version>10.0.14321.1024 (rs1_release.160715-1616)</Version>
<Company>Microsoft</Company>
<Description>Windows Image Helper</Description>
</module>
<module>
<Timestamp>131795790149717043</Timestamp>
<BaseAddress>0x7ffacb420000</BaseAddress>
<Size>204800</Size>
<Path>C:\Windows\System32\ntmarta.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Поставщик Windows NT MARTA</Description>
</module>
<module>
<Timestamp>131795790150390475</Timestamp>
<BaseAddress>0x7ffacb920000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\wldp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Политика блокировки Windows</Description>
</module>
<module>
<Timestamp>131795790149709557</Timestamp>
<BaseAddress>0x7ffacc150000</BaseAddress>
<Size>94208</Size>
<Path>C:\Windows\System32\cryptsp.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Cryptographic Service Provider API</Description>
</module>
<module>
<Timestamp>131795790149752002</Timestamp>
<BaseAddress>0x7ffacc620000</BaseAddress>
<Size>176128</Size>
<Path>C:\Windows\System32\bcrypt.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека криптографических примитивов Windows</Description>
</module>
<module>
<Timestamp>131795790149699755</Timestamp>
<BaseAddress>0x7ffacc740000</BaseAddress>
<Size>81920</Size>
<Path>C:\Windows\System32\profapi.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>User Profile Basic API</Description>
</module>
<module>
<Timestamp>131795790150392414</Timestamp>
<BaseAddress>0x7ffacc760000</BaseAddress>
<Size>65536</Size>
<Path>C:\Windows\System32\msasn1.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>ASN.1 Runtime APIs</Description>
</module>
<module>
<Timestamp>131795790149639584</Timestamp>
<BaseAddress>0x7ffacc8f0000</BaseAddress>
<Size>1003520</Size>
<Path>C:\Windows\System32\ucrtbase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795790149701594</Timestamp>
<BaseAddress>0x7ffacc9f0000</BaseAddress>
<Size>434176</Size>
<Path>C:\Windows\System32\bcryptprimitives.dll</Path>
<Version>10.0.14393.2156 (rs1_release_inmarket.180321-1733)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows Cryptographic Primitives Library</Description>
</module>
<module>
<Timestamp>131795790150393298</Timestamp>
<BaseAddress>0x7ffacca80000</BaseAddress>
<Size>348160</Size>
<Path>C:\Windows\System32\wintrust.dll</Path>
<Version>10.0.14393.2125 (rs1_release.180301-2139)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft Trust Verification APIs</Description>
</module>
<module>
<Timestamp>131795790149724748</Timestamp>
<BaseAddress>0x7ffaccae0000</BaseAddress>
<Size>692224</Size>
<Path>C:\Windows\System32\SHCore.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>SHCORE</Description>
</module>
<module>
<Timestamp>131795790149628535</Timestamp>
<BaseAddress>0x7ffacd270000</BaseAddress>
<Size>2215936</Size>
<Path>C:\Windows\System32\KernelBase.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795790150391489</Timestamp>
<BaseAddress>0x7ffacd490000</BaseAddress>
<Size>1871872</Size>
<Path>C:\Windows\System32\crypt32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>API32 криптографии</Description>
</module>
<module>
<Timestamp>131795790149737723</Timestamp>
<BaseAddress>0x7ffacd710000</BaseAddress>
<Size>638976</Size>
<Path>C:\Windows\System32\msvcp_win.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft® C Runtime Library</Description>
</module>
<module>
<Timestamp>131795790149736916</Timestamp>
<BaseAddress>0x7ffaced20000</BaseAddress>
<Size>782336</Size>
<Path>C:\Windows\System32\oleaut32.dll</Path>
<Version>10.0.14393.1378 (rs1_release.170620-2008)</Version>
<Company>Microsoft Corporation</Company>
<Description>OLEAUT32.DLL</Description>
</module>
<module>
<Timestamp>131795790149638204</Timestamp>
<BaseAddress>0x7ffacee50000</BaseAddress>
<Size>1183744</Size>
<Path>C:\Windows\System32\rpcrt4.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека удаленного вызова процедур</Description>
</module>
<module>
<Timestamp>131795790149698849</Timestamp>
<BaseAddress>0x7ffacef90000</BaseAddress>
<Size>647168</Size>
<Path>C:\Windows\System32\msvcrt.dll</Path>
<Version>7.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Windows NT CRT DLL</Description>
</module>
<module>
<Timestamp>131795790149627637</Timestamp>
<BaseAddress>0x7ffacf0d0000</BaseAddress>
<Size>704512</Size>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Version>10.0.14393.2097 (rs1_release_1.180212-1105)</Version>
<Company>Microsoft Corporation</Company>
<Description>Библиотека клиента Windows NT BASE API</Description>
</module>
<module>
<Timestamp>131795790149700675</Timestamp>
<BaseAddress>0x7ffacfb30000</BaseAddress>
<Size>2916352</Size>
<Path>C:\Windows\System32\combase.dll</Path>
<Version>10.0.14393.1198 (rs1_release_sec.170427-1353)</Version>
<Company>Microsoft Corporation</Company>
<Description>Microsoft COM для Windows</Description>
</module>
<module>
<Timestamp>131795790149702758</Timestamp>
<BaseAddress>0x7ffacfe20000</BaseAddress>
<Size>663552</Size>
<Path>C:\Windows\System32\advapi32.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Расширенная библиотека API Windows 32</Description>
</module>
<module>
<Timestamp>131795790149637329</Timestamp>
<BaseAddress>0x7ffad0210000</BaseAddress>
<Size>364544</Size>
<Path>C:\Windows\System32\sechost.dll</Path>
<Version>10.0.14393.0 (rs1_release.160715-1616)</Version>
<Company>Microsoft Corporation</Company>
<Description>Host for SCM/SDDL/LSA Lookup APIs</Description>
</module>
<module>
<Timestamp>131795790148019282</Timestamp>
<BaseAddress>0x7ffad0270000</BaseAddress>
<Size>1908736</Size>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Version>10.0.14393.1715 (rs1_release_inmarket.170906-1810)</Version>
<Company>Microsoft Corporation</Company>
<Description>Системная библиотека NT</Description>
</module>
</modulelist>
</process>
</processlist><eventlist>
<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:29,5730550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Process Start</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Parent PID: 3108, Command line: &quot;C:\Users\User\Downloads\MCLauncher.exe&quot; , Current directory: C:\Users\User\Downloads\, Environment: 
	=::=::\
	ALLUSERSPROFILE=C:\ProgramData
	APPDATA=C:\Users\User\AppData\Roaming
	CommonProgramFiles=C:\Program Files\Common Files
	CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files
	CommonProgramW6432=C:\Program Files\Common Files
	COMPUTERNAME=WIN-0UOTFKKVN1S
	ComSpec=C:\Windows\system32\cmd.exe
	FPS_BROWSER_APP_PROFILE_STRING=Internet Explorer
	FPS_BROWSER_USER_PROFILE_STRING=Default
	HOMEDRIVE=C:
	HOMEPATH=\Users\User
	LOCALAPPDATA=C:\Users\User\AppData\Local
	LOGONSERVER=\\WIN-0UOTFKKVN1S
	NUMBER_OF_PROCESSORS=1
	OneDrive=C:\Users\User\OneDrive
	OS=Windows_NT
	Path=C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Users\User\AppData\Local\Microsoft\WindowsApps;
	PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
	PROCESSOR_ARCHITECTURE=AMD64
	PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
	PROCESSOR_LEVEL=6
	PROCESSOR_REVISION=9e0a
	ProgramData=C:\ProgramData
	ProgramFiles=C:\Program Files
	ProgramFiles(x86)=C:\Program Files (x86)
	ProgramW6432=C:\Program Files
	PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules
	PUBLIC=C:\Users\Public
	SESSIONNAME=Console
	SystemDrive=C:
	SystemRoot=C:\Windows
	TEMP=C:\Users\User\AppData\Local\Temp
	TMP=C:\Users\User\AppData\Local\Temp
	USERDOMAIN=WIN-0UOTFKKVN1S
	USERDOMAIN_ROAMINGPROFILE=WIN-0UOTFKKVN1S
	USERNAME=User
	USERPROFILE=C:\Users\User
	windir=C:\Windows</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:29,8087840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 2340</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,0052569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x400000, Image Size: 0x2b3000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,0052962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x7ffad0270000, Image Size: 0x1d2000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,0053240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77d20000, Image Size: 0x183000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,0054525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\Prefetch\MCLAUNCHER.EXE-E3686D69.pf</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,0055024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\Prefetch\MCLAUNCHER.EXE-E3686D69.pf</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 24 576, EndOfFile: 24 123, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,0055190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\Prefetch\MCLAUNCHER.EXE-E3686D69.pf</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 24 123, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,0055470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\Prefetch\MCLAUNCHER.EXE-E3686D69.pf</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 24 123, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,0203030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\Prefetch\MCLAUNCHER.EXE-E3686D69.pf</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7976081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7976272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\Segment Heap</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7979644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7980658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\wow64.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x5c020000, Image Size: 0x52000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7981450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x5c080000, Image Size: 0x77000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7988039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\System32\wow64log.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7988870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x6c0000, Image Size: 0xac000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7989504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x755e0000, Image Size: 0xe0000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7990028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x6c0000, Image Size: 0xac000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7990477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\user32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x7d0000, Image Size: 0x165000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7991496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7991738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7991854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7992153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Wow64\x86</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7992342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Wow64\x86\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 520</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7992491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Wow64\x86\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 26, Data: wow64cpu.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7992580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Wow64\x86</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7993070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x5c100000, Image Size: 0xa000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7994893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7995004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\Segment Heap</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7998007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7998747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x755e0000, Image Size: 0xe0000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,7999750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x751e0000, Image Size: 0x1a1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8003892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\05f95efe-7f75-49c7-a994-60a55cc09571</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8008017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\SafeBoot\Option</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value, Set Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8008131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\SafeBoot\Option</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value, Set Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8008242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Srp\GP\DLL</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8008300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Srp\GP\DLL</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8008405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Safer\CodeIdentifiers</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8008486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8008619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8008671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 80</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8008868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8009042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8011691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8011974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:45, LastAccessTime: 16.07.2016 14:42:45, LastWriteTime: 16.07.2016 14:42:45, ChangeTime: 19.07.2018 19:32:46, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8012065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8013049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8013337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8013509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8014439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8014642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8014958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8016002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8016179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8016465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8017318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8017487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8018194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8018712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74730000, Image Size: 0x92000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8019909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8020405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\8ccca27d-f1d8-4dda-b5dd-339aee937731</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8021047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8021222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8021291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LogFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8021452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8022108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8022214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8022266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\ShowDebugInfo</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8022410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8022574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Session Manager</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8022651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8022826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8022909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 24</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8023059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8024477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8024685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8024768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8024840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8026156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8026458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8026539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8026608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8027614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8027885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8027960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8028026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8029007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8029207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8029276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8029340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8030409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8030708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 866 624, EndOfFile: 3 863 594, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8030802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 866 624, EndOfFile: 3 863 594, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8030891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8031027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8031930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8032113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8032398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8033263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8033432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8034063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 866 624, EndOfFile: 3 863 594, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8034216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8036654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8036972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8037136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8037200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 112, Data: C:\Users\User\AppData\Local\Microsoft\Windows\INetCache</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8037427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8037579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner, Group, DACL, SACL, Label, Process Trust Label</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8038527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8038809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:29, LastAccessTime: 20.07.2018 1:33:29, LastWriteTime: 18.09.2017 4:09:15, ChangeTime: 20.07.2018 19:23:27, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8038912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8039951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\apppatch64\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8040214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\AppPatch\apppatch64\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:21:40, LastAccessTime: 20.07.2018 1:21:40, LastWriteTime: 18.09.2017 4:15:39, ChangeTime: 20.07.2018 19:23:27, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8040308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\apppatch64\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8040541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:13:55, LastAccessTime: 24.08.2018 12:13:55, LastWriteTime: 24.08.2018 12:14:13, ChangeTime: 24.08.2018 12:14:13, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8040846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8041896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8042164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8042292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8042347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 112, Data: C:\Users\User\AppData\Local\Microsoft\Windows\INetCache</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8042533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8042672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner, Group, DACL, SACL, Label, Process Trust Label</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8042774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:13:55, LastAccessTime: 24.08.2018 12:13:55, LastWriteTime: 24.08.2018 12:14:13, ChangeTime: 24.08.2018 12:14:13, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8042993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8045087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8047858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8048118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:29, LastAccessTime: 20.07.2018 1:33:29, LastWriteTime: 04.03.2017 9:24:10, ChangeTime: 20.07.2018 19:24:49, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8048199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8049096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8049376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8049520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8050404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8050590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8051011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8051981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8052152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8053263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8053759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x6b830000, Image Size: 0x277000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8054879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74da0000, Image Size: 0xbe000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8055879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77560000, Image Size: 0x15f000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8056691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x774d0000, Image Size: 0x15000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8057591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77bb0000, Image Size: 0x2b000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8058408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74c30000, Image Size: 0x15a000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8059372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x75ce0000, Image Size: 0x13d9000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8060378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77cd0000, Image Size: 0x36000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8061351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x756c0000, Image Size: 0x56e000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8062126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74910000, Image Size: 0x212000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8062855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74830000, Image Size: 0xe0000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8063667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74b60000, Image Size: 0xc1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8064515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x747e0000, Image Size: 0x1f000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8065537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x747d0000, Image Size: 0xa000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8066224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x776c0000, Image Size: 0x5a000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8066925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x75390000, Image Size: 0x41000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8068017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x75040000, Image Size: 0x45000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8068870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x75560000, Image Size: 0x77000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8069823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x75c90000, Image Size: 0x46000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8070762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74b30000, Image Size: 0xd000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8071560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74e60000, Image Size: 0x88000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8072455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x774f0000, Image Size: 0xf000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8073333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77800000, Image Size: 0x94000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8074059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77780000, Image Size: 0x7b000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8075237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x770c0000, Image Size: 0x40b000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8075929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8088494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8088779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:06, LastAccessTime: 20.07.2018 1:34:06, LastWriteTime: 08.08.2017 8:16:23, ChangeTime: 20.07.2018 19:25:15, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8088876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8089871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8090151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8090289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8091195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8091386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8091677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8092547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8092716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8093431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8094068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74710000, Image Size: 0x16000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8094583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8097747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8098005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:45, LastAccessTime: 16.07.2016 14:42:45, LastWriteTime: 16.07.2016 14:42:45, ChangeTime: 19.07.2018 19:38:51, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8098088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8099174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8099443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8099562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8100452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8100634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8100914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8101773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8101942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8102687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8103192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x66680000, Image Size: 0x3000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8103433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8106043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8106297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:35:14, LastAccessTime: 20.07.2018 1:35:14, LastWriteTime: 13.02.2018 0:51:43, ChangeTime: 20.07.2018 19:23:48, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8106378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8107342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8107611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8107724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8108597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8108777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8109049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8109905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8110071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8110703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8111223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x700d0000, Image Size: 0x6a000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8111883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8115144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8115401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:32, LastAccessTime: 20.07.2018 1:33:32, LastWriteTime: 09.12.2016 13:00:58, ChangeTime: 20.07.2018 19:44:33, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8115487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8116526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8116801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8116920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8117795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8117973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8118250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8119103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8119269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8119906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8120411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74190000, Image Size: 0x1b000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8120846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8123356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8123611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:45, LastAccessTime: 16.07.2016 14:42:45, LastWriteTime: 16.07.2016 14:42:45, ChangeTime: 19.07.2018 19:38:51, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8123688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8124666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8124932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8125046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8125910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8126088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8126354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8127207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8127376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8128005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8128503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x67690000, Image Size: 0xf000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8128950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8133352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8133665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:29, LastAccessTime: 20.07.2018 1:33:29, LastWriteTime: 04.03.2017 9:24:10, ChangeTime: 20.07.2018 19:24:49, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8133754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8135965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8136186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:29, LastAccessTime: 20.07.2018 1:33:29, LastWriteTime: 04.03.2017 9:24:10, ChangeTime: 20.07.2018 19:24:49, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8136264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8137267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\570069006E0064006F00770073004500780063006C007500640065006400500072006F00630073000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8137378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\570069006E0064006F00770073004500780063006C007500640065006400500072006F00630073000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8137441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004E0075006D006200650072002D0041006C006C006F007700650064000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8137505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004E0075006D006200650072002D0041006C006C006F007700650064000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8137566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004C0061006E00670075006100670065002D0041006C006C006F007700650064000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8137619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004C0061006E00670075006100670065002D0041006C006C006F007700650064000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8137777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8137879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8137990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8138043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\EMPTY</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 120</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8138259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004C0061006E00670075006100670065002D0044006900730061006C006C006F007700650064000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8138328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004C0061006E00670075006100670065002D0044006900730061006C006C006F007700650064000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8138386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\EMPTY</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 120</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8138508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004C0061006E00670075006100670065002D0053004B0055000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8138574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004C0061006E00670075006100670065002D0053004B0055000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8139021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\NLS\Language</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8139090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\NLS\Language</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8139176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Language</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8139223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Language\InstallLanguageFallback</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 16</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8139419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Language</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8139511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8139575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8139652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8139702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: en-US</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8139802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8139866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8139949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US\Type</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 273</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8140281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US\AlternateCodePage</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8140406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8140456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: ru-RU</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8140542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8140603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8140680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU\Type</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 146</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8140899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU\DefaultFallback</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 12, Data: en-US</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU\en-US</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_MULTI_SZ, Length: 4, Data: </Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: DefaultFallback, Type: REG_SZ, Length: 12, Data: en-US</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: en-US, Type: REG_MULTI_SZ, Length: 4, Data: </Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>SUCCESS</Result>
<Detail>Index: 2, Name: LCID, Type: REG_DWORD, Length: 4, Data: 1049</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>SUCCESS</Result>
<Detail>Index: 3, Name: Type, Type: REG_DWORD, Length: 4, Data: 146</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 4, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU\AlternateCodePage</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 2, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\PendingDelete</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\PendingDelete</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8141993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8142118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8142237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8142290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8142365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8142484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8142539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8142619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8142661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8145700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8145764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8145864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8145941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8146919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8147969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8148036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\MuiCached</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8148119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\MuiCached</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8148161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8148280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_MULTI_SZ, Length: 12, Data: ru-RU</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8148418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\MuiCached</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8148463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8148573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8148640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8148726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8148809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8148856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8148923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8149995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8150064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8150106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8150153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8150191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8152643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8152959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8153045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8153120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8154336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8154619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8154696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8154766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8155766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8155962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8156035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8156098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8157292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8157558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8157630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8157694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8158714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8158974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8159046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8159110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8160290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8160551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8160625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8160686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8161698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8162099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8162230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8162296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8163374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8163568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8163637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8163698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8164695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8164878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8164947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8165011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8165978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8166241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8166311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8166371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8167405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8167657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8167729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8167790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8168787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8169034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8169106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8169164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8170211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8170458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8170527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8170588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8171660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8171910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8172098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8172242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8173320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8173580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8173650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8173713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8174833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8175088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8175160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8175218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8176307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8176495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8176562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8176623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8177648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8177897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8177966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8178027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8179058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8179313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8179382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8179446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8180449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8180643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8180712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8180773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8182158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8185718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8185826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8185896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8187295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8187503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8187572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8187638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8188691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8188954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8189026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8189090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8190151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8190412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8190481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8190542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8191664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8191935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8192007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8192071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8193152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8193398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8193470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8193531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8194504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8194759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8194828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8194892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8195889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8196144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8196216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8196277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8197319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8197565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8197634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8197695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8198407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8198524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8198626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8198682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: 0006020E</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8202508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8202771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:49, LastAccessTime: 16.07.2016 14:42:49, LastWriteTime: 16.07.2016 14:42:49, ChangeTime: 20.07.2018 19:26:58, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8202863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8203816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8204104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8204256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8205179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8205370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8205669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8206534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8206705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8207340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 147 456, EndOfFile: 144 632, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8207498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8208021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8208686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74800000, Image Size: 0x25000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8210495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8210770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8210847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8210919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8213629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8213862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:49, LastAccessTime: 16.07.2016 14:42:49, LastWriteTime: 16.07.2016 14:42:49, ChangeTime: 20.07.2018 19:26:58, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8213945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8216460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8216682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:49, LastAccessTime: 16.07.2016 14:42:49, LastWriteTime: 16.07.2016 14:42:49, ChangeTime: 20.07.2018 19:26:58, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8216760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8217153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\f25bcd2e-2690-55dc-3bc4-07b65b1b41c9</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8217607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\GRE_Initialize</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8217754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8217832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8217896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8218084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8218644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Compatibility32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8218782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Compatibility32\MCLauncher</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 172</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8218887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Compatibility32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8218971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\IME Compatibility</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8223041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8223207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8223284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8223395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8223517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8223597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8223841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8563249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8563443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8563545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8563681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8563756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8565457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8565543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8565656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8565712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8565908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8565972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8566044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8566091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8566230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\MDMEnabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8566402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8566454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8566535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8566598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8567682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8567740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8567834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8567925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8567989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8568045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\PageAllocatorUseSystemHeap</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8568211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8568283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8568335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8568416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8568482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8568538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8568582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\PageAllocatorSystemHeapIsPrivate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8568707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8568770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8568820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8568898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8568962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8569014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8569056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\AggressiveMTATesting</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8569172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8569549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8569604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8569688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\OLE\Tracing</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8569760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\Tracing</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8570183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\1aff6089-e863-4d36-bdfd-3581f07440be</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8573345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\30336ed4-e327-447c-9de0-51b652c86108</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8573685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\b87cf16b-0bf8-4492-a510-d5f59626b033</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8574993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\30336ed4-e327-447c-9de0-51b652c86108</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8575231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\b87cf16b-0bf8-4492-a510-d5f59626b033</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8578936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8579229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:33, LastAccessTime: 20.07.2018 1:33:33, LastWriteTime: 22.03.2018 6:29:36, ChangeTime: 20.07.2018 19:26:57, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8579315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8580310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8580595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8580745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8581850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8582080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8582382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8583255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8583427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8584031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 966 656, EndOfFile: 962 760, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8584191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8584712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8585117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8585183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8585294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\OLEAUT</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8585557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8585607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8585679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\system\CurrentControlSet\control\NetworkProvider\HwOrder</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8585760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\control\NetworkProvider\HwOrder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8585848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\NetworkProvider\HwOrder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8586546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8586599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8586682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Setup</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8586776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8586835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8586884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\SourcePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 16</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8587062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8587527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\f3a71a4b-6118-4257-8ccb-39a33ba059d4</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8588267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\c69cb70a-3133-4cca-ab0e-046848effcda</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8590162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8592802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe.Local</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8593980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8594442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 12960</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8596822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8596997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:08, LastAccessTime: 16.07.2016 14:43:08, LastWriteTime: 16.07.2016 14:43:08, ChangeTime: 19.07.2018 19:37:26, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8597077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8598017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8598210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8598338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8599213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8599388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8599671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8600516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8600679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8601349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8602128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x613d0000, Image Size: 0xa3000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8602533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8603541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8603630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8603779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 544</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8603926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8643387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8643587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:08, LastAccessTime: 16.07.2016 14:43:08, LastWriteTime: 16.07.2016 14:43:08, ChangeTime: 19.07.2018 19:37:26, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8643678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8644041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8644227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail>Filter: Windows, 1: Windows</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8644432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8645379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8645587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Windows\WinSxS</Path>
<Result>SUCCESS</Result>
<Detail>Filter: WinSxS, 1: WinSxS</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8645764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8646892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8647080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\MSVCR90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MSVCR90.dll, 1: msvcr90.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8647233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8734173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8751145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8751245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8751411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\PythonPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8751655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8751810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8751860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8751938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\PythonPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8752763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Session Manager</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8752847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8752946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8752999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 24</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8753198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8774490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\zlib.pyd</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8775662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8775917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8776050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8776211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8777236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8777460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8777779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8778654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8778829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8779150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8779286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8779422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8781084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8781153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8781264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\linecache</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8781397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8781444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8781536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\linecache</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8783259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8783472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8786054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8786354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:47, LastAccessTime: 20.07.2018 1:33:47, LastWriteTime: 30.03.2018 6:12:25, ChangeTime: 20.07.2018 19:25:55, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8786440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8787623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8787911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8788035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8788916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8789097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8789376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8790232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8790401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8791086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8791429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8792867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8793094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8793200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8794084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8794261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8794527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8795375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8795541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8796114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 45 056, EndOfFile: 41 984, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8796264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8796923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8799453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8799688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:47, LastAccessTime: 20.07.2018 1:33:47, LastWriteTime: 30.03.2018 6:12:25, ChangeTime: 20.07.2018 19:25:55, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8799769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8800741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8801013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8801126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8801988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8802165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8802434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8803279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8803445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8804069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8804274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8805338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8805545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8805651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8806748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8806936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8807210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8808069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8808238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8808801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 45 056, EndOfFile: 41 984, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8808948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8809358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8809657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8810798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8811048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8811195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 127, Length: 22, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8811477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 394, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8811582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 404, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8811657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 436, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8811740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 450, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8811804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 460, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8811873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 492, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8811945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 508, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 518, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 550, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 566, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 576, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 608, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 626, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 636, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 668, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 683, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 693, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 725, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 745, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 755, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 787, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8812957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 804, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 814, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 846, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 870, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 880, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 912, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 931, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 941, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 973, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 984, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 994, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 026, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 040, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 050, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 082, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8813960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 096, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 106, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 138, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 149, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 159, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 191, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 207, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 217, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 249, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 260, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 270, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 302, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 316, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 326, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 358, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8814971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 377, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 387, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 419, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 437, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 447, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 479, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 491, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 501, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 533, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 549, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 559, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 591, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 614, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 624, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 656, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8815990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 678, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8816054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 688, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8816231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 720, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8816389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 743, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8816453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 753, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8816520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 785, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8816597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 800, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8816661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 810, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8816730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 842, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8816797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 853, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8816858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 863, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8816924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 895, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8816999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 921, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 931, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 963, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 986, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 996, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 028, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 052, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 062, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 094, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 115, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 125, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 157, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 180, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 190, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8817933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 222, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 249, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 259, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 291, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 318, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 328, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 360, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 375, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 385, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 417, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 437, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 447, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 479, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 505, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 515, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8818933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 547, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 572, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 582, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 614, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 637, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 647, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 679, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 709, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 719, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 751, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 773, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 783, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 815, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 842, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 852, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8819941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 884, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 911, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 921, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 953, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 978, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 988, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 020, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 043, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 053, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 085, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 109, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 119, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 151, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 175, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 185, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8820941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 217, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 241, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 251, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 283, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 307, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 317, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 349, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 373, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 383, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 415, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 439, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 449, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 481, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 505, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 515, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8821969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 547, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 571, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 581, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 613, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 637, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 647, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 679, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 703, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 713, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 745, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 769, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 779, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 811, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 835, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8822953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 845, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 877, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 900, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 910, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 942, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 965, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 975, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 007, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 030, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 040, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 072, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 095, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 105, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 137, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 160, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8823972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 170, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 202, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 225, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 235, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 267, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 290, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 300, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 332, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 355, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 365, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 397, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 420, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 430, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 462, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 485, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8824984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 495, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8825050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 527, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8825122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 550, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8825183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 560, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8825247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 592, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8825319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 615, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8825380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 625, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8825446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 657, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8825516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 680, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8825576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 690, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8825643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 722, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8825715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 745, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8825782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 755, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8825848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 787, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8826078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 810, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8826208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 820, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8826319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 852, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8826441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 875, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8826532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 885, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8826604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 917, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8826676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 940, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8826737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 950, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8826807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 982, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8826879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 005, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8826940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 015, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 047, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 070, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 080, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 112, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 135, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 145, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 177, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 200, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 210, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 242, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 265, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 275, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 307, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 330, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8827956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 340, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 372, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 395, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 405, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 437, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 460, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 470, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 502, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 532, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 542, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 574, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 604, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 614, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 646, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 670, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8828982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 680, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 712, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 736, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 746, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 778, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 803, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 813, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 845, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 869, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 879, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 911, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 932, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 942, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 974, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8829998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 001, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 011, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 043, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 070, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 080, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 112, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 132, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 142, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 174, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 196, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 206, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 238, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 266, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 276, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8830926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 308, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 338, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 348, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 380, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 410, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 420, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 452, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 485, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 495, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 527, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 557, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 567, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 599, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 631, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 641, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8831940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 673, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 701, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 711, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 743, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 770, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 780, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 812, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 840, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 850, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 882, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 910, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 920, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 952, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 980, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 990, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8832946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 022, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 050, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 060, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 092, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 120, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 130, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 162, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 190, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 200, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 232, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 259, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 269, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 301, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 328, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 338, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8833952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 370, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 397, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 407, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 439, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 466, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 476, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 508, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 535, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 545, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 577, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 604, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 614, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 646, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 673, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 683, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8834974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 715, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8835046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 742, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8835107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 752, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8835174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 784, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8835246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 807, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8835307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 817, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8835459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 849, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8835614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 873, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8835681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 883, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8835747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 915, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8835819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 939, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8835880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 949, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8835947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 981, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 006, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 016, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 048, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 076, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 086, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 118, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 148, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 158, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 190, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 220, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 230, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 262, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 292, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 302, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8836972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 334, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 361, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 371, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 403, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 430, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 440, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 472, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 501, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 511, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 543, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 571, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 581, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 613, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 640, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 650, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8837997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 682, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 712, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 722, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 754, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 783, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 793, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 825, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 847, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 857, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 889, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 913, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 923, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 955, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 980, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8838939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 990, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 022, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 048, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 058, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 090, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 120, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 130, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 162, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 198, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 208, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 240, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 264, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 274, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 306, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 333, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8839986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 343, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 375, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 407, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 417, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 449, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 481, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 491, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 523, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 554, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 564, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 596, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 621, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 631, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 663, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8840961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 690, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 700, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 732, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 764, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 774, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 806, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 840, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 850, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 882, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 906, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 916, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 948, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 975, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 985, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 017, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8841975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 044, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 054, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 086, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 110, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 120, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 152, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 179, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 189, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 221, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 248, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 258, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 290, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 313, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 323, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8842929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 355, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 378, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 388, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 420, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 447, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 457, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 489, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 515, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 525, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 557, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 585, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 595, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 627, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 642, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 652, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8843937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 684, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 701, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 711, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 743, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 762, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 772, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 804, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 818, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 828, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 860, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 875, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 885, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 917, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 929, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 939, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 971, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8844998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 983, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8845059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 993, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8845126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 025, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8845195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 040, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8845261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 050, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8845328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 082, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8845397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 095, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8845641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 105, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8845752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 137, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8845879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 152, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8845976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 162, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 194, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 204, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 214, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 246, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 267, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 277, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 309, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 329, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 339, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 371, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 391, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 401, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 433, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 453, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8846979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 463, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 495, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 510, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 520, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 552, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 569, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 579, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 611, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 625, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 635, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 667, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 691, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 701, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 733, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 747, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8847974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 757, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 789, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 803, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 813, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 845, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 861, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 871, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 903, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 913, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 923, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 955, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 973, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 983, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 015, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 026, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8848996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 036, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 068, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 082, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 092, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 124, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 140, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 150, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 182, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 198, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 208, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 240, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 257, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 267, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 299, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 313, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8849988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 323, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8850054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 355, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8850126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 373, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8850187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 383, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8850254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 415, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8850340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 429, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8850403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 439, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8850470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 471, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8850539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 485, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8850600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 495, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8850669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 527, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8850814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 537, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8850880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 547, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8850947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 579, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 591, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 601, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 633, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 646, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 656, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 688, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 702, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 712, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 744, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 767, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 777, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 809, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 830, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 840, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8851947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 872, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 894, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 904, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 936, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 966, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 976, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 008, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 034, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 044, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 076, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 104, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 114, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 146, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 172, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 182, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8852952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 214, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 238, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 248, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 280, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 304, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 314, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 346, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 370, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 380, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 412, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 436, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 446, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 478, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 494, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 504, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8853989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 536, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 552, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 562, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 594, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 610, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 620, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 652, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 677, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 687, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 719, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 755, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 765, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 797, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 829, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8854936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 839, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8855003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 871, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8855075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 900, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8855138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 910, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8855341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 942, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8855446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 973, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8855510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 983, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8855576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 015, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8855651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 047, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8855715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 057, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8855781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 089, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8855856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 118, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8855917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 128, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8855983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 160, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 190, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 200, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 232, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 265, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 275, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 307, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 335, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 345, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 377, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 409, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 419, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 451, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 473, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8856934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 483, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 515, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 529, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 539, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 571, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 582, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 592, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 624, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 643, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 653, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 685, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 706, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 716, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 748, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 765, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 775, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8857989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 807, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 818, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 828, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 860, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 872, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 882, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 914, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 928, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 938, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 970, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 988, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 998, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 030, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 044, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 054, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8858976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 086, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 104, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 114, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 146, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 161, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 171, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 203, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 219, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 229, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 261, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 277, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 287, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 319, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 336, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 346, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8859962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 378, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 391, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 401, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 433, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 449, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 459, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 491, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 508, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 518, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 550, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 563, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 573, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 605, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 630, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 640, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8860951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 672, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 693, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 703, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 735, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 758, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 768, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 800, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 821, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 831, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 863, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 886, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 896, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 928, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 951, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 961, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8861976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 993, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 017, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 027, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 059, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 081, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 091, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 123, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 144, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 154, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 186, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 202, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 212, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 244, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 259, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 269, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8862979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 301, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 319, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 329, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 361, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 381, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 391, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 423, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 451, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 461, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 493, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 518, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 528, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 560, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 575, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 585, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8863979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 617, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 632, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 642, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 674, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 690, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 700, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 732, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 747, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 757, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 789, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 805, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 815, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 847, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 862, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8864905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 872, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8865146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 904, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8865273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 916, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8865378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 926, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8865478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 958, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8865583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 969, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8865650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 979, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8865719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 011, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8865791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 026, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8865852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 036, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8865919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 068, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8865991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 082, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 092, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 124, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 143, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 153, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 185, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 206, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 216, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 248, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 268, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 278, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 310, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 334, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 344, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8866930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 376, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 399, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 409, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 441, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 456, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 466, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 498, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 521, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 531, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 563, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 579, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 589, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 621, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 638, Length: 511</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 648, Length: 501</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8867936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 680, Length: 469</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 698, Length: 451</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 708, Length: 441</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 740, Length: 409</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 755, Length: 394</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 765, Length: 384</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 797, Length: 352</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 817, Length: 332</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 827, Length: 322</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 859, Length: 290</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 873, Length: 276</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 883, Length: 266</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 915, Length: 234</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 939, Length: 210</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 949, Length: 200</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8868972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 981, Length: 168</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8869052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 007, Length: 142</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8869119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 017, Length: 132</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8869188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 049, Length: 100</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8869257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 066, Length: 83</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8869321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 076, Length: 73</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8869390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 108, Length: 41</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8869465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 127, Length: 22</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8869559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8870775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8871011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 131 729, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8871177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 131 755, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8871257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 131 772, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8871318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 132 796, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8871399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8872657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8872731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8872845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\os</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8872989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8873036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8873130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\os</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8874222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8874455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 183 461, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8874726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 183 487, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8874892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 183 497, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8874959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 188 617, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8875042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8877619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8877693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8877802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\ntpath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8877929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8877976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8878065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\ntpath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8879159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8879400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 162 672, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8879541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 162 698, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8879691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 162 712, Length: 4 096</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8879769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 166 808, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8879855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8881309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8881376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8881475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\stat</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8881589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8881636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8881725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\stat</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8882786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8883021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 469 343, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8883179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 469 369, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8883265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 469 381, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8883326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 469 893, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8883406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8885077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8885146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8885249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\genericpath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8885365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8885412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8885504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\genericpath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8886606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8886850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 087 485, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8887016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 087 511, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8887105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 087 530, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8887166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 088 042, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8887249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8887906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8887970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8888066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\warnings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8888183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8888230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8888316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\warnings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8889358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8889590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 569 927, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8889726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 569 953, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8889809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 569 969, Length: 4 096</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8889873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 574 065, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8889962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8891278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8891341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8891438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\types</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8891555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8891602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8891690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\types</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8892732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8892993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 539 979, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8893131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 540 005, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8893217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 540 018, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8893278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 541 042, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8893358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8895813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8895882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8895988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\UserDict</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8896107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8896157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8896242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\UserDict</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8897356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8897594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 792 187, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8897761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 792 213, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8897847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 792 229, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8897908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 794 789, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8897991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8899102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8899163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8899260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\_abcoll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8899379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8899426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8899512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\_abcoll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8900570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8900803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 795 741, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8900936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 795 767, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8901022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 795 782, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8901083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 800 902, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8901166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8903075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8903136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8903235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\abc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8903354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8903399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8903485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\abc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8904762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8904997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 814 511, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8905141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 814 537, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8905225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 814 548, Length: 1 536</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8905283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 816 084, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8905366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8906200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8906261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8906355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\_weakrefset</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8906471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8906518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8906604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\_weakrefset</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8907638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8907865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 811 950, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8907981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 811 976, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8908064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 811 995, Length: 2 048</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8908125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 814 043, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8908206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8916021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8916099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8916210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\copy_reg</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8916335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8916384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8916479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\copy_reg</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8917606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8917850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 855 680, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8918002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 855 706, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8918088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 855 722, Length: 1 536</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8918149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 857 258, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,8918235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9342616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9342688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9342796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\zipextimporter</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9342937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9342984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9343076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\zipextimporter</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9344594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9344890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 435 931, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9345084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 435 957, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9345178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 435 979, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9345239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 437 003, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9345331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9505757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9505865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9506018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\encodings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9506209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9506262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9506367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\encodings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9507877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9508162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9508431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9509969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9510262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 911 751, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9510462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 911 777, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9510553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 911 803, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9510614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 912 827, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9510700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9512423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9513321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9514252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9514449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9514637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9515213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9515413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9515659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\codecs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9515806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9515853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9515945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\codecs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9517047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9517277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 838 198, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9517424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 838 224, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9517510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 838 238, Length: 5 632</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9517582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 843 870, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9517665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9523137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9523392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 913 209, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9523542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 913 235, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9523630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 913 260, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9523691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 915 820, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9523780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9526412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9526656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 080 354, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9526808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 080 380, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9526894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 080 403, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9526955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 080 915, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9527038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9534610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9534862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 078 280, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9534998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 078 306, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9535084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 078 333, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9535145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 078 845, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9535231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9542936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9543021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9543290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\random</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9543462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9543515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9543609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\random</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9544856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9545102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 245 504, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9545260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 245 530, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9545346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 245 544, Length: 6 656</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9545410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 252 200, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9545496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9547263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9547330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9547429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\__future__</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9547549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9547596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9547684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\__future__</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9558246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9558506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 794 803, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9558642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 794 829, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9558739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 794 847, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9558803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 795 359, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9558888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9560174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9560243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9560349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\hashlib</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9560470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9560518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9560609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\hashlib</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9561734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9561969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 102 055, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9562124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 102 081, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9562208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 102 096, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9562266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 104 656, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9562352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9563900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9563967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9564067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\_hashlib</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9564189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9564233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9564321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\_hashlib</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9565524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9565759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 786 760, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9565937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 786 786, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9567084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 786 802, Length: 381 952</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9568463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 168 754, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9568577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9624869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9625191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:55, LastAccessTime: 16.07.2016 14:42:55, LastWriteTime: 16.07.2016 14:42:55, ChangeTime: 20.07.2018 19:44:33, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9625285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9626407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9626717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9626889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9627792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9627978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9628283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9629142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9629316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9630078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9630638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x741b0000, Image Size: 0x13000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9631217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9632632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9632912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9632993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9633062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9633746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9633813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9633929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9634120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9634189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9634364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9634508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9634638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9634793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9634879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9634932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9635035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9635154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9635206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9635342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9635469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9635594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9635835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9638550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9638805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:55, LastAccessTime: 16.07.2016 14:42:55, LastWriteTime: 16.07.2016 14:42:55, ChangeTime: 19.07.2018 19:38:42, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9638888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9639853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9640124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9640249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9641235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9641415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9641695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9642551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9642717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9643379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9643878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74060000, Image Size: 0x2f000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9644776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9646095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9646374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9646452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9646518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9647147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9647225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9647369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9647436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCacheMaxItems</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9647580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCachePurgeIntervalSeconds</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9647696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivateKeyLifetimeSeconds</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9647821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9647951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9648017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9648109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9648156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9648303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9648427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9648544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9648724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9648807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9648860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9648959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9649511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\000602xx</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 26, Data: kernel32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9650688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\Globalization\Sorting\SortDefault.nls</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9650929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\Globalization\Sorting\SortDefault.nls</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9651048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9651952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9652132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9652423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9653287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9653456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9654041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\Globalization\Sorting\SortDefault.nls</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 371 008, EndOfFile: 3 368 788, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9654190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\Globalization\Sorting\SortDefault.nls</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9654398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\Globalization\Sorting\SortDefault.nls</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9654963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9655060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9655154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9655756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9663690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9663760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9663862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\zipfile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9663990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9664037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9664123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\zipfile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9665414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9665707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 585 497, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9665912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 585 523, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9666051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 585 538, Length: 15 360</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9666137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 600 898, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9666237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9669802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9669874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9669980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\struct</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9670104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9670154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9670243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\struct</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9671376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9671620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 480 378, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9671767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 480 404, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9671847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 480 418, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9671933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9673005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9673069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9673166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\shutil</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9673282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9673329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9673418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\shutil</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9674521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9674886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 260 406, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9675169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 260 432, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9675291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 260 446, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9675366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 265 566, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9675454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9677050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9677114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9677216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\fnmatch</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9677335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9677380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9677468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\fnmatch</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9678590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9678829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 084 943, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9678992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 084 969, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9679078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 084 984, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9679139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 086 008, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9679222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9679843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9679904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9680001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\re</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9680117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9680164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9680250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\re</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9681333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9681558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 252 457, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9681699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 252 483, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9681788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 252 493, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9681849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 255 053, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9681929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9682932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9682996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9683093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\sre_compile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9683203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9683251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9683336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\sre_compile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9684434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9684830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 443 297, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9685021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 443 323, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9685118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 443 342, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9685179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 448 462, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9685265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9686841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9686905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9687002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\sre_parse</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9687121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9687168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9687254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\sre_parse</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9688379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9688617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 451 419, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9688764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 451 445, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9688850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 451 462, Length: 7 680</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9688925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 459 142, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9689008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9690911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9690975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9691077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\sre_constants</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9691197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9691244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9691332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\sre_constants</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9692435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9692698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 448 705, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9692820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 448 731, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9692917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 448 752, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9692978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 451 312, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9693064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9696799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9696876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9696984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\collections</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9697106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9697153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9697245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\collections</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9698419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9698669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 844 022, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9698824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 844 048, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9698940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 844 067, Length: 6 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9699007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 850 211, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:30,9699093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0103074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0103171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0103295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\keyword</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0103461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0103511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0103614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\keyword</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0105304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0105609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 130 664, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0105808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 130 690, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0105902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 130 705, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0105994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0106847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0106914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0107013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\heapq</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0107138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0107185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0107274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\heapq</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0108374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0108609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 105 120, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0108753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 105 146, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0108842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 105 159, Length: 4 608</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0108914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 109 767, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0109000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0112402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0112477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0112582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\pwd</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0112704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0112751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0112843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\pwd</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0113078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0113128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0113203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\grp</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0113286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0113330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0113402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\grp</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0114624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0114713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0114840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\io</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0114957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0115004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0115087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\io</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0116250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0116500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 119 812, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0116652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 119 838, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0116752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 119 848, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0116813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 120 360, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0116899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0120282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0120356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0120467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\string</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0120589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0120639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0120730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\string</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0121861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0122107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 470 224, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0122263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 470 250, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0122348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 470 264, Length: 4 096</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0122409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 474 360, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0122495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0137578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0137664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0137778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\tempfile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0137905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0137955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0138044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\tempfile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0139235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0139509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 513 636, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0139664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 513 662, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0139767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 513 678, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0139833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 518 798, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0139930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0141504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0141568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0141670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\fcntl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0141789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0141837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0141922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\fcntl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0142391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0142440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0142521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\PySide</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0142607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0142651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0142729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\PySide</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0144191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0144435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 074, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0144579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 100, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0144665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 123, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0144726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 635, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0144809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0146233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0147117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0148084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0148284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0148502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0149849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0150076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 883, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0150198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 909, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0150284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 930, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0150345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 269 490, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0150425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0151578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0151644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0151744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\ctypes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0151866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0151913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0152002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\ctypes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0153079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0153634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 857 725, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0153869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 857 751, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0153966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 857 774, Length: 5 632</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0154030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 863 406, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0154129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0162588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0163644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0164599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0164804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0165001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0165469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0165536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0165638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\_ctypes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0165760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0165807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0165896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\_ctypes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0166999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0167234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 746 184, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0167417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 746 210, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0167581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 746 225, Length: 40 448</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0167722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 786 673, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0167811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0173939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77ac0000, Image Size: 0xec000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0176834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0177158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0177253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0177330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0186016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0186088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0186204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\OLE\Tracing</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0186318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\Tracing</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0186689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\1aff6089-e863-4d36-bdfd-3581f07440be</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0189415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0189684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:14, LastAccessTime: 20.07.2018 1:34:14, LastWriteTime: 21.06.2017 10:42:23, ChangeTime: 20.07.2018 19:26:57, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0189778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0198733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0198996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 863 896, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0199154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 863 922, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0199243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 863 944, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0199303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 864 456, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0199395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0203022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0203274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 864 828, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0203418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 864 854, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0203504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 864 877, Length: 2 048</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0203565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 866 925, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0203648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0208427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0208679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 138 307, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0208873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 138 333, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0209912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 138 354, Length: 514 560</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0211267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 652 914, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0211378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0303920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0304322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 024 727, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0304543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 024 753, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0304781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 024 777, Length: 47 104</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0304953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 071 881, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0305050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0313578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0313872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 072 256, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0314016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 072 282, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0314226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 072 308, Length: 44 544</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0314373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 116 852, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0314465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0323416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0323613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:08, LastAccessTime: 16.07.2016 14:43:08, LastWriteTime: 16.07.2016 14:43:08, ChangeTime: 19.07.2018 19:37:26, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0323704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0324954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0325170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0325347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0326248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0326428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0326716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0327580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0327749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0328725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0329320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x6d180000, Image Size: 0x8e000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0329991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0334449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0334701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 7 318 446, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0334870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 7 318 472, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0337618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 7 318 487, Length: 1 030 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0340333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 631, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0340452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0692760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74fd0000, Image Size: 0x63000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0695436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0695816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0695915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0695998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0696733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\d0f1a5c6-fc43-48ae-99bf-efb1c38be9d1</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0701348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0701628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:04, LastAccessTime: 16.07.2016 14:43:04, LastWriteTime: 16.07.2016 14:43:04, ChangeTime: 20.07.2018 19:29:06, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0701728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0702720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0703014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0703196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0704149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0704349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0704654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0705535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0705704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0706463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0706989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x746e0000, Image Size: 0x8000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0707693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0708848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0709117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0709195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0709261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0710023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0710139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0710245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0710303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 16</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0711580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\kernel32.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0711832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\kernel32.dll.mui</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0711954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0712843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0713029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0713309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0714165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0714334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0714921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\kernel32.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 958 464, EndOfFile: 957 440, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0715079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\kernel32.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0715719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\540dc156-e9d6-42dc-a225-29794149a495</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0717168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\kernel32.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0828465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0828570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0828730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\atexit</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0828919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0828969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0829071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\atexit</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0830761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0831094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 816 273, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0831335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 816 299, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0831426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 816 313, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0831484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 816 825, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0831573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0835779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe\PySide</Path>
<Result>PATH NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0837247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\KernelBase.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0837527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\KernelBase.dll.mui</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0837699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0838649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0838840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0839148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0840037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0840209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0840868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\KernelBase.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 958 464, EndOfFile: 957 952, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0841032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\KernelBase.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0842791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0843251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 517 646, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0843509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 517 672, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0843905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 517 695, Length: 111 616</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0844199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 629 311, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0844290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0863728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0863980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 117 325, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0864138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 117 351, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0878914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 117 368, Length: 4 961 280</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0891204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 078 648, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,0891331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1770660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\WINMM.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1773082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1773525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:49, LastAccessTime: 16.07.2016 14:42:49, LastWriteTime: 16.07.2016 14:42:49, ChangeTime: 19.07.2018 19:41:04, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1773677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1774774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1775079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1775254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1776182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1776387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1776697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1777581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1777761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1778545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1779368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74230000, Image Size: 0x24000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1780207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1782626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\WINMMBASE.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1785006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1785194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:49, LastAccessTime: 16.07.2016 14:42:49, LastWriteTime: 16.07.2016 14:42:49, ChangeTime: 19.07.2018 19:41:04, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1785275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1786247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1786458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1786569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1787458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1787638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1787923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1788893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1789090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1789760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1790290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x741f0000, Image Size: 0x23000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1790863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1792830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1793046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1793127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1793201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1794329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1794595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1794670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1794733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1796604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1796872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 391 896, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1797108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 391 922, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1810484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 391 936, Length: 3 632 640</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1818824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 024 576, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,1818951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2512757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77be0000, Image Size: 0xe5000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2513539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2518614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe.Local</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2519942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2522662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2522851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:35:27, LastAccessTime: 20.07.2018 1:35:27, LastWriteTime: 02.11.2016 14:04:46, ChangeTime: 20.07.2018 2:17:47, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2522937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2524014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2524214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2524366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2525261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2525452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2525754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2526619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2526788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2527494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2527946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x6dcd0000, Image Size: 0x94000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2528383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2531290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2531603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2531692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2531766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2533517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2533986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2590605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2590970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 927 812, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2591242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 927 838, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2592403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 927 856, Length: 390 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2593192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 7 318 000, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2593295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2667399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2667756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 653 138, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2667975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 653 164, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2731762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 653 184, Length: 1 690 624</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2736245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 343 808, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,2736381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3300397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3300780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 343 973, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3300993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 343 999, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3301528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 344 023, Length: 173 568</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3302082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 517 591, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3302201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3367245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3367353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3367503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\platform</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3367700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3367752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3367861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\platform</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3369501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3370046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 216 758, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3370337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 216 784, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3370445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 216 800, Length: 11 264</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3370526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 228 064, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3370628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3393145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3393233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3393352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\json</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3393499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3393546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3393641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\json</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3394896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3395145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 120 850, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3395303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 120 876, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3395392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 120 897, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3395453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 121 921, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3395538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3397151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3398057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3399154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3399365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3399586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3400705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3400930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 122 095, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3401068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 122 121, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3401154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 122 141, Length: 3 072</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3401221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 125 213, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3401298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3403551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3403778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 129 490, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3403911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 129 516, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3403994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 129 536, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3404055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 130 560, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3404135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3408336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3408585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 008 931, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3408765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 008 957, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3408856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 008 984, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3409042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 009 496, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3409183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3413090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3413339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 125 702, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3413469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 125 728, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3413555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 125 748, Length: 3 584</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3413619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 129 332, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3413702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3417600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3417678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3417786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\threading</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3417913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3417961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3418052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\threading</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3419338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3419581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 521 546, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3419753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 521 572, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3419842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 521 589, Length: 8 192</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3419917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 529 781, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3420005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3422582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3422651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3422754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\traceback</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3422876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3422923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3423011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\traceback</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3424164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3424405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 536 990, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3424546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 537 016, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3424632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 537 033, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3424693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 539 593, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3424776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3429417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3429494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3429602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\socket</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3429730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3429777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3429868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\socket</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3431043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3431284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 437 379, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3431445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 437 405, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3431536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 437 419, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3431597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 442 539, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3431680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3433226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3433290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3433390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\_socket</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3433509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3433556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3433642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\_socket</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3434842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3435080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 169 073, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3435335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 169 099, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3435426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 169 114, Length: 20 992</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3435518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 190 106, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3435603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3439973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3440047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3440150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3440266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>ACCESS DENIED</Result>
<Detail>Desired Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3440419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3440521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3440887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3440940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3441017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3441092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3441172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3441233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 8, Data: 2.0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3441411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 8, Data: 2.0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3441574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3441638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3441851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3441907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog\210B074C</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3442003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3442070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Callout</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 70, Data: %SystemRoot%\System32\fwpuclnt.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3442206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Callout</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 70, Data: %SystemRoot%\System32\fwpuclnt.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3442411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3442480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3442583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 10</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3443109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 10</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3443386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3443444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000000A</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3443525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Next_Catalog_Entry_ID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1013</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3443646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Num_Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 12</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3443793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3443851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3443962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3444015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3444159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3444275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3444419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3444503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3444561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3444644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3444749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3444882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3444957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3445015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3445095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3445298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3445428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3445503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3445561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3445674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3445785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3445913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3445990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3446046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3446126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3446229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3446353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3446428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3446483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3446567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3446669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3446794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3446869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3446924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3447002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3447135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3447268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3447342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3447401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3447481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3447583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3447708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3447783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3447838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3447916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3448162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3448373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3448467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3448528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3448614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3448766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3449016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3449093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3449152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3449235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3449340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3449465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3449537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3449595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3449675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3449778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3449902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3449944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3450091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3450149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3450235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 20</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3450506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 20</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3450661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3450720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\00000014</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3450803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Num_Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 6</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3450947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3451002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3451105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3451155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3451238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\napinsp.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3451365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\napinsp.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3451495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3451623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3451748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3451867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3451994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: A2 CB 4A 96 BC B2 EB 40 8C 6A A6 DB 40 16 1C AE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3452122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\AddressFamily</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3452232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\SupportedNameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 37</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3452354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3452476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3452604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\StoresServiceClassInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3452728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3452853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3455031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3455147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3455219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3455327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3455466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3455596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3455715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3455840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3455962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3456086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: CE 89 FE 03 6D 76 76 49 B9 C1 BB 9B C4 2C 7B 4D</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3456208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\AddressFamily</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3456319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\SupportedNameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 39</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3456441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3456560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3456682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\StoresServiceClassInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3456804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3456942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3457075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3457158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3457219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3457300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3457427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3457552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3457973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3458120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3458242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3458366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: CD 89 FE 03 6D 76 76 49 B9 C1 BB 9B C4 2C 7B 4D</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3458491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\AddressFamily</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3458599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\SupportedNameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 38</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3458721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3458843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3458962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\StoresServiceClassInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3459081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3459206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3459336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3459416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3459477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3459561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\NLAapi.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3459688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\NLAapi.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3459813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3459935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3460056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3460176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3460297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: 3A 24 42 66 A8 3B A6 4A BA A5 2E 0B D7 1F DD 83</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3460419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\AddressFamily</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3460525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\SupportedNameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 15</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3460641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3460760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3460882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\StoresServiceClassInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3461001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3461123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3461251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3461375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3461436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3461517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\System32\mswsock.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3461641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\System32\mswsock.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3461769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3461891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3462018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3462137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3462262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: 40 9D 05 22 9E 7E CF 11 AE 5A 00 AA 00 A7 11 2B</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3462381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\AddressFamily</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3462489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\SupportedNameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 12</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3462605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3462724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3462846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\StoresServiceClassInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3462968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3463087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3463215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3463290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3463351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3463434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\System32\winrnr.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3463567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\System32\winrnr.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3463691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3463816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3463941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3464063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3464185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: EE 37 26 3B 80 E5 CF 11 A5 55 00 C0 4F D8 D4 AC</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3464306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\AddressFamily</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3464417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\SupportedNameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 32</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3464536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3464656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3464775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\StoresServiceClassInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3464897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3465016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3465140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3465182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3465232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3465345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3465395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3465476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock2\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3465553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3465625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3465672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Ws2_32NumHandleBuckets</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3465794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3467493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3467556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3467656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\functools</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3467775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3467820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3467905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\functools</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3469221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3469496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 086 051, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3469681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 086 077, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3469787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 086 094, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3469848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 087 118, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3469933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3471039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3471105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3471202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\_ssl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3471319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3471366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3471452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\_ssl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3472654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3472892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 190 545, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3473028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 190 571, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3474962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 190 583, Length: 590 848</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3476123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 781 431, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3476214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3570641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x753e0000, Image Size: 0x17d000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3571954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x751d0000, Image Size: 0xe000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3574522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3575037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3575137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3575220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3576428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3576708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3576780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3576847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3593506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3593600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3593730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\subprocess</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3593919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3593969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3594071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\subprocess</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3595598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3595905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 480 566, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3596133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 480 592, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3596232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 480 610, Length: 10 240</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3596315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 490 850, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3596401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3599953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3600025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3600133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\win32com</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3600258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3600308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3600399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\win32com</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3601555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3601796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 385 857, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3601948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 385 883, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3602037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 385 908, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3602098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 386 932, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3602178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3603671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3604879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3605863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3606059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3606276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3606655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3606719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3606816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\win32api</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3606938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3606985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3607073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\win32api</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3608179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3608406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 876 773, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3608561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 876 799, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3608653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 876 815, Length: 39 936</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3608788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 916 751, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3608872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3618433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3618688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 909, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3618865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 935, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3619009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 955, Length: 42 496</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3620217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 391 451, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3620328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3636062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\secur32.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3638492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3638783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:01, LastAccessTime: 16.07.2016 14:43:01, LastWriteTime: 16.07.2016 14:43:01, ChangeTime: 19.07.2018 19:38:51, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3638877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3639874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3640162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3640337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3641226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3641412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3641714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3642570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3642742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3644407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3645033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x73ae0000, Image Size: 0xa000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3645770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3646964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3647244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3647324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3647396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3648272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3648344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3648455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\pythoncom</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3648588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3648637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3648729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\pythoncom</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3649953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3650197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 079 147, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3650355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 079 173, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3650530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 079 192, Length: 142 848</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3650857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 040, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3650943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3676800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rpcss.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3681510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3681798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:04, LastAccessTime: 16.07.2016 14:43:04, LastWriteTime: 16.07.2016 14:43:04, ChangeTime: 19.07.2018 19:40:16, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3681901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3683170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3683469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3683630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3684569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3684760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3685087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3685982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3686159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3686949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3687519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74110000, Image Size: 0x75000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3688741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3689930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3690218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3690307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3690387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3730164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3730358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:59, LastAccessTime: 20.07.2018 20:11:59, LastWriteTime: 20.07.2018 13:54:12, ChangeTime: 20.07.2018 20:09:33, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3730449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3731782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3732056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3732253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3733658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3733932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3734403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3735475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3735661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3736406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3736952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x60750000, Image Size: 0x17c000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3737481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3737703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3737830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3738018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3739019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3739238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:59, LastAccessTime: 20.07.2018 20:11:59, LastWriteTime: 20.07.2018 13:54:12, ChangeTime: 20.07.2018 20:09:33, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3740088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3741177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74d90000, Image Size: 0x6000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3741701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3744294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\NETAPI32.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3746632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3746904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:49, LastAccessTime: 16.07.2016 14:42:49, LastWriteTime: 16.07.2016 14:42:49, ChangeTime: 19.07.2018 19:37:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3746998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3747995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3748281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3748411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3749322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3749502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3749807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3750987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3751181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3751880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3752450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x71140000, Image Size: 0x13000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3753010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3756457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\NETUTILS.DLL</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3758776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3759047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:55, LastAccessTime: 16.07.2016 14:42:55, LastWriteTime: 16.07.2016 14:42:55, ChangeTime: 19.07.2018 19:37:42, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3759141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3760133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3760574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3760709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3761649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3761831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3762139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3763028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3763200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3763895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3764461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x70ca0000, Image Size: 0xb000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3764940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3770212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WKSCLI.DLL</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3772717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3772986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:55, LastAccessTime: 16.07.2016 14:42:55, LastWriteTime: 16.07.2016 14:42:55, ChangeTime: 19.07.2018 19:41:08, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3773080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3774091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3774379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3774510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3775418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3775601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3775911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3776795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3776967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3777660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3778189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x70cb0000, Image Size: 0x10000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3778707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3780294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3780602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3780693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3780777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3781890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3782162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3782245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3782322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3783384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3783641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3783722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3783796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3784830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3785082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3785162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3785234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3786271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3786448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3786525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3786600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3798189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3798286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3798428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3798569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3798699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3798791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe\Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 84, Data: C:\Program Files (x86)\360\Total Security</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3799015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3801467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3801647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:30, LastAccessTime: 23.08.2018 15:02:29, LastWriteTime: 23.08.2018 15:02:29, ChangeTime: 23.08.2018 15:02:29, FileAttributes: DA</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3801739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3804085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3804263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:30, LastAccessTime: 20.07.2018 20:11:30, LastWriteTime: 20.07.2018 20:11:30, ChangeTime: 20.07.2018 20:11:30, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3804348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3805393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3805634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>LockFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Exclusive: False, Offset: 0, Length: 4 294 967 295, Fail Immediately: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3805731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 152, EndOfFile: 146, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3805933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 146, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3806440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>UnlockFileSingle</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 4 294 967 295</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3806537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3808898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3809197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:36, LastAccessTime: 20.07.2018 20:11:36, LastWriteTime: 20.07.2018 13:54:11, ChangeTime: 20.07.2018 20:09:20, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3809360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3811624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3811776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:36, LastAccessTime: 20.07.2018 20:11:36, LastWriteTime: 20.07.2018 13:54:11, ChangeTime: 20.07.2018 20:09:20, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3811859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3812946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3813139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>LockFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Exclusive: False, Offset: 0, Length: 4 294 967 295, Fail Immediately: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3813220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 12 288, EndOfFile: 8 350, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3813411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 8 350, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3813885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>UnlockFileSingle</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 4 294 967 295</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3813979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3814431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3814547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3814658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3814721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\ru-RU</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 532</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3814902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3814990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3815062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3815143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3815198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\ru-RU</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 532</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3815328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3815409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\ru-RU</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 90</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3815558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\ru</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {0000004A-57EE-1E5C-00B4-D0000BB1E11E}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3819661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3819839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:30, LastAccessTime: 20.07.2018 20:11:30, LastWriteTime: 20.07.2018 20:11:30, ChangeTime: 20.07.2018 20:11:30, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3819927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3820927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3821124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>LockFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Exclusive: False, Offset: 0, Length: 4 294 967 295, Fail Immediately: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3821207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 152, EndOfFile: 146, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3821385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 146, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3821606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>UnlockFileSingle</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 4 294 967 295</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3821700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3824017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3824191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:36, LastAccessTime: 20.07.2018 20:11:36, LastWriteTime: 20.07.2018 13:54:11, ChangeTime: 20.07.2018 20:09:20, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3824277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3826469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3826624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:36, LastAccessTime: 20.07.2018 20:11:36, LastWriteTime: 20.07.2018 13:54:11, ChangeTime: 20.07.2018 20:09:20, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3826707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3827754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3827940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>LockFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Exclusive: False, Offset: 0, Length: 4 294 967 295, Fail Immediately: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3828020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 4 096, EndOfFile: 3 052, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3828192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 3 052, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3828713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>UnlockFileSingle</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 4 294 967 295</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3828810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3829821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3830012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>LockFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Exclusive: False, Offset: 0, Length: 4 294 967 295, Fail Immediately: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3830095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 4 096, EndOfFile: 3 052, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3830264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 3 052, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3830525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>UnlockFileSingle</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 4 294 967 295</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3830611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3834960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3835052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3835185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3835315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3835415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3835478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe\Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 84, Data: C:\Program Files (x86)\360\Total Security</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3835695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3836914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3837138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>LockFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Exclusive: False, Offset: 0, Length: 4 294 967 295, Fail Immediately: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3837227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 12 288, EndOfFile: 8 350, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3837437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 8 350, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3837975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>UnlockFileSingle</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 4 294 967 295</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3838072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3839382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3839457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3839582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3839737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3840089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3840172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3840305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3840382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3840557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 30, Data: Common AppData</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3840748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3840881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3841009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3841125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3841244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3841363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3841482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3841601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3841721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3841840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3841959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3842078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3842197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3842313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3842433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3842552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3842668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3842787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3842909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3843103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3843181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3843286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3843527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3843588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3843690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3843810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3843887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3843943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 52, Data: %SystemDrive%\ProgramData</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3844098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 52, Data: %SystemDrive%\ProgramData</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3844286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3844588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\FileSystem\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3844677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\FileSystem</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3844763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\FileSystem</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3844818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\FileSystem\LongPathsEnabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3844976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\FileSystem</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3846034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\ProgramData</Path>
<Result>NAME COLLISION</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3850766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\ProgramData</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3851043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\ProgramData</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:47:48, LastAccessTime: 20.07.2018 20:20:30, LastWriteTime: 20.07.2018 20:20:30, ChangeTime: 20.07.2018 20:20:30, FileAttributes: HDNCI</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3851138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\ProgramData</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3851429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3851501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3851625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3851769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3851828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3851919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3863594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\urlmon.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3865946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3866237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:59, LastAccessTime: 20.07.2018 1:34:59, LastWriteTime: 30.03.2018 5:58:40, ChangeTime: 20.07.2018 19:24:44, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3866326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3867296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3867836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3868016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3868961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3869152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3869448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3870321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3870493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3871213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3871825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x72cc0000, Image Size: 0x195000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3872693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3875073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\iertutil.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3877480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3877741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:35:05, LastAccessTime: 20.07.2018 1:35:05, LastWriteTime: 30.03.2018 6:32:00, ChangeTime: 20.07.2018 19:25:12, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3877824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3878788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3879062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3879184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3880054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3880237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3880517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3881376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3881545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3882210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3882758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x725e0000, Image Size: 0x22b000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3883487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3886277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3886573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3886656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3886731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3888443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3888726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3888803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3888875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3889964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\0bca4784-8257-51a0-d9ec-24fe1fe4c90d</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3890854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\ff32ada1-5a4b-583c-889e-a3c027b201f5</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3893918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3894200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 435 714, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3894442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 435 740, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3894533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 435 772, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3894619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3895375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe\win32com\</Path>
<Result>PATH NOT FOUND</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3896345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3897398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3898783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3898982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3899201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3900684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3900908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 387 475, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3901063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 387 501, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3901155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 387 533, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3901235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 392 653, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3901313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3903302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe\win32com\</Path>
<Result>PATH NOT FOUND</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3904291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3905183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3906106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3906297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3906820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3908231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3908458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 400 491, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3908607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 400 517, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3908696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 400 548, Length: 6 656</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3908760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 407 204, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3908837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3911098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3911181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3911306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\winerror</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3911478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3911525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3911625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\winerror</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3912766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3913002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 347 472, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3913168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 347 498, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3913256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 347 514, Length: 37 888</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3913381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 385 402, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3913467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3924400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3924643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 392 977, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3924785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 393 003, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3924873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 393 032, Length: 7 168</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3924934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 400 200, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3925020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3966906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3967022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3967177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\pywintypes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3967349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3967401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3967504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\pywintypes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3969058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3969352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 909, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3969551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 935, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3969648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 955, Length: 42 496</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3969892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 391 451, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3969986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3979858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3980110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 407 375, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3980273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 407 401, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3980368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 407 433, Length: 6 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3980443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 413 577, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3980528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3982332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3982399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3982507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\glob</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3982631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3982681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3982773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\glob</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3983881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3984116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 095 792, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3984310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 095 818, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3984410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 095 830, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3984474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 096 854, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3984557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3987327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3987568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 387 081, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3987710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 387 107, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3987790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 387 143, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3987876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3990976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3991051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3991159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\helpers</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3991286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3991334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3991422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\helpers</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3992641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3992882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 601 095, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3993032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 601 121, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3993126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 601 136, Length: 93 184</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3993351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 694 320, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,3993436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4011171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\OneDrive\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4012221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4012470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Desktop\*</Path>
<Result>SUCCESS</Result>
<Detail>Filter: *, 1: .</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4012756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>0: .., 1: desktop.ini, 2: MCLauncher.lnk, 3: ProcessMonitor.zip, 4: Uninstall Tool.lnk, 5: Yandex.lnk, 6: µTorrent.lnk, 7: Помощник по обновлению до Windows 10.lnk</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4012958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>NO MORE FILES</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4013049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4014155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4014368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Desktop\*</Path>
<Result>SUCCESS</Result>
<Detail>Filter: *, 1: .</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4014537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>0: .., 1: desktop.ini, 2: MCLauncher.lnk, 3: ProcessMonitor.zip, 4: Uninstall Tool.lnk, 5: Yandex.lnk, 6: µTorrent.lnk, 7: Помощник по обновлению до Windows 10.lnk</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4014698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>NO MORE FILES</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4014784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4017366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4017524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:13:55, LastAccessTime: 24.08.2018 12:13:55, LastWriteTime: 24.08.2018 12:14:13, ChangeTime: 24.08.2018 12:14:13, AllocationSize: 01.01.1601 3:00:01, EndOfFile: 01.01.1601 3:00:01, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4017607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4019904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4020067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4020142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4021217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4021411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4022613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4022838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Wina</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4022940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:13:55, LastAccessTime: 24.08.2018 12:13:55, LastWriteTime: 24.08.2018 12:14:13, ChangeTime: 24.08.2018 12:14:13, FileAttributes: A, AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x500000001fca2, EaSize: 0, Access: Generic Read, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4023098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Wina</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4023165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:13:55, LastAccessTime: 24.08.2018 12:13:55, LastWriteTime: 24.08.2018 12:14:13, ChangeTime: 24.08.2018 12:14:13, FileAttributes: A, AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x500000001fca2, EaSize: 0, Access: Generic Read, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4119250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 17 240 064, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4157775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 064, Length: 85</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4157897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>END OF FILE</Result>
<Detail>Offset: 17 240 149, Length: 4 096</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4158110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4159955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Write, Read Attributes, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Overwritten</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4172875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Wina</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4172988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:11, LastWriteTime: 24.08.2018 12:38:31, ChangeTime: 24.08.2018 12:38:31, FileAttributes: A, AllocationSize: 0, EndOfFile: 0, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x600000001de63, EaSize: 0, Access: Generic Write, Read Attributes, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4173285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 17 240 064, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4214416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 16 777 216, Length: 262 144, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4243757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 039 360, Length: 200 704, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4247585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 064, Length: 85, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4247923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4248104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4249564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4249760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4346622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 507 776, Length: 32 768, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4461753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4461861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4462035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4462689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4462742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4462839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4462936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4463052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4463127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\EnableShellExecuteHooks</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4463360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4463454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4463509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4463728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4463914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4463988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\EnableShellExecuteHooks</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4464182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4467211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4467421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4467513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4468837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4468901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4469009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4469097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4469208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4469258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4469333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Explorer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4470316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4470535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryRemoteProtocolInformation</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>INVALID PARAMETER</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4470635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4470837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4473766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4474068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:17, LastAccessTime: 20.07.2018 1:34:17, LastWriteTime: 06.03.2018 9:03:35, ChangeTime: 20.07.2018 19:24:46, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4474151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4475140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4475431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4475605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4476528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4476725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4477021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4478030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4478207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4478938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4479545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x728e0000, Image Size: 0x14f000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4480299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4482202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4482499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4482784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4482900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4484962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4485031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4485147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4485244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4485322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4485399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4485574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4485651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4485704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4485790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4485881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4485928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4486064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4486147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4486197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4486289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4486366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4486424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4486469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4486591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4486660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4486710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4486787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4486868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4486909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4487973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4488962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4489012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4489092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4489162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4489217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4489261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4489383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4489450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4489500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4489572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4489647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4489688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4489799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4490098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4490148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4490234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4490361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4490406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\ValidateRegItems</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4490522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4490591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4490641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4490722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4490802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4490843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\MonitorRegistry</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4490974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4491373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4491425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4491508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4491583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4491639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4491686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4491813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4491880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4491930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4492004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4492234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4492287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4492406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4493401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4493506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4493561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4493631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4493700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4493744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4493844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4494035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4494165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4494210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4494276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4494370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4494445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4494570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4494639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4494739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4494819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4494930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4494999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4495096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4495174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4495285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4495348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4495448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4495526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1581568</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4495670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4495789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4495842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4495922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4496038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4496083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4496168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4496304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4496349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4496415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4496498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4496545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4496617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4496681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4496748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4496792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4496928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4497304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4497357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4497446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4497551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4497598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\ValidateRegItems</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4497731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4497803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4497853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4497936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4498014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4498058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\MonitorRegistry</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4498180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4498407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4498474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4498543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4498590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4498668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Drive\shellex\FolderExtensions</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4498773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4498867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4498920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4498986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4499072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Drive\shellex\FolderExtensions</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4499141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: {fbeb8a05-beee-4442-804e-409d6c4515e9}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4499222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4499277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4499341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4499385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4499454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4499532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4499610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4499648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4499706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4499787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4499848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 32</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4500000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4500105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 1, Length: 288</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4500164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4500687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4500740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4500831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4500914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4500978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4501028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4501164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4501233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4501286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4501361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4501444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4501485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4501602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4502339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4502394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4502488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KindMap</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4502582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4502646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4502696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: program</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4502876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4502926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4502987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4503056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4503106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4503181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4503275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4503353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4503394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4503452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4503546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4503610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\.exe\Content Type</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 50, Data: application/x-msdownload</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4503757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4504422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4504511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4505068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4505128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\COM3</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4505214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\COM3</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4505259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\COM3\Com+Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4505414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\COM3</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4505987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74ef0000, Image Size: 0x84000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4507996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4508290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4508473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4508545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4509841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4509933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4510010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4510063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4510171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4510309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4510420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4510470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4510531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4510636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4510728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4510783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4510858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4510963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4511019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4511107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4511185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 48, Data: Memory Mapped Cache Mgr</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4511249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4511304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4511387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4511451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 48, Data: Memory Mapped Cache Mgr</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4511512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4511736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4511847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4511958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4512013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4512108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4512168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4512249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4512318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4512448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4512520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4512617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4512695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\system32\propsys.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4512753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4512811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4512892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4512953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\system32\propsys.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4513022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4513080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4513160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4513221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\system32\propsys.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4513285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4513338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4513421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4513482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Both</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4513645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4513695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4513764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4513864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4513964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x100</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4514931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4515008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings\Software\Microsoft\Ole\FeatureDevelopmentProperties</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4515091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4515155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4515205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Ole\FeatureDevelopmentProperties</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4515296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4515377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4515424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4515499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\OLE</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4515573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4515629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4515670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\MaxSxSHashCount</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4515806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4516305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4516385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4516441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4516507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4516576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4516626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4516712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4516820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4516895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4516939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4517003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4517095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4517178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4517233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4517305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4521203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4521591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:17, LastAccessTime: 20.07.2018 1:34:17, LastWriteTime: 06.03.2018 9:03:35, ChangeTime: 20.07.2018 19:24:46, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4521685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4524085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4524317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:17, LastAccessTime: 20.07.2018 1:34:17, LastWriteTime: 06.03.2018 9:03:35, ChangeTime: 20.07.2018 19:24:46, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4524400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4526861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\System32\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4527113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Windows\System32\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:24:02, LastAccessTime: 20.07.2018 1:24:02, LastWriteTime: 06.03.2018 9:08:30, ChangeTime: 20.07.2018 19:29:33, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4527193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\System32\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4530407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4530640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:17, LastAccessTime: 20.07.2018 1:34:17, LastWriteTime: 06.03.2018 9:03:35, ChangeTime: 20.07.2018 19:24:46, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4530720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4533078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4533300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:17, LastAccessTime: 20.07.2018 1:34:17, LastWriteTime: 06.03.2018 9:03:35, ChangeTime: 20.07.2018 19:24:46, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4533380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4535837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\System32\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4536059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Windows\System32\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:24:02, LastAccessTime: 20.07.2018 1:24:02, LastWriteTime: 06.03.2018 9:08:30, ChangeTime: 20.07.2018 19:29:33, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4536137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\System32\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4537766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4537835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4537951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4538051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4538126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4538181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4538347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4538428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4538483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4538569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4538661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4538705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4538832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4538927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4538979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4539060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4539145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4539209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4539265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4539331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellState</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 36, Data: 24 00 00 00 34 28 00 00 00 00 00 00 00 00 00 00</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4539472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellState</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 36, Data: 24 00 00 00 34 28 00 00 00 00 00 00 00 00 00 00</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4539603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4539713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4539766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4539860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4539941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4539999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4540046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4540176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4540243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4540295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4540370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4540450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4540492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4540611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4540689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4540738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4540955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4541093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4541193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4541276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4541431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4541503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4541556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4541636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4541716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4541761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4541880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4541960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4542944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4543027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4543099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4543152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4543193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4543312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4543376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4543426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4543501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4543576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4543617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4543805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4543891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4543952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4544030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4544163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4544282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4544398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4544512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4544628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4544745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4544864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4544977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4545094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4545213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4545327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4545437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4545551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4545667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4545781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowStatusBar</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4546839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4546997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4547066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4547141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4547191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4547271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4547380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4547468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4547596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4547657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4547762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4547828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\.exe\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: exefile</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4547959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\CurVer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\CurVer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4548973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4549992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4550073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4550147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4550197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4550330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4550388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4550466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4550524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4550654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4550713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4550807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4551048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4551142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4551272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4551341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4551438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4551505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\SystemFileAssociations\.exe\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4551641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4551704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4551796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4551879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4551929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\SystemFileAssociations\.exe\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4552954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4553015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4553106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4553187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4553239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4553386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4553442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4553519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4553577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\.exe\Content Type</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 50, Data: application/x-msdownload</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4553732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4553796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4553890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4553968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\IsShortcut</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4554971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\SystemFileAssociations\.exe\IsShortcut</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4555098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4555156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4555245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4555309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\AlwaysShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4555420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4555481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4555572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4555636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\SystemFileAssociations\.exe\AlwaysShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4555758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4555819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4555907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4555968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\NeverShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4556082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4556143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4556234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4556295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\SystemFileAssociations\.exe\NeverShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4556448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4556503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4556550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4556905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4556957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4557052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4557154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4557226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4557279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4557365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4557417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4557559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: Desktop</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4557694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4557808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4557916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: Desktop</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4558041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4558149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4558257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21769</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4558384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-183</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4558509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4558617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4558722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4558827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4558930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4559113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4559238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4559346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4559462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4559567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4559686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4559792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4559936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4559997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4560094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4560296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4560351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4560457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4560506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4560581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4560797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4560905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4560952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4561027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4561119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4561169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4561216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 44, Data: %USERPROFILE%\Desktop</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4561509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4563718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>NAME COLLISION</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4566463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4566671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: DACL</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4566760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4567707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4567879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>SUCCESS</Result>
<Detail>Information: DACL</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4567954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4569142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\cversions.1.db</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4569466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\cversions.1.db</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4569624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4570705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4570902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4571198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4572060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4572226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4572966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\cversions.1.db</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 16 384, EndOfFile: 16 384, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4573124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\cversions.1.db</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4573392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\cversions.1.db</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4574850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4575066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 135 168, EndOfFile: 134 416, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4575251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4575368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4576252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4576432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4576706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4577551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4577714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4578354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 135 168, EndOfFile: 134 416, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4578498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4578731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4580992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Desktop\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4581208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Desktop\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 288, EndOfFile: 282, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4581311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Desktop\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 282, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4581793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Desktop\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:13, LastAccessTime: 19.07.2018 20:08:13, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4581892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Desktop\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4582577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4582663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4582740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4582790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4583375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4583513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4583594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4583715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4583790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4583851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Directory\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4583962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Folder\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4584951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AllFilesystemObjects\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4585910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\Directory\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4586037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Directory\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4586176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4586231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4586295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4586361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4586419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Directory\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4586508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4586583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4586638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4586724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4586788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Folder\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4586913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4586971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Folder\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\AllFilesystemObjects\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AllFilesystemObjects\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4587993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\Directory\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Directory\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Directory\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4588979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Folder\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4589093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4589154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4589245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4589323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4589376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Folder\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4589445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4589498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4589572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4589628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\AllFilesystemObjects\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4589741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4589802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4589988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AllFilesystemObjects\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Directory\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Folder\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4590949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AllFilesystemObjects\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\Directory\IsShortcut</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Directory\IsShortcut</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4591936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Folder\IsShortcut</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4592052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4592110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4592202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4592265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\AllFilesystemObjects\IsShortcut</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4592385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4592448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4592523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4592592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4592631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\Directory\AlwaysShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4592731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Directory\AlwaysShowExt</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 2, Data: </Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4592858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4592916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4592977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4593055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4593121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4593160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\Directory\NeverShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4593257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Directory\NeverShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4593363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4593412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4593471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4593565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4593631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Folder\NeverShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4593745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4593806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4593897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4593961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\AllFilesystemObjects\NeverShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4594088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4594144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4594185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4594587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4594640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4594737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4594834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4594900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4594953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4595033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4595086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4595227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Libraries</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4595366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4595493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4595607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 56, Data: Microsoft\Windows\Libraries</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4595734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4595903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4596008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4596114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4596219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4596321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4596424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4596532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4596635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4596737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4596856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4596961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4597078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4597186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4597288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4597394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4597535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4597596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4597685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4597859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4597915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4598023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4598072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4598142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4598228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4598316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4598363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4598435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4598519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4598560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4598613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4598881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4598934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4599026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4599114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4599175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4599228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4599308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4599358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4599494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: AppData</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4599627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4599846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4599954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: AppData\Roaming</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4600128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4600239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4600347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4600450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4600552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4600655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4600760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4600862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4600968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4601070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4601170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4601272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4601375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4601525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4601627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4601730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4601868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4601932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4602021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4602115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4602170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4602264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4602314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4602378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4602422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 60, Data: %USERPROFILE%\AppData\Roaming</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4602694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4603073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4603126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4603226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4603320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4603386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4603439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4603519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4603569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4603705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: Local Documents</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4603835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4603946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4604049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Documents</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4604176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4604284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{d3162b92-9365-467a-956b-92703aca08af}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4604409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4604517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21770</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4604641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-112</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4604766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4604874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4604977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4605085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4605187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4605290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4605406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4605511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4605614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4605719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4605836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4605941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4606088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4606149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4606237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4606387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4606442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4606531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4606581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4606650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4606739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4606825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4606869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4606941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4607019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4607063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4607110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{F42EE2D3-909F-4907-8871-4C22FC0BF756}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4607312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4607365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4607456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4607539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4607600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4607653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4607733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4607783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4607913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: Profile</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4608046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4608157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4608263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4608368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4608470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4608576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4608678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4608781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4608886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4608988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4609094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4609196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4609335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4609565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4609687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4609792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4609897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4610005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4610111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4610252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4610316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4610410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4610884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4610939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4611036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4611141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4611216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4611258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4611410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4611546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4611634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4612959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Documents\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4613178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Documents\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 408, EndOfFile: 402, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4613280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Documents\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 402, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4613762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Documents\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:14, LastAccessTime: 19.07.2018 20:08:14, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4613862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Documents\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4614352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4614416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4614527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4614632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4614704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4614762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4614859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4614920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4615078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: Local Music</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4615217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4615336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4615441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 12, Data: Music</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4615566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4615674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{3dfdf296-dbec-4fb4-81d1-6a3438bcf4de}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4615801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12689</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4615929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21790</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4616056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-108</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4616181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4616289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4616394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4616497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4616599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4616704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4616824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4616929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4617031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4617139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4617253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4617358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4617500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4617563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4617660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4617821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4617876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4617973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4618023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4618098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4618190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4618275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4618322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4618395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4618475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4618522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4618569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{A0C69A99-21C8-4671-8703-7934162FCF1D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4618810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4618863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4618960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4619046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4619109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4619151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4619467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4619655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4619738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4620971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Music\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4621184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Music\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 504, EndOfFile: 504, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4621284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Music\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 504, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4621703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Music\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:14, LastAccessTime: 19.07.2018 20:08:14, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4621800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Music\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4622345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4622406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4622520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4622625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4622697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4622755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4622861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4622919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4623074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 30, Data: Local Pictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4623215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4623326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4623431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Pictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4623559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4623670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{24ad3ad4-a569-4530-98e1-ab02f9417aa8}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4623792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12688</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4623922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21779</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4624049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-113</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4624174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4624282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4624384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4624490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4624595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4624698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4624814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4624952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4625060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4625163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4625279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4625385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4625526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4625592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4625689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4625853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4625911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4626005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4626055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4626127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4626219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4626307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4626354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4626429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4626512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4626559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4626606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{0DDD015D-B06C-45D5-8C4C-F59713854639}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4626856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4626906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4627000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4627086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4627147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4627191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4627327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4627463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4627546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4628828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Pictures\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4629178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Pictures\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 504, EndOfFile: 504, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4629286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Pictures\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 504, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4629698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Pictures\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:13, LastAccessTime: 19.07.2018 20:08:13, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4629798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Pictures\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4630280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4630341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4630455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4630560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4630632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4630690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4630782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4630840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4630992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 26, Data: Local Videos</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4631131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4631247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4631355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 14, Data: Videos</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4631480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4631591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{f86fa3ab-70d2-4fc7-9c99-fcbf05467f3a}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4631715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12690</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4631846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21791</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4631973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-189</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4632098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4632209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4632347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4632458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4632563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4632666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4632788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4632893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4632998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4633101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4633217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4633325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4633466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4633530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4633627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4633788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4633843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4633940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4633993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4634065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4634153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4634242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4634289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4634364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4634450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4634494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4634544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4634785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4634838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4634935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4635018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4635084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4635129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4635273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4635447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4635536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4636808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Videos\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4637021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Videos\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 504, EndOfFile: 504, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4637121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Videos\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 504, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4637600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Videos\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:09, LastAccessTime: 19.07.2018 20:08:09, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4637700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Videos\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4638185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4638246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4638359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4638464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4638537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4638595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4638797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4638894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4639052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: Local Downloads</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4639190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4639304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4639409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Downloads</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4639534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4639642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{088e3905-0323-4b02-9826-5d99428e115f}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4639767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4639875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21798</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4639999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-184</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4640124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4640229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4640335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4640437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4640542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4640645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4640764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4640867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4640969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4641072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4641188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4641293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4641435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4641501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4641606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4641773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4641831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4641922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4641972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4642044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4642135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4642221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4642268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4642343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4642426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4642471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4642521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4642773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4642825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4642922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4643005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4643069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4643113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4643249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4643382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4643463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4644718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4644939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Downloads\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 288, EndOfFile: 282, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4645042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 282, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4645369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Downloads\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:15, LastAccessTime: 19.07.2018 20:08:15, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4645463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4646011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4646072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4646186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4646291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4646363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4646422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4646516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4646574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4646729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: OneDrive</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4646870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {5E6C858F-0E22-4760-9AFE-EA3317B67173}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4646998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4647106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: OneDrive</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4647233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 94, Data: shell:::{018D5C66-4533-4307-9B53-224DE2ED1FE6}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4647361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4647472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 98, Data: @%SystemRoot%\System32\SettingSyncCore.dll,-1024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4647596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 82, Data: %SystemRoot%\system32\imageres.dll,-1040</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4647721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4647829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4647931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4648037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\LocalRedirectOnly</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4648186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4648292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4648397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4648616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4648724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\DefinitionFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 64</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4648843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4648959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4649067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4649209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4649275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4649367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4649533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4649591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4649685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4649735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4649804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4649896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4649982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4650029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4650104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4650184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4650231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4650278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4650527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4650577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4650674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4650757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4650818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4650863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4650998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4651134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4651215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4652486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\OneDrive\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4652694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\OneDrive\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 96, EndOfFile: 95, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4652797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\OneDrive\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 95, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4653187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\OneDrive\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:26:50, LastAccessTime: 19.07.2018 20:26:50, LastWriteTime: 23.08.2018 20:16:07, ChangeTime: 23.08.2018 20:16:07, FileAttributes: HS</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4653284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\OneDrive\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4653869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4653933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4654043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4654138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4654207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4654257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4654415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4654564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4654897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4654952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4655052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4655146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4655213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4655271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4655359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4655412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4655551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: UsersFilesFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4655684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4655792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4655897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4655999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: ::{59031a47-3f72-44a7-89c5-5595fe6b30ee}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4656124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4656229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4656332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4656432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4656531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4656634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4656736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4656839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4656941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4657044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4657146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4657246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4657349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4657454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4657556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4657695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4657756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4657850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4657961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4658027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4658091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4658141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4658504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4658701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4658834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4658886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4658950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4659055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4659133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4035182893</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4659269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4659338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4659440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4659523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4659632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4659698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4659801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4659878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4659983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4660050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4660150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4660227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 5243433</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4660366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4660463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4660515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4660596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4660712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4660759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4660845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4660956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4661000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4661069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4661153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4661200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4661272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4661338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4661405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4661449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{59031A47-3F72-44A7-89C5-5595FE6B30EE}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4661582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4661848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4661901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4661992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4662095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4662142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\ValidateRegItems</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4662266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4662336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4662385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4662469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4662546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4662588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\MonitorRegistry</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4662701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4662865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4662917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4663003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4663100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4663161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders\StorageDelegateSuppressionPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {92803FB4-7706-4035-ACD7-F63E069D3697}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4663297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4663394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4663447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4663530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4663605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4663663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4663710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\PreventItemCreationInUsersFilesFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4663834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4663901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4663954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4664031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4664114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4664156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\PreventItemCreationInUsersFilesFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4664275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4664342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4664391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4664474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4664560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4664602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders\StorageDelegate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {DFFACDC5-679F-4156-8947-C5C76BC0B67F}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4664732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4665173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4665242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4665314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4665361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4665452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4665588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4665699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4665749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4665813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4665910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4665979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4666192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4666262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4666328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4666378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4666464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4666572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4666677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4666719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4666785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4666877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4666943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\Windows.Storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4667018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4667073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4667156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4667223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32\LoadWithoutCOM</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4667359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4667478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4667541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4667611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4667661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4667747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4667852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4667935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4668112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4668190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4668295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4668395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4668450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4668520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4668592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4668647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4668733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4668802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 50, Data: Shell File System Folder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4668866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4668921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 50, Data: Shell File System Folder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4669957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\Windows.Storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\Windows.Storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\Windows.Storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Both</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4670966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4671016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4671082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4671185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4671282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4671334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4671401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4671456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4671539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4671617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4671670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4671744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4671916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4671980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4672044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4672094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4672174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4672268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4672343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4672387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4672443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4672529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4672609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4672661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4672728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4672919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4672986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4673080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4673174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4673224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4673454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4673523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4673620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4673706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 17</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4673847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4673917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4674016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4674097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 17</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4674232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4674299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4674396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4674476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\DescriptionID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4674598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4674665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4674762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4674839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\HelpTopic</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4674958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4675025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4675119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4675197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\AllowChildAliasRegistration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4675310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4675379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4675476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4675554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\RecursiveSearch</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4675720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4675789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4675886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4675967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\TargetKnownFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {5E6C858F-0E22-4760-9AFE-EA3317B67173}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4676147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4676213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4676310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4676391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\TargetKnownFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {5E6C858F-0E22-4760-9AFE-EA3317B67173}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4676665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4676740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4676842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Notify</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4676939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4676992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Notify</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4677086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4677136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4679898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4680064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:06:01, LastAccessTime: 20.07.2018 19:30:20, LastWriteTime: 20.07.2018 19:30:20, ChangeTime: 20.07.2018 19:30:20, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4680153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4680907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4681037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4681117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4681170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4681281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4681416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4681522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4681572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4681638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4681743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4681832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4681887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4681968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 70, Data: Property System Both Class Factory</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 70, Data: Property System Both Class Factory</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4682976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4683057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4683120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4683251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4683320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4683420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4683497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\system32\propsys.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4683555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4683611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4683691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4683752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\system32\propsys.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4683819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4683874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4683954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4684012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\system32\propsys.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4684076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4684132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4684212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4684273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Both</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4684431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4684481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4684550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4684652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4684749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4684802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4684871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4684927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4685963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4686043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4686096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4686168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4686772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4686822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4686905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4686991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: {008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: {00BCFC5A-ED94-4e48-96A1-3F6217F21990}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 2, Name: {0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 3, Name: {0482af6c-08f1-4c34-8c90-e17ec98b1e17}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 4, Name: {054FAE61-4DD8-4787-80B6-090220C4B700}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 5, Name: {0762D272-C50A-4BB0-A382-697DCD729B80}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 6, Name: {0AC0837C-BBF8-452A-850D-79D08E667CA7}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 7, Name: {0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 8, Name: {0ddd015d-b06c-45d5-8c4c-f59713854639}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 9, Name: {0F214138-B1D3-4a90-BBA9-27CBC0C5389A}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 10, Name: {10C07CD0-EF91-4567-B850-448B77CB37F9}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 11, Name: {1777F761-68AD-4D8A-87BD-30B759FA33DD}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 12, Name: {18989B1D-99B5-455B-841C-AB7C74E4DDFC}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 13, Name: {190337d1-b8ca-4121-a639-6d472d16972a}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 14, Name: {1A6FDBA2-F42D-4358-A798-B74D745926C5}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4687991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 15, Name: {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 16, Name: {1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 17, Name: {1C2AC1DC-4358-4B6C-9733-AF21156576F0}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 18, Name: {1e87508d-89c2-42f0-8a7e-645a0f50ca58}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 19, Name: {2112AB0A-C86A-4ffe-A368-0DE96E47012E}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 20, Name: {2400183A-6185-49FB-A2D8-4A392A602BA3}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 21, Name: {24D89E24-2F19-4534-9DDE-6A6671FBB8FE}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 22, Name: {289A9A43-BE44-4057-A41B-587A76D7E7F9}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 23, Name: {2A00375E-224C-49DE-B8D1-440DF7EF3DDC}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 24, Name: {2B0F765D-C0E9-4171-908E-08A611B84FF6}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 25, Name: {2B20DF75-1EDA-4039-8097-38798227D5B7}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 26, Name: {2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 27, Name: {2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 28, Name: {31C0DD25-9439-4F12-BF41-7FF4EDA38722}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 29, Name: {3214FAB5-9757-4298-BB61-92A9DEAA44FF}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 30, Name: {339719B5-8C47-4894-94C2-D8F77ADD44A6}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 31, Name: {33E28130-4E1E-4676-835A-98395C3BC3BB}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 32, Name: {352481E8-33BE-4251-BA85-6007CAEDCF9D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 33, Name: {35286a68-3c57-41a1-bbb1-0eae73d76c95}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4688963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 34, Name: {374DE290-123F-4565-9164-39C4925E467B}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 35, Name: {3B193882-D3AD-4eab-965A-69829D1FB59F}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 36, Name: {3D644C9B-1FB8-4f30-9B45-F670235F79C0}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 37, Name: {3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 38, Name: {43668BF8-C14E-49B2-97C9-747784D784B7}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 39, Name: {48daf80b-e6cf-4f4e-b800-0e69d84ee384}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 40, Name: {491E922F-5643-4af4-A7EB-4E7A138D8174}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 41, Name: {4BD8D571-6D19-48D3-BE97-422220080E43}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 42, Name: {4BFEFB45-347D-4006-A5BE-AC0CB0567192}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 43, Name: {4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 44, Name: {4D9F7874-4E0C-4904-967B-40B0D20C3E4B}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 45, Name: {52528A6B-B9E3-4add-B60D-588C2DBA842D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 46, Name: {52a4f021-7b75-48a9-9f6b-4b87a210bc8f}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 47, Name: {54EED2E0-E7CA-4fdb-9148-0F4247291CFA}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 48, Name: {56784854-C6CB-462B-8169-88E350ACB882}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 49, Name: {5cd7aee2-2219-4a67-b85d-6c9ce15660cb}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 50, Name: {5CE4A5E9-E4EB-479D-B89F-130C02886155}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 51, Name: {5E6C858F-0E22-4760-9AFE-EA3317B67173}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 52, Name: {625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4689950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 53, Name: {62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 54, Name: {69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 55, Name: {6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 56, Name: {724EF170-A42D-4FEF-9F26-B60E846FBA4F}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 57, Name: {754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 58, Name: {767E6811-49CB-4273-87C2-20F355E1085B}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 59, Name: {76FC4E2D-D6AD-4519-A663-37BD56068185}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 60, Name: {7b0db17d-9cd2-4a93-9733-46cc89022e7c}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 61, Name: {7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 62, Name: {7d1d3a04-debb-4115-95cf-2f29da2920da}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 63, Name: {7d83ee9b-2244-4e70-b1f5-5393042af1e4}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 64, Name: {7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 65, Name: {82A5EA35-D9CD-47C5-9629-E15D2F714E6E}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 66, Name: {82A74AEB-AEB4-465C-A014-D097EE346D63}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 67, Name: {8983036C-27C0-404B-8F08-102D10DCFD74}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 68, Name: {8AD10C31-2ADB-4296-A8F7-E4701232C972}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 69, Name: {905e63b6-c1bf-494e-b29c-65b732d3d21a}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 70, Name: {915221FB-9EFE-4bda-8FD7-F78DCA774F87}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 71, Name: {9274BD8D-CFD1-41C3-B35E-B13F55A758F4}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 72, Name: {98EC0E18-2098-4D44-8644-66979315A281}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4690967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 73, Name: {9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 74, Name: {9e3995ab-1f9c-4f13-b827-48b24b6c7174}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 75, Name: {9E52AB10-F80D-49DF-ACB8-4330F5687855}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 76, Name: {a0c69a99-21c8-4671-8703-7934162fcf1d}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 77, Name: {A302545D-DEFF-464b-ABE8-61C8648D939B}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 78, Name: {a305ce99-f527-492b-8b1a-7e76fa98d6e4}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 79, Name: {A3918781-E5F2-4890-B3D9-A7E54332328C}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 80, Name: {A4115719-D62E-491D-AA7C-E74B8BE3B067}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 81, Name: {A440879F-87A0-4F7D-B700-0207B966194A}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 82, Name: {A520A1A4-1780-4FF6-BD18-167343C5AF16}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 83, Name: {A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 84, Name: {A63293E8-664E-48DB-A079-DF759E0509F7}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 85, Name: {A77F5D77-2E2B-44C3-A6A2-ABA601054A51}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 86, Name: {A990AE9F-A03B-4e80-94BC-9912D7504104}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 87, Name: {AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 88, Name: {AB5FB87B-7CE2-4F83-915D-550846C9537B}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 89, Name: {AE50C081-EBD2-438A-8655-8A092E34987A}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 90, Name: {B4BFCC3A-DB2C-424C-B029-7FE99A87C641}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4691950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 91, Name: {B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 92, Name: {B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 93, Name: {b7bede81-df94-4682-a7d8-57a52620b86f}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 94, Name: {B88F4DAA-E7BD-49a9-B74D-02885A5DC765}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 95, Name: {B94237E7-57AC-4347-9151-B08C6C32D1F7}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 96, Name: {B97D20BB-F46A-4C97-BA10-5E3608430854}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 97, Name: {bcb5256f-79f6-4cee-b725-dc34e402fd46}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 98, Name: {bcbd3057-ca5c-4622-b42d-bc56db0ae516}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 99, Name: {bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 100, Name: {C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 101, Name: {C3F2459E-80D6-45DC-BFEF-1F769F2BE730}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 102, Name: {C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 103, Name: {C5ABBF53-E17F-4121-8900-86626FC2C973}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 104, Name: {C870044B-F49E-4126-A9C3-B52A1FF411E8}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 105, Name: {CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 106, Name: {D0384E7D-BAC3-4797-8F14-CBA229B392B5}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 107, Name: {D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 108, Name: {D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 109, Name: {D9DC8A3B-B784-432E-A781-5A1130A75963}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 110, Name: {DBE8E08E-3053-4BBC-B183-2A7B2B191E59}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4692970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 111, Name: {de61d971-5ebc-4f02-a3a9-6c82895e5c04}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 112, Name: {DE92C1C7-837F-4F69-A3BB-86E631204A23}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 113, Name: {DE974D24-D9C6-4D3E-BF91-F4455120B917}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 114, Name: {DEBF2536-E1A8-4c59-B6A2-414586476AEA}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 115, Name: {df7266ac-9274-4867-8d55-3bd661de872d}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 116, Name: {DFDF76A2-C82A-4D63-906A-5644AC457385}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 117, Name: {E25B5812-BE88-4bd9-94B0-29233477B6C3}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 118, Name: {E555AB60-153B-4D17-9F04-A5FE99FC15EC}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 119, Name: {ED4824AF-DCE4-45A8-81E2-FC7965083634}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 120, Name: {EDC0FE71-98D8-4F4A-B920-C8DC133CB165}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 121, Name: {EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 122, Name: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 123, Name: {F38BF404-1D43-42F2-9305-67DE0B28FC23}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 124, Name: {f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 125, Name: {f42ee2d3-909f-4907-8871-4c22fc0bf756}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 126, Name: {F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 127, Name: {FD228CB7-AE11-4AE3-864C-16F3910AB8FE}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 128, Name: {FDD39AD0-238F-46AF-ADB4-6C85480369C7}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4693892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 129, Length: 288</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4694042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4694230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4694283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4694388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4694485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4694554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4694613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4694699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4694754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4694912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Searches</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4695050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4695167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4695272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Searches</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4695397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4695508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 160, Data: ::{59031a47-3f72-44a7-89c5-5595fe6b30ee}\{7d1d3a04-debb-4115-95cf-2f29da2920da}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4695635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4695740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 82, Data: @%SystemRoot%\system32\shell32.dll,-9031</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4695868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 78, Data: %SystemRoot%\system32\imageres.dll,-18</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4695995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4696131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4696239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4696341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4696447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4696552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4696671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4696776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\PublishExpandedPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4696896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4697101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4697256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\FolderTypeID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {0b0ba2e3-405f-415e-a6ee-cad625207853}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4697392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4697544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4697610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4697710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d1d3a04-debb-4115-95cf-2f29da2920da}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4697840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4697907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4697973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4698023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4698120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4698234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4698328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4698372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4698439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4698541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4698627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4698680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4698744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4698807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4698860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4698949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 42, Data: Known Folder Manager</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 42, Data: Known Folder Manager</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4699885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4700993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4701054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Both</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4701207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4701256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4701323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4701423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4701520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4701572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4701633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4701689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4701772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4701847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4701899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4701968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4702115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4702176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4702243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4702290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4702373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4702467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4702548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4702589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4702645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4702730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4702811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4702863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4702933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4703229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4703285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4703406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4703456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4703636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4703689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4703780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4703833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4703900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4703977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4704060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4704107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4704179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4704257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4704301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4704351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4704620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4704673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4704767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4704853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4704916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4704961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4705105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4705241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4705324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4705462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4705512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4705601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4705687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4705748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4705806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4705883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4705933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4706080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: Windows</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4706210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4706324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4706432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4706534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4706637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4712413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4712594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4712707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4712810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4712918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4713020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4713123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4713225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4713328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4713436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4713538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4713644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4713746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4713851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4714004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4714084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4714209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4714320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4714372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4714472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4714561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4714627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4714683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4714766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4714810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4714951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 38, Data: ProgramFilesCommon</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4715084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4715195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4715298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4715400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4715500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4715602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4715705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4715807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4715910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4716012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4716115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4716217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4716364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4716470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4716572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4716675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4716935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4717104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4717273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4717467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4717536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4717633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4717733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4717783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4717877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4717960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4718027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4718077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4718160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4718207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4718345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 26, Data: MusicLibrary</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4718478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4718608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4718717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: Music.library-ms</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4718844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4718952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 160, Data: ::{031E4825-7B94-4dc3-B131-E946B44C8DD5}\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4719082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12689</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4719207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-34584</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4719337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 82, Data: %SystemRoot%\system32\imageres.dll,-1004</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4719465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4719573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\StreamResource</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 74, Data: %SystemRoot%\system32\shell32.dll,-2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4719697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\StreamResourceType</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: LIBRARY</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4719828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4719936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4720041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4720163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\Stream</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4720282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4720390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4720492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4720598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4720706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4720844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4720905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4720997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4721099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4721149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4721235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4721313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4721371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4721423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4721498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4721542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4721684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: PublicLibraries</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4721817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {DFDF76A2-C82A-4D63-906A-5644AC457385}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4721944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4722050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Libraries</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4722174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4722282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4722388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4722493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4722595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4722701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4722809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4722914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4723016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4723122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4723241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4723346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4723449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4723554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4723670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4723776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4723914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4723975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4724055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48daf80b-e6cf-4f4e-b800-0e69d84ee384}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4724141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4724191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4724271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4724346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4724407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4724457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4724535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4724579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4724712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 30, Data: Common Desktop</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4724842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {DFDF76A2-C82A-4D63-906A-5644AC457385}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4724967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4725075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: Desktop</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4725197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4725305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4725410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21799</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4725535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4725640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Security</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 116, Data: D:P(A;OICI;FA;;;BA)(A;OICI;0x1200a9;;;IU)(A;OICI;FA;;;SY)</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4725765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4725873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4726014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4726119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4726225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4726344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4726449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4726707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4726879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4727067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4727192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4727333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4727399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4727491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4727591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4727640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4727729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4727807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4727868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4727920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4727995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4728039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4728172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 22, Data: CD Burning</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4728303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4728427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4728533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 56, Data: Microsoft\Windows\Burn\Burn</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4728660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4728768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4728907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21815</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4729029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4729134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4729239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4729342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4729447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\LocalRedirectOnly</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4729563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4729669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4729771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4729876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4729979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4730084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4730198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4730336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4730475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4730536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4730619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4730710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4730757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4730843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4730918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4730976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4731029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4731106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4731148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4731278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 38, Data: OneDriveCameraRoll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4731408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {339719B5-8C47-4894-94C2-D8F77ADD44A6}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4731533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4731638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: Camera Roll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4731760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4731866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4731971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4732073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4732176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4732278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4732381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4732483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4732586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4732688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4732794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4732899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4733002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\DefinitionFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 64</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4733118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4733237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\FolderTypeID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {b3690e58-e961-423b-b687-386ebfd83239}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4733362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4733500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4733561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4733642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4733741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4733788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4733871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4733944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4734002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4734054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4BD9-94B0-29233477B6C3}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4734126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4734171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4734298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 42, Data: SavedPicturesLibrary</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4734428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4734553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4734661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 50, Data: SavedPictures.library-ms</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4734786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4734894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 160, Data: ::{031E4825-7B94-4dc3-B131-E946B44C8DD5}\{E25B5812-BE88-4bd9-94B0-29233477B6C3}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4735021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4735132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-34583</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4735257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4735362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4735465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\StreamResource</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 74, Data: %SystemRoot%\system32\shell32.dll,-6</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4735586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\StreamResourceType</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: LIBRARY</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4735747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4735855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4735958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4736063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\Stream</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4736177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4736384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4736501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4736609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4736714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4736853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4736914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4737008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4737108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4737157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4737243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4737315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4737376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4737426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4737501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4737548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4737675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 22, Data: MAPIFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4737806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4737917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4738022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4738124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 98, Data: shell:::{89D83576-6BD1-4C86-9454-BEB04E94C819}\*</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4738252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4738357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4738460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4738562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4738665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4738767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4738872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4738975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4739077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4739180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4739282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4739382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4739487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4739590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4739692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4739825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4739886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4739969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4740061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4740111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4740191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4740266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4740324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4740374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4740449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4740493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4740626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 36, Data: Common Start Menu</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4740759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4740884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4740989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 58, Data: Microsoft\Windows\Start Menu</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4741114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4741222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4741324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21786</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4741449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4741554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4741657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4741762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4741865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4741967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4742070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4742189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4742291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4742397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4742499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4742615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4742718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4742854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4742912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4742998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4743084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4743131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4743217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4743289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4743350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4743399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4743471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4743516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4743646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 12, Data: Games</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4743779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4743887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4743992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4744098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: ::{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4744220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4744328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4744427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4744533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4744635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4744771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4744876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4744979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4745081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4745186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4745289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4745391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4745494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4745596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4745699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4745832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4745893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4745971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{CAC52C1A-B53D-4edc-92D7-6B2E8AC19434}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4746325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4746381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4746475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4746563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4746627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4746680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4746760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4746807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4746946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: My Video</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4747079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4747190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4747295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 14, Data: Videos</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4747420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4747528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{A0953C92-50DC-43BF-BE83-3742FED03C9C}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4747652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12690</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4747777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-21791</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4747904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-189</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4748057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4748165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4748270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4748373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4748478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Roamable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4748597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4748716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4748824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4748927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4749057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4749176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4749281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4749420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4749481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4749572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4749666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Hide</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4749799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Hide</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4750096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4750207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4750257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4750331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4750426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4750467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisablePersonalDirChange</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4750592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4750689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4750739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4750825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4750935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4750982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4751052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4751179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4751226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4751307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4751379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4751476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4751520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4751592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Write</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4751678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4751722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4751764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4751974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4752024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4752107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4752190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4752254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4752307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4752384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4752434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4752576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 26, Data: Quick Launch</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4752709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4752836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4752944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: Microsoft\Internet Explorer\Quick Launch</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4753066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4753174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4753279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4753382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4753484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4753587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4753689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4753792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4753894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4753997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4754102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4754205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4754310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4754412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4754515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4754617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4754756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4754814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4754900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52a4f021-7b75-48a9-9f6b-4b87a210bc8f}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4754989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4755039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4755119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4755191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4755252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4755302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4755377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4755421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4755551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 44, Data: ProgramFilesCommonX86</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4755681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4755889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4756005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4756111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4756213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4756319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4756421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4756521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4756623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4756726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4756828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4756931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4757033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4757136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4757261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4757363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4757468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4757571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4757673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4757809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4757870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4757953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4758042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4758089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4758172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4758244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4758305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4758355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4758430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4758471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4758604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 36, Data: OneDriveDocuments</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4758734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4758859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4758967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Documents</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4759092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4759197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4759300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4759405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4759510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4759616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4759718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4759821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4759926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4760028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4760134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4760239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4760341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\DefinitionFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 64</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4760461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4760580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\FolderTypeID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {DD61BD66-70E8-48dd-9655-65C5E1AAC2D1}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4760704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4760843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4760901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4760990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4761073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4761120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4761200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4761272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4761331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4761380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4761455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4761497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4761627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 22, Data: 3D Objects</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4761760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {5E6C858F-0E22-4760-9AFE-EA3317B67173}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4761885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4761990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 22, Data: 3D Objects</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4762112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4762217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4762322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-21825</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4762461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-198</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4762588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4762696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4762802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4762907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4763009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4763115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4763217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4763323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4763425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4763528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4763636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\FolderTypeID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {b3690e58-e961-423b-b687-386ebfd83239}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4763755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4763893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4763954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4764040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4764134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4764187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4764306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4764356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4764550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4764605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4764700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4764749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4764819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4764907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4764988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4765035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4765104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4765284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4765342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4765395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4765774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4765830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4765924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4766010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4766074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4766118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4766262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4766401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4766484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4766578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4766628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4766716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4766800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4766863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4766919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4766994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4767041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4767176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 36, Data: ConnectionsFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4767309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4767420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4767553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4767658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4767764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 168, Data: ::{26EE0668-A00A-44D7-9371-BEB064C98683}\0\::{7007ACC7-3202-11D1-AAD2-00805FC1270E}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4767891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4767999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4768102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4768204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4768310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4768415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4768517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4768623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4768722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4768825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4768927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4769033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4769138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4769240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4769343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4769479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4769542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4769623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4769717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4769767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4769850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4769925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4769983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4770144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4770221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4770266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4770399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 30, Data: PrintersFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4770529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4770637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4770742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4770845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4770978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 164, Data: ::{21EC2020-3AEA-1069-A2DD-08002B30309D}\::{2227A280-3AEA-1069-A2DE-08002B30309D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4771127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4771235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4771338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4771443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4771546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4771651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4771753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4771856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4771958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4772064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4772166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4772271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4772374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4772479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4772582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4772718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4772778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4772859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4772947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4772997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4773078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4773152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4773213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4773263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4773335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4773380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4773507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 28, Data: VideosLibrary</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4773640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4773768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4773873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 36, Data: Videos.library-ms</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4773998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4774108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 160, Data: ::{031E4825-7B94-4dc3-B131-E946B44C8DD5}\{491E922F-5643-4af4-A7EB-4E7A138D8174}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4774233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12690</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4774360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-34620</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4774488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 82, Data: %SystemRoot%\system32\imageres.dll,-1005</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4774613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4774721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\StreamResource</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 74, Data: %SystemRoot%\system32\shell32.dll,-4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4774845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\StreamResourceType</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: LIBRARY</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4774976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4775084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4775189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4775399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\Stream</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4775532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4775640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4775746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4775851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4775956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4776100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4776164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4776253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4776352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4776402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4776488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4776560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4776621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4776671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4776751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4776796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4776929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: My Pictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4777062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4777173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4777275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Pictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4777403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4777511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{3ADD1653-EB32-4CB0-BBD7-DFA0ABB5ACCA}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4777635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12688</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4777763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-21779</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4777890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-113</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4778015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4778123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4778225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4778331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4778461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Roamable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4778580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4778702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4778807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4778915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4779018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4779137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4779242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4779378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4779439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4779525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4779611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Hide</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4779738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Hide</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4779965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4780065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4780112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4780184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4780267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4780309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisablePersonalDirChange</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4780420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4780514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4780564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4780650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4780749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4780794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4780866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4780982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Write</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4781999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4782049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4782187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: ResourceDir</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4782320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4782431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4782534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4782636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4782739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4782841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4782944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4783046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4783149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4783251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4783354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4783456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4783559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4783661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4783764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4783866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4783969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4784071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4784171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4784307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4784368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4784448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4784537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4784584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4784664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4784739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4784800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4784850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4784925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4784966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4785213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 30, Data: Common Startup</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4785371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4785498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4785606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: StartUp</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4785734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4785842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4785944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21787</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4786069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4786177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4786279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4786385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4786487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4786592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4786695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4786839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4786947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4787052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4787158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4787277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4787382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4787521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4787584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4787673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4787781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4787831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4787914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4787989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4788050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4788100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4788177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4788222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4788352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: PublicGameTasks</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4788479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4788607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4788715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 62, Data: Microsoft\Windows\GameExplorer</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4788837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4788945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4789047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4789150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4789344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4789452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4789557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4789659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\LocalRedirectOnly</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4789779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4789881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4789986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4790092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4790194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4790297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4790399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4790502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4790638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4790701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4790779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DEBF2536-E1A8-4c59-B6A2-414586476AEA}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4790867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4790917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4790998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4791070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4791131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4791181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4791258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4791300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4791455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: SyncSetupFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4791582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4791690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4791796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4791898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4792003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 252, Data: ::{26EE0668-A00A-44D7-9371-BEB064C98683}\0\::{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\::{F1390A9A-A3F4-4E5D-9C5F-98F3BD8D935C},</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4792128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4792258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4792364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4792466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4792569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4792668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4792771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4792873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4792976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4793078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4793181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4793283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4793386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4793488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4793591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4793727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4793788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4793868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0F214138-B1D3-4a90-BBA9-27CBC0C5389A}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4793959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4794009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4794090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4794162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4794223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4794272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4794350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4794392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4794525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: CommonVideo</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4794652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {DFDF76A2-C82A-4D63-906A-5644AC457385}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4794779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4795015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 14, Data: Videos</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4795231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4795492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12690</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4795644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21804</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4795852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 76, Data: %SystemRoot%\system32\imageres.dll,-3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4795987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4796096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4796201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4796309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4796411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4796517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4796636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4796744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4796846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4796952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4797068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4797176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4797331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4797398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4797492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4797600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag\ThisPCPolicy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4797747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4797808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4797927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4797979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4798107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4798157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4798243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4798323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4798387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4798437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4798520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4798570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4798703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: History</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4798833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4798960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4799066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 52, Data: Microsoft\Windows\History</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4799190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4799298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4799404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4799506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4799609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4799714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4799816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4799919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\LocalRedirectOnly</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4800038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4800141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4800243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4800370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4800476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4800581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4800684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4800789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4800925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4800988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4801977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4802022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4802155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 36, Data: SyncResultsFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4802285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4802393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4802498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4802598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4802703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 252, Data: ::{26EE0668-A00A-44D7-9371-BEB064C98683}\0\::{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\::{BC48B32F-5910-47F5-8570-5074A8A5636A},</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4802831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4802939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4803041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4803144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4803246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4803352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4803454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4803557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4803659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4803759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4803864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4803967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4804069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4804172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4804274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4804407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4804468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4804554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4804787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4804873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4805008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4805108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4805183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4805236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4805316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4805366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4805504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 30, Data: ConflictFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4805635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4805745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4805848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4805950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4806056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 252, Data: ::{26EE0668-A00A-44D7-9371-BEB064C98683}\0\::{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\::{E413D040-6788-4C22-957E-175D1C513A34},</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4806183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4806288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4806391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4806496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4806599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4806701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4806804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4806906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4807009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4807139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4807241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4807344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4807446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4807549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4807652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4807787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4807848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4807926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4808026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4808075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4808159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4808231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4808292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4808341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4808413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4808458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4808588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: RecycleBinFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4808807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4808923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4809026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4809131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: ::{645FF040-5081-101B-9F08-00AA002F954E}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4809256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4809422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4809533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4809638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4809741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4809846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4809948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4810051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4810156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4810281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4810386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4810491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4810591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4810694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4810799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4810932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4810996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4811073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4811184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4811237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4811336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4811389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4811541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4811594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4811677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4811752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4811810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4811863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4811938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4811982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4812115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: CSCFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4812245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4812353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4812456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4812561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 98, Data: shell:::{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\*</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4812686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4812791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4812918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4813024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4813126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4813229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4813331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4813434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4813533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4813636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4813741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4813844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4813946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4814049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4814148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4814281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4814345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4814692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4814847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4814921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4815054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4815174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4815265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4815340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4815456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4815528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4815722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Ringtones</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4815935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4816143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4816318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 56, Data: Microsoft\Windows\Ringtones</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4816534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4816720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4816902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4817049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4817185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4817315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4817448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4817578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4817706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4817833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4817986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4818116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4818263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4818426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4818562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4818670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4818817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4818886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4818983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4819086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4819135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4819227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4819310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4819377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4819429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4819510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4819557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4819690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: Common Programs</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4819823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {A4115719-D62E-491D-AA7C-E74B8BE3B067}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4819950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4820058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Programs</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4820183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4820291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4820396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21782</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4820518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4820623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4820729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4820831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4820936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4821039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4821144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4821261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4821366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4821468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4821596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4821712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4821817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4821953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4822017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4822097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4822186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4822236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4822319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4822396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4822455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4822507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4822582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4822626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4822754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: NetHood</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4822881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4823006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4823111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 72, Data: Microsoft\Windows\Network Shortcuts</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4823250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4823358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4823463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4823568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4823671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4823773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4823879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4823981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4824084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4824328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4824497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4824663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4824826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4824965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4825076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4825181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4825322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4825389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4825480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4825580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4825627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4825716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4825796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4825860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4825910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4825984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4826029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4826167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Contacts</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4826300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4826411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4826516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Contacts</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4826641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4826752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 160, Data: ::{59031a47-3f72-44a7-89c5-5595fe6b30ee}\{56784854-C6CB-462B-8169-88E350ACB882}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4826879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 98, Data: @%CommonProgramFiles%\system\wab32res.dll,-10200</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4827007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 98, Data: @%CommonProgramFiles%\system\wab32res.dll,-10100</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4827131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-181</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4827256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4827389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4827494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4827600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4827705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Roamable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4827821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4827940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4828046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PublishExpandedPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4828162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4828267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4828386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\FolderTypeID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {de2b70ec-9bf7-4a93-bd3d-243f7881d492}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4828508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4828650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4828711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4828799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4828891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag\ThisPCPolicy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4829029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4829090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4829201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4829254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4829448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4829500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4829597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4829650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4829722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4829813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4829991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4830040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4830115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4830198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4830245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4830301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{56784854-C6CB-462B-8169-88E350ACB882}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4830561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4830614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4830708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4830794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4830855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4830899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4831043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4831176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4831259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4831356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4831406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4831495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4831578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4831642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4831694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4831769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4831819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4831949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 46, Data: UserProgramFilesCommon</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4832080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {5cd7aee2-2219-4a67-b85d-6c9ce15660cb}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4832207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4832315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 14, Data: Common</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4832437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4832570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4832675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4832778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4832880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4832986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4833088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4833193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4833296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4833398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4833504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4833606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4833709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4833811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4834024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4834207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4834423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4834515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4834612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcbd3057-ca5c-4622-b42d-bc56db0ae516}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4834714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4834764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4834850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4834930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4834994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4835044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4E48-96A1-3F6217F21990}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4835119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4835166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4835304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 28, Data: Roaming Tiles</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4835437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4835562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4835667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 62, Data: Microsoft\Windows\RoamingTiles</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4835789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4835895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4836025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4836127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4836230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4836335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4836440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4836546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4836651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4836753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4836873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4836978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\PublishExpandedPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4837094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4837200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4837305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4837407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4837549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4837610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4837693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{00BCFC5A-ED94-4e48-96A1-3F6217F21990}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4837806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Show</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4837937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Show</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4838072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag\BaseFolderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {33E28130-4E1E-4676-835A-98395C3BC3BB}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4838194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag\BaseFolderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {33E28130-4E1E-4676-835A-98395C3BC3BB}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4838513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4838621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4838671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4838746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4838829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4838873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisablePersonalDirChange</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4838989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4839086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4839136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4839225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4839325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4839372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4839444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4839566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4839613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4839693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4839765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4839857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4839904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4839973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Write</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4840970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4841112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 42, Data: UsersLibrariesFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4841245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4841355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4841461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4841566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: ::{031E4825-7B94-4dc3-B131-E946B44C8DD5}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4841688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4841793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4841898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4842001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4842103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4842209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4842311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4842414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4842516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4842619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4842721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4842824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4842929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4843032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4843134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4843270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4843331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4843417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4843508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4843558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4843638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4843838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4843913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4843971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4844054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4844104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4844234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: Cookies</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4844364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4844489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4844597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 60, Data: Microsoft\Windows\INetCookies</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4844722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4844827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4844929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4845035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4845137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4845242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4845345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4845472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4845578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4845683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4845786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4845894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4845996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4846101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4846204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4846306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4846442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4846506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4846586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4846678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4846725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4846805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4846877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4846935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4846988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4847063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4847104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4847232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 44, Data: LocalizedResourcesDir</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4847362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4847470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4847573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4847675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4847778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4847880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4847985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4848085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4848188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4848290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4848393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4848492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4848595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4848697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4848800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4848902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4849005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4849107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4849301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4849440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4849501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4849581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4849670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4849717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4849800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4849875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4849933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4849983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4850055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4850099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4850252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: CommonRingtones</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4850379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4850504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4850612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 56, Data: Microsoft\Windows\Ringtones</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4850736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4850842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4850947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4851050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4851152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4851255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4851360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4851462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4851565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4851670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4851789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4851892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4851994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4852097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4852199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4852302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4852435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4852496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4852579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4852662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4852709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4852792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4852864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4852922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4852975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4853047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4853091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4853244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: GameTasks</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4853374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4853598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4853712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 62, Data: Microsoft\Windows\GameExplorer</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4853837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4853942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4854047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4854150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4854252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4854355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4854457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4854560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\LocalRedirectOnly</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4854679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4854782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4854884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4854987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4855089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4855194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4855297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4855399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4855535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4855596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4855676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4855765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4855815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4855895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4855967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4856028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4856078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4856156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4856197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4856327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Favorites</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4856458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4856569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4856674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Favorites</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4856796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4856901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4857006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21796</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4857131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-115</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4857256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4857386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4857491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4857594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4857699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Roamable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4857815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4857934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4858037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PublishExpandedPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4858156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,4858261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5002849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5003200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5003425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5003527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5003677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5032377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5032482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5032710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5032776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5033106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5033164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5033289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5033344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5033441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5033593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5033693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5033743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5033823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5033929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5033984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5034048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Favorites</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Favorites</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5034441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5034815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Show</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5034990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Show</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5035153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag\BaseFolderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {18989B1D-99B5-455B-841C-AB7C74E4DDFC}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5035284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag\BaseFolderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {18989B1D-99B5-455B-841C-AB7C74E4DDFC}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5035566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5035680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5035732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5035810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5035907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5035951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisablePersonalDirChange</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5036079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5036184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5036234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5036331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5036461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5036508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5036580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5036843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5036971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5037087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5037192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5037309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5037359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5037431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Write</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5037514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5037566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5037608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5037691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5037747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5037857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5037910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5038032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5038079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5038157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5038248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5038320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5038373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5038456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5038550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5038597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5038672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5038733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5038791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5038841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5039049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5039118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5039345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: HomeGroupFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5039631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5039766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5039874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5040074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: ::{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5040204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5040315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5040420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 82, Data: %SystemRoot%\system32\imageres.dll,-1013</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5040545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5040653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5040761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5040866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5040971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5041074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5041179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5041285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5041387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5041495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5041600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5041706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5041922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5042215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5042490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5042612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5042667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5042756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5042844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5042908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5042961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5043044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5043091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5043227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 14, Data: SendTo</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5043360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5043490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5043598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 50, Data: Microsoft\Windows\SendTo</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5043723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5043831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5043933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5044036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5044141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5044244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5044349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5044451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5044557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5044662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5044767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5044870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5044975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5045077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5045263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5045366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5045507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5045568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5045648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5045740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5045789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5045873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5045947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5046008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5046061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482AF6C-08F1-4C34-8C90-E17EC98B1E17}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5046139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5046183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5046316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 44, Data: PublicAccountPictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5046449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {DFDF76A2-C82A-4D63-906A-5644AC457385}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5046576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5046684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: AccountPictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5046809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5046914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5047022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 106, Data: @C:\Windows\SysWOW64\Windows.UI.Immersive.dll,-38304</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5047147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5047255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5047358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5047463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5047571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5047676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5047779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5047898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5048003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5048108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5048211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5048333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5048438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5048577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5048638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5048721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0482af6c-08f1-4c34-8c90-e17ec98b1e17}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5048815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5048865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5048948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5049128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5049255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5049319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5049413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5049469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5049610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 42, Data: ImplicitAppShortcuts</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5049743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {9e3995ab-1f9c-4f13-b827-48b24b6c7174}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5049868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5049976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 42, Data: ImplicitAppShortcuts</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5050103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5050214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5050319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5050427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5050533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5050638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5050740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5050849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5050954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5051056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5051178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5051284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5051466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5051572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5051680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5051788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5051926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5051990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5052076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bcb5256f-79f6-4cee-b725-dc34e402fd46}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5052170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5052220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5052303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5052378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5052442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5052491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5052566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5052608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5052744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 42, Data: Administrative Tools</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5052874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {A77F5D77-2E2B-44C3-A6A2-ABA601054A51}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5052998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5053107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 42, Data: Administrative Tools</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5053228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5053337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5053442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21762</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5053566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5053672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5053777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5053882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5053990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5054093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5054195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5054312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5054417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5054522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5054625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5054741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5054846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5054985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5055046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5055126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5055218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5055268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5055348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5055423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5055481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5055531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5055614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5055658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5055788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: My Music</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5055924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5056038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5056143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 12, Data: Music</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5056268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5056434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{1CF1260C-4DD0-4EBB-811F-33C572699FDE}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5056564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12689</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5056689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-21790</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5056816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-108</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5056941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5057052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5057154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5057260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5057362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Roamable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5057481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5057600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5057706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5057811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5057916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5058035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5058141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5058276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5058337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5058426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5058515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Hide</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5058648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Hide</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5059030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5059182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5059238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5059315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5059410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5059454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisablePersonalDirChange</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5059584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5059681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5059734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5059822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5059925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5059972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Write</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5060950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5061022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5061083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5061136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5061210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5061260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5061399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 42, Data: AddNewProgramsFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5061535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5061643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5061748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5061850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5061997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 180, Data: shell:::{26EE0668-A00A-44D7-9371-BEB064C98683}\0\::{15eae92e-f17a-4431-9f28-805e482dafd4}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5062125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5062233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5062335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5062438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5062540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5062646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5062748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5062851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5062953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5063056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5063161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5063263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5063366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5063468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5063571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5063707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5063770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5063851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{de61d971-5ebc-4f02-a3a9-6c82895e5c04}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5063948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5063998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5064081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5064153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5064216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5064266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5064341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5064385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5064516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Captures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5064646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {18989B1D-99B5-455B-841C-AB7C74E4DDFC}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5064771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5064876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Captures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5065001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5065109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5065211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-21826</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5065333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5065441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5065577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5065682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5065785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5065887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5065990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5066092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5066195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5066300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5066400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5066502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5066605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5066740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5066801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5066882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{EDC0FE71-98D8-4F4A-B920-C8DC133CB165}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5066973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5067020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5067103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5067178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5067239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5067289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5067364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5067405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5067541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 26, Data: UserProfiles</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5067677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5067785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5067887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5067990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5068095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5068198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21813</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5068322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5068425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Security</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5068533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Security</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 144, Data: D:P(A;OICI;FA;;;SY)(A;OICI;FA;;;BA)(A;OICI;GXGR;;;BU)(A;OICI;GXGR;;;WD)</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5068766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5068877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5068982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5069087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5069190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5069309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5069414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5069517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5069622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5069738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5069841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5069979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5070040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5070126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5070229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5070278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5070362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5070436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5070497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5070547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5070622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5070666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5070794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 30, Data: InternetFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5070921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5071032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5071135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5071237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: ::{871C5380-42A0-1069-A2EA-08002B30309D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5071359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5071467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5071570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5071669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5071772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5071916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5072021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5072121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5072223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5072323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5072426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5072528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5072631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5072730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5072833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5072966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5073027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5073110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5073199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5073246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5073329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5073401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5073459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5073509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5073587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5073628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5073758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 36, Data: CameraRollLibrary</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5073889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5074013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5074118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 44, Data: CameraRoll.library-ms</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5074240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5074346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 160, Data: ::{031E4825-7B94-4dc3-B131-E946B44C8DD5}\{2B20DF75-1EDA-4039-8097-38798227D5B7}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5074468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5074576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-34582</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5074698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5074803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5074905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\StreamResource</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 74, Data: %SystemRoot%\system32\shell32.dll,-5</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5075027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\StreamResourceType</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: LIBRARY</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5075155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5075263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5075365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5075468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\Stream</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5075587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5075692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5075797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5075897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5076000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5076135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5076196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5076285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5076379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5076426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5076507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5076579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5076640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5076690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5076762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5076803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5076933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 14, Data: System</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5077061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5077197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5077302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5077404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5077504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5077607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5077709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5077812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5077914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5078017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5078119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5078219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5078418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5078585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5078693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5078795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5078900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5079003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5079105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5079241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5079308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5079407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5079496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5079546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5079629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5079701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5079759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5079812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5079890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5079931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5080061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Programs</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5080189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5080344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5080452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Programs</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5080574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5080682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5080784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21782</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5080906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5081012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5081111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5081217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5081319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5081422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5081524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5081641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5081746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5081848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5081951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5082067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5082170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5082303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5082366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5082450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5082538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5082585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5082666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5082740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5082801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5082851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5082921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5082965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5083092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: Camera Roll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5083223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {33E28130-4E1E-4676-835A-98395C3BC3BB}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5083347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5083452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: Camera Roll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5083574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5083680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5083782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-21824</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5083907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5084012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5084115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5084217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5084320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5084422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5084522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5084624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5084752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5084854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5084957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5085059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5085162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\InitFolderHandler</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {B26388EA-AD62-430f-AF5C-CFA63BFE94A6}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5085312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5085372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5085456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AB5FB87B-7CE2-4F83-915D-550846C9537B}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5085555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5085605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5085688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5085760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5085819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5085871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5085940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5085985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5086112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: MyComputerFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5086240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5086345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5086447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5086553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5086675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5086780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5086882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5086985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5087087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5087190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5087292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5087392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5087495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5087597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5087697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5087800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5087902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5088005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5088104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5088237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5088295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5088559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5088667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5088717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5088805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5088888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5088949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5089002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5089074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5089124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5089251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 56, Data: Common Administrative Tools</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5089384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5089509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5089614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 42, Data: Administrative Tools</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5089739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5089847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5089952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21762</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5090074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5090182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5090285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5090390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5090495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5090601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5090731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5090850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5090955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5091060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5091166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5091282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5091387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5091520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5091584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5091667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5091756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5091803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5091883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5091955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5092014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5092063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5092138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5092180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5092310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: DocumentsLibrary</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5092437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5092562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5092670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 42, Data: Documents.library-ms</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5092792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5092900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 160, Data: ::{031E4825-7B94-4dc3-B131-E946B44C8DD5}\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5093025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5093133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-34575</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5093258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 82, Data: %SystemRoot%\system32\imageres.dll,-1002</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5093379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5093487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\StreamResource</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 74, Data: %SystemRoot%\system32\shell32.dll,-1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5093609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\StreamResourceType</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: LIBRARY</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5093737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5093842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5093947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5094064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\Stream</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5094183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5094288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5094393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5094496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5094623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5094762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5094826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5094914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5095014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5095061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5095144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5095214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5095274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5095324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5095402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5095443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5095576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 44, Data: Application Shortcuts</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5095707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5095831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5095937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: Microsoft\Windows\Application Shortcuts</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5096059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5096164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5096266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-50704</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5096391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5096496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5096599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5096704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5096807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5096909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5097012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5097128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5097236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5097341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5097444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5097557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5097663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5097798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5097859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5097943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A3918781-E5F2-4890-B3D9-A7E54332328C}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5098031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5098078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5098159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5098231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5098292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5098341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5098411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5098580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5098713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 14, Data: Recent</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5098868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5098995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5099101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 50, Data: Microsoft\Windows\Recent</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5099225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5099331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 40, Data: @shell32,dll,-12692</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5099452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21797</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5099577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-117</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5099702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5099810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5099912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5100018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5100123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5100225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5100342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5100447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5100550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5100655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5100771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5100877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5101010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5101073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5101151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5101378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5101428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5101511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5101586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5101647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5101699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B7BEDE81-DF94-4682-A7D8-57A52620B86F}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5101771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5101813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5101946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: Screenshots</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5102073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {33E28130-4E1E-4676-835A-98395C3BC3BB}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5102198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5102303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: Screenshots</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5102425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5102531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5102633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-21823</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5102755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5102858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5102963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5103065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5103171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5103273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5103373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5103500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5103603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5103708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5103811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5103910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5104013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5104146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5104207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5104284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{b7bede81-df94-4682-a7d8-57a52620b86f}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5104373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5104420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5104503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5104575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5104636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5104686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4EAB-965A-69829D1FB59F}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5104761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5104802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5104933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 28, Data: SavedPictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5105063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {33E28130-4E1E-4676-835A-98395C3BC3BB}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5105185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5105290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 30, Data: Saved Pictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5105412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5105520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5105623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-34583</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5105747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5105850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5105955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5106063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5106166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5106268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5106371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5106470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5106576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5106678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5106781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5106883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5106983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5107116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5107180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5107254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3B193882-D3AD-4eab-965A-69829D1FB59F}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5107354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5107401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5107482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5107556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5107615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5107664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5107739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5107784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5107911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 28, Data: Local AppData</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5108038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5108241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5108435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 28, Data: AppData\Local</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5108629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5108784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5108895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5109000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5109102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5109205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5109310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5109413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\LocalRedirectOnly</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5109557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5109665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5109767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5109873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\PublishExpandedPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5109989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5110094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5110197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5110299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5110438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5110504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5110596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5110693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5110740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5110826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5110903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5110964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5111017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5111092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5111133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5111263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 40, Data: ThisPCDesktopFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5111394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5111504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5111607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: Desktop</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5111732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5111840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5111967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5112075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21769</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5112200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-183</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5112336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5112444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5112549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5112654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5112759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\Roamable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5112876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5112992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5113097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5113203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5113305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5113424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5113530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5113665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5113726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5113807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5113906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5113962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5114076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5114128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5114344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5114400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5114499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5114549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5114619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5114707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5114790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5114837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5114909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5114987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5115034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5115087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{754AC886-DF64-4CBA-86B5-F7FBF4FBCEF5}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5115367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5115419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5115513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5115599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5115666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5115707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5115860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5115990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5116073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5116173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5116223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5116309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5116392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5116455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5116508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5116588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5116633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5116763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 30, Data: CommonPictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5116918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {DFDF76A2-C82A-4D63-906A-5644AC457385}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5117043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5117151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Pictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5117275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5117381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12688</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5117505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21802</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5117627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 76, Data: %SystemRoot%\system32\imageres.dll,-3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5117968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5118079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5118184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5118290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5118398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5118500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5118619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5118725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5118830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5118932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5119051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5119157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5119295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5119356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5119445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5119542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5119594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5119680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5119752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5119813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5119863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1E87508D-89C2-42F0-8A7E-645A0F50CA58}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5119944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5119991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5120121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 22, Data: AppsFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5120251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5120362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5120464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5120567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 94, Data: shell:::{4234d49b-0245-4df3-b780-3893943456e1}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5121318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5152467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5152603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5152714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5152825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5152930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5153035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5153140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5153246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5153348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5153451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5153559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5153661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5153767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5153869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5154038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5154124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5154249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1e87508d-89c2-42f0-8a7e-645a0f50ca58}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5154398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5154451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5154559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5154659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5154725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5154781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5154869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5154919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5155060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: PrintHood</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5155193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5155326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5155434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 72, Data: Microsoft\Windows\Printer Shortcuts</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5155559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5155664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5155767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5155872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5155977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5156080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5156182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5156285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5156390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5156493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5156598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5156847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5156989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5157097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5157202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5157305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5157446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5157515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5157612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5157715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5157764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5157859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5157942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5158006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5158058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5158136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5158183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5158313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 36, Data: Development Files</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5158446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5158618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5158726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: DevelopmentFiles</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5158856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5158961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5159067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5159169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5159272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5159377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5159479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5159585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5159690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5159793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5159895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5160000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5160106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5160211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5160313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5160419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5160554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5160618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5160698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DBE8E08E-3053-4BBC-B183-2A7B2B191E59}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5160815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5160862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5160948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5161025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5161086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5161136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5161211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5161255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5161391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: PhotoAlbums</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5161521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {33E28130-4E1E-4676-835A-98395C3BC3BB}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5161649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5161757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: Slide Shows</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5161879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5161987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5162089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21819</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5162214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5162319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5162422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5162535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5162641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5162743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5162848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5162954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5163056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5163162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5163264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5163380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5163488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5163621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5163685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5163774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5163865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5163912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5163995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5164073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5164131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5164184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5164267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5164311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5164442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Downloads</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5164575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5164685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5164838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Downloads</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5164962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5165070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{374DE290-123F-4565-9164-39C4925E467B}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5165195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5165303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-21798</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5165428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-184</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5165553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5165661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5165763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5165868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5165974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Roamable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5166093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5166212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5166317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PublishExpandedPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5167877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5168027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5168151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5168259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5168406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5168478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5168584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5168686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Hide</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5168822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Hide</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5169096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5169218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5169268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5169345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5169445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5169489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisablePersonalDirChange</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5169614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5169717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5169769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5169858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5169969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Write</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5170952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5171027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5171099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5171160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5171213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5171282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5171401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Show</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5171540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Show</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5171673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag\BaseFolderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {4BD8D571-6D19-48D3-BE97-422220080E43}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5171792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag\BaseFolderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {4BD8D571-6D19-48D3-BE97-422220080E43}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5172025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5172124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5172171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5172243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5172324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5172363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisablePersonalDirChange</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5172515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5172604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5172653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5172737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5172834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5172878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5172947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Write</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5173906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5174044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5174089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5174163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5174233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5174294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5174344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5174418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5174468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5174615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: AppUpdatesFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5174751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5174864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5174970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5175072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5175180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 250, Data: ::{26EE0668-A00A-44D7-9371-BEB064C98683}\0\::{7b81be6a-ce2b-4676-a29e-eb907a5126c5}\::{d450a8a1-9568-45c7-9c0e-b4f9fb4537bd}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5175302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5175410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5175513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5175615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5175718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5175823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5175925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5176031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5176131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5176341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5176457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5176588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5176690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5176793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5176895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5177036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5177100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5177186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a305ce99-f527-492b-8b1a-7e76fa98d6e4}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5177286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5177333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5177419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5177494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5177557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5177607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5177685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5177729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5177862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: CommonDownloads</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5177990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {DFDF76A2-C82A-4D63-906A-5644AC457385}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5178114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5178220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Downloads</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5178344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5178449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5178552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21808</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5178674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5178779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5178882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5178984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5179089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5179192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5179297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5179414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5179519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5179621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5179727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5179843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5179946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5180081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5180145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5180228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4f30-9B45-F670235F79C0}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5180339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Show</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5180464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Show</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5180594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag\BaseFolderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {374DE290-123F-4565-9164-39C4925E467B}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5180713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag\BaseFolderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {374DE290-123F-4565-9164-39C4925E467B}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5180949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5181048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5181098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5181170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5181251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5181292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisablePersonalDirChange</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5181406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5181497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5181547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5181633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5181730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5181774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5181843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Write</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5182985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5183029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5183104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5183176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5183237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5183287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5183359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5183412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5183553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 28, Data: OneDriveMusic</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5183686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5183811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5183919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 12, Data: Music</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5184040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5184149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5184254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5184356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5184459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5184586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5184692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5184794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5184897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5184999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5185102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5185207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5185307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\DefinitionFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 64</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5185426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5185542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\FolderTypeID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {672ECD7E-AF04-4399-875C-0290845B6247}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5185664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5185803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5185863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5185947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5186110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5186160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5186243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5186451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5186528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5186587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5186675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5186725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5186858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 50, Data: Common Start Menu Places</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5186988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5187113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5187221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 72, Data: Microsoft\Windows\Start Menu Places</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5187343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5187448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5187554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21786</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5187675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5187786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5187889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5187991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5188097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5188199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5188302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5188418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5188523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5188629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5188731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5188847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5188950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5189088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5189149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5189230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A440879F-87A0-4F7D-B700-0207B966194A}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5189321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5189368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5189449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5189523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5189584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5189637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4E80-94BC-9912D7504104}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5189709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5189753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5189884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: PicturesLibrary</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5190011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5190138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5190244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 40, Data: Pictures.library-ms</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5190366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5190474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 160, Data: ::{031E4825-7B94-4dc3-B131-E946B44C8DD5}\{A990AE9F-A03B-4e80-94BC-9912D7504104}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5190629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12688</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5190756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-34595</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5190881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 82, Data: %SystemRoot%\system32\imageres.dll,-1003</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5191006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5191114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\StreamResource</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 74, Data: %SystemRoot%\system32\shell32.dll,-3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5191236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\StreamResourceType</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: LIBRARY</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5191360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5191468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5191574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5191690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\Stream</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5191806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5191912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5192017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5192119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5192225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5192360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5192421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5192510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5192607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5192654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5192737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5192809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5192870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5192920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5192995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5193039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5193169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 14, Data: Public</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5193300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5193410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5193519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5193785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Session Manager</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5193873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5193951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 24</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5194084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5194294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5194535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5194652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21816</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5194779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5194884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Security</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5195009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Security</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 384, Data: D:PAI(A;OICI;FA;;;BA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;SY)(A;OICIIO;0x1301ff;;;IU)(A;;0x1200af;;;IU)(A;OICIIO;0x1301ff;;;SU)(A;;0x1200af;;;SU)(A;OICIIO;0x1301ff;;;S-1-5-3)(A;;0x1200af;;;S-1-5-3)</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5195137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5195242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5195369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5195475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5195577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5195693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5195926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5196034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5196140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5196256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5196358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5196500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5196563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5196655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5196760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5196813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5196943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5197029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5197093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5197145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5197220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5197264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5197395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 36, Data: RecordedTVLibrary</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5197528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {48daf80b-e6cf-4f4e-b800-0e69d84ee384}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5197652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5197758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 44, Data: RecordedTV.library-ms</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5197882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5197987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5198090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-34615</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5198212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 82, Data: %SystemRoot%\system32\imageres.dll,-1008</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5198334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5198439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\StreamResource</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 74, Data: %SystemRoot%\system32\shell32.dll,-8</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5198561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\StreamResourceType</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: LIBRARY</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5198686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5198819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5198924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5199040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\Stream</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5199157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5199262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5199364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5199467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5199569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5199705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5199766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5199852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5199946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5199996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5200079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5200154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5200215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5200265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4F11-9E78-5F7800F2E772}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5200337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5200381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5200509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 54, Data: HomeGroupCurrentUserFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5200636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5200744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5200847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5200949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 110, Data: ::{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\$CurrentUser$</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5201074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5201179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5201282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5201384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5201487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5201589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5201692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5201794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5201894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5201994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5202096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5202199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5202301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5202404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5202503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5202639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5202700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5202789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5202878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5202927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5203008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5203080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5203141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5203191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5203263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5203304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5203434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: LocalAppDataLow</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5203565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5203673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5203775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: AppData\LocalLow</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5203897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5204002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5204133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5204235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5204338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\Security</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 40, Data: S:(ML;OICI;NW;;;LW)</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5204459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5204565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5204670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\LocalRedirectOnly</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5204784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5204889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5205005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5205108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\PublishExpandedPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5205227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5205332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 8192</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5205446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5205551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5205684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5205864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5206039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5206177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5206233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5206327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5206407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5206471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5206524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5206598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5206648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5206781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 38, Data: Roamed Tile Images</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5206917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5207042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5207147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 70, Data: Microsoft\Windows\RoamedTileImages</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5207269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5207374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5207477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5207576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5207679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5207781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5207884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5207984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5208083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5208183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5208286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5208388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5208488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5208590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5208690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5208793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5208926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5208987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5209064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5209156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5209205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5209289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5209363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5209424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5209474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5209549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5209591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5209718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 22, Data: CryptoKeys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5209851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5209956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5210059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5210159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5210261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5210364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5210463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5210563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5210666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5210765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5210871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5210970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5211070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5211170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5211308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5211411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5211513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5211613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5211716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5211849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5211910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5211990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B88F4DAA-E7BD-49a9-B74D-02885A5DC765}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5212076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5212123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5212206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5212278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5212339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5212389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5212458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5212502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5212633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: Original Images</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5212760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5212885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5212987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 96, Data: Microsoft\Windows Photo Gallery\Original Images</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5213112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5213217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5213317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5213419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5213522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5213625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5213724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5213827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5213927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5214029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5214129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5214231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5214334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5214434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5214533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5214666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5214802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5214863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5214938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2C36C0AA-5812-4b87-BFD0-4CD0DFB19B39}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5215029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5215079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5215159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5215234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5215295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5215345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5215417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5215459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5215705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: User Pinned</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5215844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {52a4f021-7b75-48a9-9f6b-4b87a210bc8f}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5215971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5216076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: User Pinned</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5216198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5216304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5216406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5216509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5216639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5216744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5216847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5216946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5217049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5217151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5217268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5217370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5217473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5217575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5217692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5217794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5217930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5217994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5218077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9e3995ab-1f9c-4f13-b827-48b24b6c7174}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5218168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5218218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5218298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5218373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5218434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5218484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DF7266AC-9274-4867-8D55-3BD661DE872D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5218556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5218600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5218728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 54, Data: ChangeRemoveProgramsFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5218855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5218963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5219066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5219166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5219271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 168, Data: ::{26EE0668-A00A-44D7-9371-BEB064C98683}\0\::{7b81be6a-ce2b-4676-a29e-eb907a5126c5}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5219396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5219498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5219601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5219703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5219803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5219903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5220005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5220105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5220207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5220307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5220410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5220509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5220609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5220712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5220811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5220944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5221005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5221080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{df7266ac-9274-4867-8d55-3bd661de872d}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5221172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5221219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5221302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5221374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5221432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5221485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5221557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5221601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5221728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: Common Documents</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5221886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {DFDF76A2-C82A-4D63-906A-5644AC457385}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5222011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5222116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Documents</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5222235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5222341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5222440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21801</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5222562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 76, Data: %SystemRoot%\system32\imageres.dll,-3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5222684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5222787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5222889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5222992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5223094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5223194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5223308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5223410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5223513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5223612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5223726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5223831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5223961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5224022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5224106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5224197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5224244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5224324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5224396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5224455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5224507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5224585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5224629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5224757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: SystemX86</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5224884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5224992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5225095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5225194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5225391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5225507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5225610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5225710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5225812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5225915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5226017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5226117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5226217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5226319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5226419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5226521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5226624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5226724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5226826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5226956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5227017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5227109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5227195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5227245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5227325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5227394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5227452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5227502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5227580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5227624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5227754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: AccountPictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5227885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5228009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5228115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: Microsoft\Windows\AccountPictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5228236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5228342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5228444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 106, Data: @C:\Windows\SysWOW64\Windows.UI.Immersive.dll,-38305</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5228566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5228671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5228774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5228876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5228979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5229079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\Roamable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5229195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5229336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5229442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5229544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5229647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5229760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5229863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5229996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5230057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5230151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5230240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5230287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5230370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5230442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5230503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5230553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5230625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5230669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5230796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: OneDrivePictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5230927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5231051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5231154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Pictures</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5231279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5231381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5231484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5231583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5231686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5231786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5231888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5231988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5232090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5232190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5232293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5232392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5232495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\DefinitionFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 64</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5232608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5232747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\FolderTypeID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {71D642A9-F2B1-42cd-AD92-EB9300C7CC0A}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5232872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5233007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5233068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5233151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5233240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5233287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5233368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5233437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5233498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5233548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5233622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5233664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5233791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: CommonMusic</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5233922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {DFDF76A2-C82A-4D63-906A-5644AC457385}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5234044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5234149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 12, Data: Music</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5234273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5234379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12689</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5234503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21803</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5234628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 76, Data: %SystemRoot%\system32\imageres.dll,-3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5234750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5235022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5295328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5295508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5295625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5295736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5295860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5295971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5296074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5296179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5296295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5296403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5296567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5296650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5296786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5296927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5296985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5297093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5297190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5297262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5297318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5297403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5297453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5297589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 40, Data: SearchHistoryFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5297722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5297847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5297955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 84, Data: Microsoft\Windows\ConnectedSearch\History</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5298080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5298188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5298287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5298390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5298490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5298592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5298697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5298797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5298900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5299002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5299105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5299318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5299434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5299537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5299639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5299742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5299927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5299997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5300088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5300188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5300241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5300329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5300418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5300482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5300534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5300609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5300656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5300786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 26, Data: ProgramFiles</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5300922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5301030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5301135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5301238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5301340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5301446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21781</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5301568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5301676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5301778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5301881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5301983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5302086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5302188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5302307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5302410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5302512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5302618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5302731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5302834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5302970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5303033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5303125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5303216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5303266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5303352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5303427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5303488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5303540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5303615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5303662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5303792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 12, Data: Fonts</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5303923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F38BF404-1D43-42F2-9305-67DE0B28FC23}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5304047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5304200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5304302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5304405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5304507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5304607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5304707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5304809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5304909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5305011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5305111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5305208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5305311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5305410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5305513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5305613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5305751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5305854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5305989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5306053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5306139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5306225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5306275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5306355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5306430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5306491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5306541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5306621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5306668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5306796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: Startup</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5306926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {A77F5D77-2E2B-44C3-A6A2-ABA601054A51}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5307051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5307156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: StartUp</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5307278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5307383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5307486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21787</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5307607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5307713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5307815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5307921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5308023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5308126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5308228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5308344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5308450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5308552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5308655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5308768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5308871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5309104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5309167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5309267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5309361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5309414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5309497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5309575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5309636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5309685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5309757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5309805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5309935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 30, Data: Recorded Calls</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5310065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {5E6C858F-0E22-4760-9AFE-EA3317B67173}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5310190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5310292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 30, Data: Recorded Calls</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5310420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5310522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5310625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-21827</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5310749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5310855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5310954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5311057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5311159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5311292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5311395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5311497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5311600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5311702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5311805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5311907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5312010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5312143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5312204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5312287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5312387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5312439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5312572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5312628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5312902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5312957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5313063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5313113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5313182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5313301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5313392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5313439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5313512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5313597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5313645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5313694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{2F8B40C2-83ED-48EE-B383-A1F157EC6F9A}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5314019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5314071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5314165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5314273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5314343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5314384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5314539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5314670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5314758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5314861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5314913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5314999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5315085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5315149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5315202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5315274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5315321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5315454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 22, Data: Start Menu</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5315584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5315709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5315811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 58, Data: Microsoft\Windows\Start Menu</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5315936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5316038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5316141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21786</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5316263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5316371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5316470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5316576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5316676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5316775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5316878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5316994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5317097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5317202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5317302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5317421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5317526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5317662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5317723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5317806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5317922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5317972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5318058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5318133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5318197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5318246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5318318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5318363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5318496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 40, Data: NetworkPlacesFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5318634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5318886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5319014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5319163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: ::{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5319302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5319410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5319513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5319615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5319715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5319817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5319923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5320025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5320125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5320227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5320327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5320430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5320532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5320662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5320765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5320903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5320967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5321059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5321156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5321205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5321291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5321372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5321433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5321482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5321557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5321599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5321732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Playlists</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5321859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {4BD8D571-6D19-48D3-BE97-422220080E43}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5321984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5322089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Playlists</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5322211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5322319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5322422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-21818</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5322544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5322646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5322749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5322848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5322951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5323051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5323156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5323258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5323358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5323461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5323563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5327342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5327506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5327661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5327736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5327849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5327957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5328010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5328110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5328309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5328431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5328497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5328592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5328647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5328824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: DpapiKeys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5328957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5329065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5329168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5329270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5329370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5329475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5329578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5329678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5329777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5329880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5329983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5330082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5330182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5330282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5330384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5330487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5330586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5330686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5330816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5330955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5331016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5331105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5331196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5331246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5331335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5331415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5331476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5331526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5331601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5331648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5331778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Personal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5331908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5332019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5332124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Documents</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5332246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5332357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5332487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5332592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 100, Data: @%SystemRoot%\system32\windows.storage.dll,-21770</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5332717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-112</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5332842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5332947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5333050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5333155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5333257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Roamable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5333374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5333493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5333598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5333703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5333806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5333922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5334028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5334166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5334227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5334313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5334421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Hide</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5334557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Hide</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5334817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5334925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5334975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5335047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5335144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5335186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisablePersonalDirChange</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5335305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5335407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5335457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5335546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5335654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5335701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5335770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5335903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5335948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Write</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5336992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5337128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: OEM Links</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5337264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5337388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5337493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: OEM Links</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5337615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5337723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5337826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5337926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5338028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5338131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5338355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5338469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5338571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5338701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5338807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5338906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5339009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5339112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5339214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5339317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5339455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5339519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5339599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5339796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5339846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5339934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5340012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5340076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5340128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337D1-B8CA-4121-A639-6D472D16972A}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5340203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5340250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5340383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: SearchHomeFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5340516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5340627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5340730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5340832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: ::{9343812e-1c37-4a49-a12e-4b2d810d956b}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5340954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5341056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5341159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5341259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5341361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5341466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5341569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5341669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5341768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5341871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5341973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5342076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5342179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5342278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5342378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5342517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5342577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5342663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{190337d1-b8ca-4121-a639-6d472d16972a}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5342782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Show</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5342913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag\ThisPCPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Show</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5343043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag\BaseFolderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {FDD39AD0-238F-46AF-ADB4-6C85480369C7}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5343165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag\BaseFolderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {FDD39AD0-238F-46AF-ADB4-6C85480369C7}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5343403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5343508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5343555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5343628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5343711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5343752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisablePersonalDirChange</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5343866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5343954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\fdeploy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Write</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5344963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5345002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5345077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5345129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5345232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5345282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5345451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5345495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5345572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5345644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5345708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5345758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5345836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5345886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5346024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: ThisDeviceFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5346154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5346265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5346368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5346470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: ::{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5346622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5346728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5346830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5346930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5347030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5347135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5347238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5347337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5347440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5347542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5347642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5347745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5347847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5348035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5348163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5348301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5348362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5348448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1C2AC1DC-4358-4B6C-9733-AF21156576F0}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5348540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5348590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5348673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5348750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5348811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5348861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5348936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5348980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5349113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 38, Data: SystemCertificates</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5349241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5349349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5349448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5349551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5349651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5349753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5349853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5349955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5350055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5350158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5350257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5350360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5350493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5350593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5350695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5350795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5350895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5350994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5351094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5351224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5351285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5351366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{54EED2E0-E7CA-4fdb-9148-0F4247291CFA}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5351452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5351501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5351582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5351657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5351715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5351767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5351839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5351881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5352008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 12, Data: Links</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5352139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5352247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5352352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 12, Data: Links</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5352474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5352582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 160, Data: ::{59031a47-3f72-44a7-89c5-5595fe6b30ee}\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5352709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5352815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21810</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5352939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-185</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5353064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5353197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5353302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5353408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5353507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\Roamable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5353626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5353743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5353848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\PublishExpandedPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5353967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5354073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5354189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5354294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5354430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5354491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5354574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{bfb9d5e0-c6a9-404c-b2b2-ae6db6af4968}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5354671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5354724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5354821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5354870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5355053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5355106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5355200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5355250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5355317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5355402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5355483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5355530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5355599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5355677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5355721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5355771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5356023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5356073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5356164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5356247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5356311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5356350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5356486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5356619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5356702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5356799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5356849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5356935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5357018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5357081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5357134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5357212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5357256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5357383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: UserProgramFiles</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5357514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5357638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5358530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Programs</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5358697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5358805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5358910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5359012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5359112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5359215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5359317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5359420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5359522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5359625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5359727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5359830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5359932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5360035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5360137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5360240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5360387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5360450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5360542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5cd7aee2-2219-4a67-b85d-6c9ce15660cb}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5360647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5360700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5360788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5360869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5360930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5360980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5361054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5361096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5361232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: Common Templates</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5361362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5361484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5361589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 56, Data: Microsoft\Windows\Templates</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5361736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5361841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5361941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5362043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5362143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5362246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5362345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5362445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5362545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5362645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5362744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5362844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5362947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5363046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5363146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5363249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5363387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5363448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5363531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5363620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5363670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5363750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5363828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5363886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5363938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5364013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5364055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5364185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 12, Data: Cache</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5364315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5364440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5364542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 56, Data: Microsoft\Windows\INetCache</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5364664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5364772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5364872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5364972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5365074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5365177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5365277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5365379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\LocalRedirectOnly</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5365496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5365598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5365701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5365800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5365900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5366003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5366102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5366205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5366343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5366404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5366490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5366573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5366623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5366704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5366776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5366837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5366886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5366958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5367003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5367136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Templates</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5367271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5367396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5367593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 56, Data: Microsoft\Windows\Templates</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5367806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5367961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5368072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5368175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5368277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5368405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5368510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5368612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5368715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5368812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5368914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5369017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5369117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5369216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5369319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5369419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5369560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5369624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5369712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5369807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5369859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5369945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5370023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5370084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5370136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5370211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5370253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5370386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 44, Data: Device Metadata Store</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5370516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5370638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5370743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 76, Data: Microsoft\Windows\DeviceMetadataStore</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5370865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5370970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5371073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5371175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5371278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5371380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5371483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5371585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5371685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5371787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5371887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5371987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5372089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5372220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5372319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5372422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5372552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5372616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5372693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5372785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5372832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5372915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5372987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5373045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5373098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5373173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5373214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5373347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 38, Data: ControlPanelFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5373478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5373613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5373719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5373818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 86, Data: ::{26EE0668-A00A-44D7-9371-BEB064C98683}\0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5373943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5374048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5374148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5374248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5374350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5374450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5374553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5374652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5374755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5374855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5374957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5375057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5375159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5375256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5375359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5375489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5375553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5470971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5471248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5471337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5471478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5471638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5471724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5471785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5471891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5471957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5472132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: ProgramFilesX86</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5472278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5472395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5472503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5472603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5472708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5472810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21817</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5472935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5473038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5473143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5473248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5473351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5473453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5473556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5473675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5473777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5473883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5473988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5474102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5474207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5474351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5474417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5474523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5474805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5474869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5474971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5475068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5475140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5475196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5475287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5475340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5475545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: SyncCenterFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5475678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5475786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5475891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5475994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5476107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 168, Data: ::{26EE0668-A00A-44D7-9371-BEB064C98683}\0\::{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5476238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5476343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5476445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5476548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5476653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5476756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5476858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5476964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5477063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5477163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5477266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5477368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5477471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5477576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5477676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5477814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5477881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5477969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5478069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5478116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5478205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5478282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5478346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5478396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5478473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5478518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5478651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 36, Data: CredentialManager</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5478781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5478886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5478989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5479091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5479194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5479296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5479399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5479499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5479598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5479753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5480344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5480485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5480587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5480690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5480851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5480953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5481056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5481155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5481258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5481399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5481463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5481557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{915221FB-9EFE-4bda-8FD7-F78DCA774F87}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5481649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5481701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5481787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5481865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5481928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5481978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5482056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5482097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5482233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 44, Data: SearchTemplatesFolder</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5482361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {F1B32785-6FBA-4FCF-9D55-7B8E7F157091}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5482488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5482593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 88, Data: Microsoft\Windows\ConnectedSearch\Templates</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5482715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5482820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5482923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5483023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5483125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5483225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5483327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5483427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5483530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5483632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5483732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5483832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5483934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5484037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5484136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5484239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5484375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5484436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5484513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5484707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5484779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5484876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5484968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5485040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5485092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5485181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5485234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5485367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 22, Data: SavedGames</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5485497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5485605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5485710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: Saved Games</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5485832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5485943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 160, Data: ::{59031a47-3f72-44a7-89c5-5595fe6b30ee}\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5486070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5486178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21814</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5486314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-186</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5486442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5486544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5486649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5486805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5486913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\Roamable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5487029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5487148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5487253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\PublishExpandedPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5487370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5487475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5487589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5487694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5487830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5487891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5487974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43b0-B5B4-2D72E54EAAA4}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5488087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5488140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5488278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5488334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AllowedEnumeration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5488605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5488661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5488769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5488822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5488891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5488996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5489082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5489129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5489204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5489295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5489340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5489389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5489705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5489758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5489852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5489957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5490029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5490071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5490223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5490359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5490445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5492227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Searches\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5492476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Searches\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 528, EndOfFile: 524, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5492589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Searches\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 524, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5493083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Searches\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:15, LastAccessTime: 19.07.2018 20:08:15, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5493182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Searches\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5495404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Contacts\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5495620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Contacts\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 416, EndOfFile: 412, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5495720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Contacts\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 412, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5496103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Contacts\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:14, LastAccessTime: 19.07.2018 20:08:14, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5496200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Contacts\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5497757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Favorites\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5497967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Favorites\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 408, EndOfFile: 402, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5498064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Favorites\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 402, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5498466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Favorites\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:14, LastAccessTime: 19.07.2018 20:08:14, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5498560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Favorites\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5500547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Links\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5500760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Links\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 504, EndOfFile: 504, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5500857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Links\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 504, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5501320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Links\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:16, LastAccessTime: 19.07.2018 20:08:16, LastWriteTime: 20.07.2018 19:29:34, ChangeTime: 20.07.2018 19:29:34, FileAttributes: HS</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5501416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Links\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5502863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Saved Games\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5503073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Saved Games\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 288, EndOfFile: 282, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5503170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Saved Games\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 282, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5503519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Saved Games\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:16, LastAccessTime: 19.07.2018 20:08:16, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5503616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Saved Games\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5504054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5504121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5504395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5504539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5504603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: DelegateFolders</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5504700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5504774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5504849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5504896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5504977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5505093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5505287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5505362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5505417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5505484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5505614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5505667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5505730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5505777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5505841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5505916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5505977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 1, Length: 288</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: {DFFACDC5-679F-4156-8947-C5C76BC0B67F}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 1, Length: 288</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5506971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\UsersFiles\NameSpace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\UsersFiles\NameSpace\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5507922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5508010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5508163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5508276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5508321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5508387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5508490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5508562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5508700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5508770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5508875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5508958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5509069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5509135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5509235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5509313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5509421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5509487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5509584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5509662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1080</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5509806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5509897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5509950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5510027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5510135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5510183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5510266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5510371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5510418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5510482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5510570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5510615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5510687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5510759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5510828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5510875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5511016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5513324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5513488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:06:01, LastAccessTime: 20.07.2018 19:30:20, LastWriteTime: 20.07.2018 19:30:20, ChangeTime: 20.07.2018 19:30:20, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5513568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5514707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5514776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5514876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5515006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5515081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5515139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5515239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5515291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Data</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5515485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Data</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 370, Data: D6 0D 00 00 0D F0 AD BA 41 00 00 00 08 00 00 00</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5515641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5515718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5515771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5515857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5515948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5516009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5516064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5516139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5516181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5516317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5516896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 10668</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5517078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5517137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5517220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5517317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5517383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5517439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5517516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5517566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5517707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5517982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5518214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryRemoteProtocolInformation</Operation>
<Path>C:\</Path>
<Result>INVALID PARAMETER</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5518314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail>Filter: Users, 1: Users</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5518494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5519533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5519741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 176, EndOfFile: 174, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5519838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 174, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5520143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:47:50, LastAccessTime: 16.07.2016 14:45:35, LastWriteTime: 16.07.2016 14:45:35, ChangeTime: 19.07.2018 19:43:16, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5520234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5521500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5521694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryRemoteProtocolInformation</Operation>
<Path>C:\Users</Path>
<Result>INVALID PARAMETER</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5521780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>Filter: User, 1: User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5521927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5524127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5524221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5524304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5524359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5524479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F324E4F9-8496-40B2-A1FF-9617C1C9AFFE}\Instance</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5524612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F324E4F9-8496-40B2-A1FF-9617C1C9AFFE}\Instance</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5525734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5525792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5525881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Rpc</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5525977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5526050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5526113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc\MaxRpcSize</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5526285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5526548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5526634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5526734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5526778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName\ComputerName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: WIN-0UOTFKKVN1S</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5526925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5527000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\Setup</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5527069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SYSTEM\Setup</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5527111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SYSTEM\Setup\OOBEInProgress</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5527249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SYSTEM\Setup</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5527318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\Setup</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5527377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SYSTEM\Setup</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5527418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SYSTEM\Setup\SystemSetupInProgress</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5527540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SYSTEM\Setup</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5527656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5527720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5528119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5528172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5528255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\Rpc</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5528327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Rpc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5528743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5528795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5528867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Rpc</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5528934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5528989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5529036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc\IdleTimerWindow</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5529175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5531990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5532062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5532178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5532256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x100</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5532322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Notify, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5533322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5533447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5533652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5533705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5533804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KindMap</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5533899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5533959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5534009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: program</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5534198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5534245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5534309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5534378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5534428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5534505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5534608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5534683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5534727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5534791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5534885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5534951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\.exe\Content Type</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 50, Data: application/x-msdownload</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5535104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5535433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5535503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5535575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5535622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5535699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5535791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5535863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5535918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5535976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\.exe\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: exefile</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\CurVer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\CurVer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5536949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5537002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5537076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5537146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5537195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5537276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5537323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5537376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5537450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5537506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\IsShortcut</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5537733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5537794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5537888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5537955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\NoStaticDefaultVerb</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\shell</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\shell\(Default)</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5538983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5539041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5539113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5539165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\shell\open\NeverDefault</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5539296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile\shell</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5539775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\bf4c9654-66d1-5720-7b51-d2ae226735ea</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5540470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5540537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5540637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5540725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5540775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5540850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5540903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5540977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5541047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5541096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5541202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5541761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\e305fb0f-da8e-52b5-a918-7a4f17a2531a</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5542177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5542227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5542315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5542390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5542493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5542540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5542612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Explorer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5545640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5545950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:41, LastAccessTime: 20.07.2018 1:33:41, LastWriteTime: 03.06.2017 12:28:56, ChangeTime: 20.07.2018 19:25:40, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5546042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5547042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5547330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5547496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5548438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5548638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5548937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5549796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5549968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5550685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5551275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x627d0000, Image Size: 0x3d000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5551979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5553896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5554179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5554262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5554331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5554999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5555066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5555179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5555265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5555370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5555417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5555495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Explorer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5555900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5555961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5556080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5556132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5556221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5556312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5556407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5556454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5556528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5556625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5556678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5556731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Start Menu</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 118, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5557127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5557304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5557368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5557462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5557515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5557584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5557645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5557695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5557784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5557892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5557939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Start Menu</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 86, Data: %ProgramData%\Microsoft\Windows\Start Menu</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5558249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5558404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5558465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5558557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5558609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5558676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5558759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5558842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5558892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5558961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5559039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5559083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5559141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Recent</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 110, Data: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5559487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5559745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5559809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5559900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5559953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5560019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5560102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5560183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5560227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5560296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5560371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5560416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5560460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Personal</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 48, Data: %USERPROFILE%\Documents</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5560706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5561033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Rpc\Extensions</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5561117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc\Extensions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5561205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc\Extensions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5561252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 24, Data: combase.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5561394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc\Extensions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5561804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5561873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5561945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x100</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5562000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5562072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5562142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5562189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5627521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5627740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Properties</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5628089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5628311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5628413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Properties</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5628638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5629882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5630081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5630151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx\AllowDevelopmentWithoutDevLicense</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 65535</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5630441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5630514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5630663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5630713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock\AllowDevelopmentWithoutDevLicense</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 24</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5630838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5632974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5633079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5633162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5633220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5633320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AppID\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5633459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AppID\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5633572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5633647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5633700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AppID\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5633772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AppID\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5633860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5633905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5633982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\OLE\AppCompat</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5634071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\AppCompat</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5634168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\AppCompat</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5634218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\AppCompat\RaiseDefaultAuthnLevel</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5634367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\AppCompat</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5634437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5634489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5634572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5634647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5634705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5634755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\DefaultAccessPermission</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5637681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rpcss.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5638368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5639839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5639945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5640033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\AnonymousAppContainerImpersonationLevelCheck</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 80</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5640144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5640205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5640266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5640321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\EveryoneIncludesAnonymous</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5640413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5644837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5644932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5645009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5645064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5645175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5645317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5645441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5645491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5645552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5645727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5645821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5645879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5645973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5646037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5646123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5646195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {00000320-0000-0000-C000-000000000046}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5646286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5646336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5646497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5646580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5646646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x100</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5646702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5646771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5646843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5646890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5649229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 10168</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5698065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 9824</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5699065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 13060</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5700057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5700152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5700293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\PropertySystem\SystemPropertyHandlers</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5700484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\PropertySystem\SystemPropertyHandlers</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5700551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\PropertySystem\SystemPropertyHandlers\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5700753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\PropertySystem\SystemPropertyHandlers</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5700850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5700902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5701002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5701118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5701166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\.exe\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {66742402-F9B9-11D1-A202-0000F81FEDEE}</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5701249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5701329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5701401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5701468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5701512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5701612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}\OverrideFileSystemProperties</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5701789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}\OverrideFileSystemProperties</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5701922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5701980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5702044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5702091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5702177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5702271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5702346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5702390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5702454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5702562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5702631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}\DisableProcessIsolation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5702786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5702853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5702953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5703030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}\NoOplock</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5703163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5703227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5703296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5703343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5703418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\ExplorerCLSIDFlags\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5703521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\ExplorerCLSIDFlags\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5703623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5703684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5703770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5703845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}\UseInProcHandlerCache</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5703958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5704025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5704119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5704197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}\UseOutOfProcHandlerCache</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5704330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5704759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5704828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5704903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5704950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5705044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F324E4F9-8496-40B2-A1FF-9617C1C9AFFE}\Instance</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5705161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F324E4F9-8496-40B2-A1FF-9617C1C9AFFE}\Instance</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5705704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5705770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5705862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5705931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\AppUserModelID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5706064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5706128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5706219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\Application</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5706305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5706358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\Application</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5707236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004F006E00650043006F00720065002D00440065007600690063006500460061006D0069006C007900490044000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5707577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5707635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5707729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5707812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5707923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5708001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5708192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5708244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5708327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5708441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5708488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5708643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5708693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5708771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5709073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5709148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5709328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5709383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5709474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5709580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5709643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5711674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Free Space Query, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5711949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySizeInformationVolume</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail>TotalAllocationUnits: 12 978 687, AvailableAllocationUnits: 3 547 468, SectorsPerAllocationUnit: 8, BytesPerSector: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5712048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5712425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5712486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5712575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Internet Explorer\Main</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5712686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5712744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FrameTabWindow</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5712927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5712979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5713071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5713173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5713226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FrameTabWindow</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5713428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FrameMerging</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5713553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FrameMerging</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5713780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\SessionMerging</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5713902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\SessionMerging</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5714049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\AdminTabProcs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5714165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\AdminTabProcs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5714495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5714547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5714628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Internet Explorer\Security</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5714727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Security</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5714775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Security\RunBinaryControlHostProcessInSeparateAppContainer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5714924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5714977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5715065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Security</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5715160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Security</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5715210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Security\RunBinaryControlHostProcessInSeparateAppContainer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5715370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Security\RunBinaryControlHostProcessInDungeonAppContainer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5715586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Security\RunBinaryControlHostProcessInDungeonAppContainer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5715830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5715883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5715966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Internet Explorer\Main</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5716041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer\Main</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5716212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5716260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5716332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Internet Explorer\Main</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5716459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\TabProcGrowth</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5716589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\TabProcGrowth</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5716828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\TabProcGrowth</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5716947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\TabProcGrowth</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5717107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5717229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5717346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5717465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5717803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5717853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5717944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5718016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5718096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5718144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5718279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5718351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5718401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5718484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5718551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5718634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5718681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5718748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5718831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5719036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5719177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5719296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5719371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5719418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5719487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5719573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5719662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5719717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5719803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5719859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5720316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5720374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5720454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5720507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5720776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5720831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_URI_DISABLECACHE</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5720909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5720961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_URI_DISABLECACHE</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5721485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5721568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5721679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5721759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\shell\open\NoSmartScreen</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5722172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5722244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5722316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5722363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5722460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5722588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5722690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5722734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5722798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5722898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5722984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: Security Manager</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: Security Manager</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5723973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\urlmon.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\urlmon.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5724987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5725064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5725125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Both</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5725286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5725339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5725408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5725505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5725602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5725655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5725721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5725774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5725857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5725932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5725984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5726067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5726247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5726311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5726378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5726425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5726505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5726599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5726677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5726718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5726777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5726865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5726943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5726996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5727065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5727320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5727370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5727450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5727516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5727591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5727638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5727777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5727926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5727990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5728087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5728140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5728256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5728306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5728389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5728456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5728555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5728602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5728852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5728974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5729024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5729101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5729168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5729256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5729301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5729364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\ZoneMap\Ranges\</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5729445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5729492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5729558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\ZoneMap\Ranges\</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5729639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5729683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5729741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\ZoneMap\Ranges\</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5729954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004F006E00650043006F00720065002D00440065007600690063006500460061006D0069006C007900490044000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Policies</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5730952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 1, Values: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5731924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5732021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5732068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5732132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5732201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5732240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 2, Values: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5732298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5732359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5732404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5732470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5732570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5732617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5732695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCreateKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read/Write, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5732888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5733955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5734185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5734241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5734324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5734376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5734623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5734678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5734756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5734808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5734900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5735074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5735216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5735304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5735357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5735440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Internet Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5735507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5735587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5735634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5735703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Internet Explorer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5735789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5735836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5735903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Security</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5735980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Security</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5736022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5736147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Security</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5736219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5736269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5736349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Security</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5736426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Security</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5736465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5736579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Security</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5739538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5739602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5739682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\Setup</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5739773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SYSTEM\Setup</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5739820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SYSTEM\Setup\SystemSetupInProgress</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5739989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SYSTEM\Setup</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5740940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5741976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5742051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5742098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5742164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5742242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5742286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5742358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5742411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5742486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5742533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5742597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5742663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5742754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5742979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5743976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 33</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5744982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5745071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5745115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5745181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5745262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5745306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5745378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5745431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5745506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5745553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5745616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5745683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5745724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 219</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5745985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5746035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5746110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read/Write</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5746198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5746298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5746711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5746980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5747226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5747473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5747525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5747564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5747617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail>Index: 2, Name: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5747719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5747772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5747852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5748110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5748199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5748251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5748340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5748409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5748503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5748550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5748617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5748700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5748747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5748819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5748872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5748963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 71</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail>Index: 3, Name: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5749991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5750972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail>Index: 4, Name: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5751964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 5, Length: 288</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5752956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5753950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5754036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5754078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5754280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5754327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5754391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5754471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5754538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5754582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5754657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5754712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5754817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5754876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5754945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 33</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5755984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5756965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5757034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5757075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 219</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5757242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5757294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5757366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read/Write</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5757450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5757510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5758045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5758400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5758768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5759267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5759353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5759428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5759508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones</Path>
<Result>SUCCESS</Result>
<Detail>Index: 2, Name: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5759666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5759752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5759885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5760032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5760140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5760217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5760350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5760456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5760594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5760672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5760782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5760913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5760985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5761107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5761193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5761314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5761395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5761506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5761622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5761691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 71</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5761905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5761982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5762062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones</Path>
<Result>SUCCESS</Result>
<Detail>Index: 3, Name: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5762204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5762287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5762406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5762547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5762647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5762725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5762852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5762946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5763077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5763151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5763259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5763387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5763462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5763581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5763667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5763794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5763869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5763974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5764093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5764157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5764365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5764442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5764520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones</Path>
<Result>SUCCESS</Result>
<Detail>Index: 4, Name: 4</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5764661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5764742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5764861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5764999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5765099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5765177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5765301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5765401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5765528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5765603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5765717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5765839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5765914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5766035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5766119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5766238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5766313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5766418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5766526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5766592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 3</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5766922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5767005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5767080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 5, Length: 288</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5767160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5768274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5768382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5768559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5768648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5769075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5769294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5769482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5769684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5770233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5770302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5770430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5770485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5770568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5770676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5770776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5770826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5770895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5770986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5771034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5771086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cache</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 112, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCache</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5771480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5774322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\INetCache</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5774555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\INetCache</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:06:02, LastAccessTime: 23.08.2018 15:25:53, LastWriteTime: 23.08.2018 15:25:53, ChangeTime: 23.08.2018 15:25:53, FileAttributes: HSDNCI</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5774649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\INetCache</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5775018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5775092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5775203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5775259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5775345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5775442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5775533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5775580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5775658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5775741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5775791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5775840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cookies</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 116, Data: %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCookies</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5776220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5778855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\INetCookies</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5779049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\INetCookies</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:06:02, LastAccessTime: 20.07.2018 2:51:59, LastWriteTime: 20.07.2018 2:51:59, ChangeTime: 20.07.2018 2:51:59, FileAttributes: HSDNCI</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5779129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\INetCookies</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5781886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5782058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:11, LastWriteTime: 24.08.2018 12:38:31, ChangeTime: 24.08.2018 12:38:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5782132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5782423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5782615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail>Filter: Users, 1: Users</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5782811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5783742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5783939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>Filter: User, 1: User</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5784169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5785083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5785269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail>Filter: AppData, 1: AppData</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5785429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5786477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5786668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData\Roaming</Path>
<Result>SUCCESS</Result>
<Detail>Filter: Roaming, 1: Roaming</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5786809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5789882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5790031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:11, LastWriteTime: 24.08.2018 12:38:31, ChangeTime: 24.08.2018 12:38:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5790106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5792314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5792461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5792533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5794578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5794719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:06:02, LastAccessTime: 24.08.2018 12:31:43, LastWriteTime: 24.08.2018 12:31:43, ChangeTime: 24.08.2018 12:31:43, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5794791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5796864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5797141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:06:02, LastAccessTime: 19.07.2018 20:06:03, LastWriteTime: 19.07.2018 20:06:03, ChangeTime: 19.07.2018 20:06:03, FileAttributes: HD</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5797221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5799318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5799451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:06:01, LastAccessTime: 20.07.2018 19:30:20, LastWriteTime: 20.07.2018 19:30:20, ChangeTime: 20.07.2018 19:30:20, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5799523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5801632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5801770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 9:04:24, LastAccessTime: 24.08.2018 12:33:31, LastWriteTime: 24.08.2018 12:33:31, ChangeTime: 24.08.2018 12:33:31, FileAttributes: RD</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5801839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5802837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 12152</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5805638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5805840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Label</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5805920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Information: Label</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5806031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5808575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5808722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:11, LastWriteTime: 24.08.2018 12:38:31, ChangeTime: 24.08.2018 12:38:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5808796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5810960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5811096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:11, LastWriteTime: 24.08.2018 12:38:31, ChangeTime: 24.08.2018 12:38:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5811165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5813337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe:Zone.Identifier</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5813817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5813905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5814047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5814107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5814216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5814396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5814545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5814667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5814725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5814822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5814933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5814983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5815138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5815188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5815288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5815421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5815465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5815626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5815673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5815817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5815897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5816014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\command</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5816124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5816177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5816257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5816313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5816390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\command</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5816565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\shell\open\command\DelegateExecute</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5816878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5816967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5817064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5817191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\DropTarget</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5817288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5817341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\shell\open\DropTarget</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5818712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Safer\CodeIdentifiers</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5818804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5818912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5818964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5819119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5819183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5819252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5819358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\command</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5819449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5819502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5819574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5819629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5819707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\command</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5819765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\shell\open\command\command</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5819895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5819948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5820009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5820103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\command</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5820186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5820236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5820300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5820355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5820430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\command</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5820488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\shell\open\command\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: &quot;%1&quot; %*</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5820555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5820771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5820832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5820898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5820945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5821034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5821183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5821300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5821341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5821408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5821499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5821582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5821635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5821704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5821782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5821837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5821920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5821987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 76, Data: ShellItemArray Shell Namespace helper</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 76, Data: ShellItemArray Shell Namespace helper</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5822987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5823940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5824004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Both</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5824154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5824201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5824270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5824370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5824467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5824522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5824586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5824638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5824719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5824799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5824852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5824927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5825118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5825179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5825242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5825292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5825373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5825467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4D4E-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5825544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5825589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5825644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5825733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5825813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5825866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5825932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5826791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5826877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5826988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5827093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5827146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5827218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5827312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5827362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5827426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5827509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5827559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5827714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5827761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5827844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5827910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5827996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5828082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5828132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5828199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5828282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5828329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5828390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5828467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5828514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5828575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5828614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5829210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5829276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5829346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5829390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5829465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5829556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5829631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5829689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5829747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5829828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5829894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\.exe\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: exefile</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5829986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\CurVer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\CurVer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5830958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\Progid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\Progid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\ShellCompatibility\ProgIDs\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5831928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5832000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5832066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5832111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\InheritConsoleHandles</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5832255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5832324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5832374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5832451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5832546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5832587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\InheritConsoleHandles</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5832706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5832759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5832825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5832922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\ddeexec</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5833008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5833061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\shell\open\ddeexec</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5833446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5833499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5833582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5833657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5833720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5833767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5833898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5833967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5834948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5835022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5835100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5835142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5835252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5835391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5835444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5835516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\App Paths\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5835637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5835682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5835895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\MCLauncher.exe</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5835984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5836205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5836280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5836380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5836449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\shell\open\SetWorkingDirectoryFromTarget</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5836577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5836638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5836729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5836790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\shell\open\NoWorkingDirectory</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5899025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5899122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5899247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5899432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5899518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5899582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5899696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5899773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}\Data</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5899923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}\Data</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 370, Data: D6 0D 00 00 0D F0 AD BA 01 00 00 00 08 00 00 00</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5900075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5900153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5900203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5900289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5900383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5900446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5900499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5900574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5900618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5900757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5901596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5901654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5901740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5901840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5901904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5901956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5902040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5902087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Data</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5902211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Data</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 370, Data: D6 0D 00 00 0D F0 AD BA 41 00 00 00 08 00 00 00</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5902350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5902419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5902469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5902547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5902632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5902693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5902746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5902815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5902857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5902987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5903957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5904012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5904098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5904195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5904256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5904311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5904561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5904627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}\Data</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5904805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}\Data</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 3 542, Data: D6 0D 00 00 00 00 00 00 01 00 00 00 10 00 00 00</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5904951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5905023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5905076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5905154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5905240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5905300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5905353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5905422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5905464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5905594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5907462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5907522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5907611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5907711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5907777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5907833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5907913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5907957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5908099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5911130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5911343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5911437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5912529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5913263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5919561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 048 576, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5924589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 097 152, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5929762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 145 728, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,5935630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 194 304, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6024138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 5 242 880, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6029036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 291 456, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6033832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 7 340 032, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6190037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 388 608, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6195317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 9 437 184, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6200157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 10 485 760, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6205909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 11 534 336, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6210447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 582 912, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6962466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 13 631 488, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6968182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 14 680 064, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6972869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 15 728 640, Length: 1 048 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6976914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 064, Length: 4 096, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6977505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>SetEndOfFileInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>EndOfFile: 17 240 149</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6977917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6978297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6978502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6979876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6980114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6980433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6981336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6981511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6982309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6985093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6985331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6985589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Information: Label</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6985852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner, Group, DACL, SACL, Label, Process Trust Label</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6985941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6988867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6989014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6989274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6989512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6990532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6990731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6991086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6991360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6992236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6992407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6992709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6993543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6993710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6993978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6994289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6995275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:31,6995444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,5310663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Process Create</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>PID: 6080, Command line: &quot;C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe&quot; </Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,5310719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Process Start</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Parent PID: 84, Command line: &quot;C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe&quot; , Current directory: C:\Users\User\AppData\Roaming\MCLauncher\, Environment: 
	=::=::\
	=C:=C:\Users\User\AppData\Roaming\MCLauncher
	ALLUSERSPROFILE=C:\ProgramData
	APPDATA=C:\Users\User\AppData\Roaming
	CommonProgramFiles=C:\Program Files (x86)\Common Files
	CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files
	CommonProgramW6432=C:\Program Files\Common Files
	COMPUTERNAME=WIN-0UOTFKKVN1S
	ComSpec=C:\Windows\system32\cmd.exe
	FPS_BROWSER_APP_PROFILE_STRING=Internet Explorer
	FPS_BROWSER_USER_PROFILE_STRING=Default
	HOMEDRIVE=C:
	HOMEPATH=\Users\User
	LOCALAPPDATA=C:\Users\User\AppData\Local
	LOGONSERVER=\\WIN-0UOTFKKVN1S
	NUMBER_OF_PROCESSORS=1
	OneDrive=C:\Users\User\OneDrive
	OS=Windows_NT
	Path=C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Users\User\AppData\Local\Microsoft\WindowsApps;
	PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
	PROCESSOR_ARCHITECTURE=x86
	PROCESSOR_ARCHITEW6432=AMD64
	PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
	PROCESSOR_LEVEL=6
	PROCESSOR_REVISION=9e0a
	ProgramData=C:\ProgramData
	ProgramFiles=C:\Program Files (x86)
	ProgramFiles(x86)=C:\Program Files (x86)
	ProgramW6432=C:\Program Files
	PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules
	PUBLIC=C:\Users\Public
	SESSIONNAME=Console
	SystemDrive=C:
	SystemRoot=C:\Windows
	TEMP=C:\Users\User\AppData\Local\Temp
	TMP=C:\Users\User\AppData\Local\Temp
	USERDOMAIN=WIN-0UOTFKKVN1S
	USERDOMAIN_ROAMINGPROFILE=WIN-0UOTFKKVN1S
	USERNAME=User
	USERPROFILE=C:\Users\User
	windir=C:\Windows
	__COMPAT_LAYER=ElevateCreateProcess</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,7039150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 12028</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7039723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7039903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7040089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\SafeBoot\Option</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value, Set Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7040150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\SafeBoot\Option</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value, Set Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7040255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Safer\CodeIdentifiers</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7040349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7040482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7040540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 80</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7040726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\AuthenticodeEnabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7040898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7041042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7041560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7041665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7041715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 112, Data: C:\Users\User\AppData\Local\Microsoft\Windows\INetCache</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7041915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7042020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows NT\CurrentVersion</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7042117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7042197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7042264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7042352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7042402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 16</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7042538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7042859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner, Group, DACL, SACL, Label, Process Trust Label</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7044544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7044921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:29, LastAccessTime: 20.07.2018 1:33:29, LastWriteTime: 18.09.2017 4:09:15, ChangeTime: 20.07.2018 19:23:27, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7045034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7046120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\apppatch64\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7046392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\AppPatch\apppatch64\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:21:40, LastAccessTime: 20.07.2018 1:21:40, LastWriteTime: 18.09.2017 4:15:39, ChangeTime: 20.07.2018 19:23:27, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7046489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\apppatch64\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7046733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:11, LastWriteTime: 24.08.2018 12:38:31, ChangeTime: 24.08.2018 12:38:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7047115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:11, LastWriteTime: 24.08.2018 12:38:31, ChangeTime: 24.08.2018 12:38:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7047289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7048835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7049090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 866 624, EndOfFile: 3 863 594, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7049182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 866 624, EndOfFile: 3 863 594, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7049284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7049464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7050434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7050631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7050947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7051825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7051999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7052290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 866 624, EndOfFile: 3 863 594, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7052562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7053598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7054077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7054266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7054365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7054465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7054546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7054834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7054947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7055089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7056072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7056269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7056590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7057674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7057887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7058192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7058355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7071898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7072166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\{82cd83da-d86b-4add-9ee3-92bcc3d5d6c0}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7072305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7072410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7072515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\{82cd83da-d86b-4add-9ee3-92bcc3d5d6c0}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7072601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7072975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 299 008, Length: 32 768, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7493109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 363 392, Length: 32 768, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7619729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7620009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\{82cd83da-d86b-4add-9ee3-92bcc3d5d6c0}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7620180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7620322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7620452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\{82cd83da-d86b-4add-9ee3-92bcc3d5d6c0}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7620538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7621812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7623126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7623308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7623369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7623547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7708941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004F006E00650043006F00720065002D00440065007600690063006500460061006D0069006C007900490044000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7710146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7710517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 866 624, EndOfFile: 3 863 594, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7710617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 866 624, EndOfFile: 3 863 594, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7710720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7710894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7711875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7712077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7712393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7713260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7713432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7714302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 866 624, EndOfFile: 3 863 594, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7714460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7714837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7715837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7716128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7716230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7716322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7716385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7716679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Applications\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7716879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Applications\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7718020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7718098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7718172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7718222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7718305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Applications\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7718405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Applications\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7718521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7718588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7718693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7718776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\AppUserModelID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7718934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7718998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7719095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\Application</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7719181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7719234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\Application</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7719308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7719369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7719447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7719508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\shell\open\FriendlyAppName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7719638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7719696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7719788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\Application</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7719868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7719918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\Application</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7719984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\command</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\command</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\shell\open\command\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: &quot;%1&quot; %*</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7720976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Applications\%1.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7721059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Applications\%1.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7721234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7721289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7721370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\command</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7721442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7721494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7721558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7721611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7721685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\command</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7721741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\shell\open\command\DelegateExecute</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7721885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7721938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7721999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\DropTarget</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\shell\open\DropTarget</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\command</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\shell\open\command</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\shell\open\command\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: &quot;%1&quot; %*</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile\shell\open\command</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7722996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7723068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\App Paths\%1.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7723204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7723251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7723328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\%1.exe</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7723425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\%1.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7723511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7723564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7723641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\Progid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7723714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7723763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\Progid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7724035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7724301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7724365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7724428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7724475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7724564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7724719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7724838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7724885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7724944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: ShellItem Shell Namespace helper</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: ShellItem Shell Namespace helper</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7725927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7726010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7726091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7726141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7726373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7726440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7726537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7726620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7726744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7726811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7726911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7726991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Both</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7727972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7728038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7728138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7728238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7728290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7728357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7728412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7728493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7728570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7728623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7728701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7728897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7728958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7729025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7729072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7729155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7729246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7729327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7729371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7729429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7729515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7729595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7729645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7729715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7730019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7730066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7730113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile\shell\open</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,7806606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x400000, Image Size: 0x2b3000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,7807116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x7ffad0270000, Image Size: 0x1d2000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,7807387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77d20000, Image Size: 0x183000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,7808775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\Prefetch\MCLAUNCHER.EXE-A65AC714.pf</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,7809279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\Prefetch\MCLAUNCHER.EXE-A65AC714.pf</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 16 384, EndOfFile: 15 519, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,7809437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\Prefetch\MCLAUNCHER.EXE-A65AC714.pf</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 15 519, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,7809695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\Prefetch\MCLAUNCHER.EXE-A65AC714.pf</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 15 519, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7810382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7821567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,7821983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 553 984, Length: 24 576, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,7963946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\Prefetch\MCLAUNCHER.EXE-A65AC714.pf</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8021214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 408, Length: 32 768, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8071266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 12152, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8071951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 13060, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8072300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 9824, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8072624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 10168, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8072926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 10668, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8073106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 12960, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8484953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8485030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Policies</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8485083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8485127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8485324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8485374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8485424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8485476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8485523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8485571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8485615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Security</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8485659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Security</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8485717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8485767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8488327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 13 312, Length: 32 768, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8683042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 107 520, Length: 32 768, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,8996853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 103 424, Length: 4 096, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9057808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 136 192, Length: 32 768, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9276164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\GRE_Initialize</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9276408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9276505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9276574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9276787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9277311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 2340, User Time: 0.2656250, Kernel Time: 0.3281250</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9281262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9281375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\Segment Heap</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9284528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9285523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\wow64.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x5c020000, Image Size: 0x52000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9286235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x5c080000, Image Size: 0x77000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9289983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\System32\wow64log.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9291022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x750000, Image Size: 0xac000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9291654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x755e0000, Image Size: 0xe0000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9292155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x750000, Image Size: 0xac000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9292604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\user32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x750000, Image Size: 0x165000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9293674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9293956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9294184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9294474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Wow64\x86</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9294605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Wow64\x86\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 520</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9294749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Wow64\x86\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 26, Data: wow64cpu.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9294835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Wow64\x86</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9295328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x5c100000, Image Size: 0xa000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9297065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9297165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\Segment Heap</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9299758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9300572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x755e0000, Image Size: 0xe0000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9301509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x751e0000, Image Size: 0x1a1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9305485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\05f95efe-7f75-49c7-a994-60a55cc09571</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9306978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\SafeBoot\Option</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value, Set Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9307219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\SafeBoot\Option</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value, Set Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9307333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Srp\GP\DLL</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9307391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Srp\GP\DLL</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9307491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Safer\CodeIdentifiers</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9307565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9307682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9307734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 80</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9307906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9308072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9310799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9311065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:45, LastAccessTime: 16.07.2016 14:42:45, LastWriteTime: 16.07.2016 14:42:45, ChangeTime: 19.07.2018 19:32:46, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9311156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9312145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9312436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9312605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9313511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9313702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9314018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9314855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9315021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9315298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9316113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9316273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9316963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9317462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74730000, Image Size: 0x92000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9318559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9318997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\8ccca27d-f1d8-4dda-b5dd-339aee937731</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9319717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9319864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9319933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LogFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9320108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9320745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9320847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9320900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\ShowDebugInfo</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9321036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9321219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Session Manager</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9321291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9321360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9321404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 24</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9321543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9322862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9323058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9323139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9323211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9324241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9324516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9324590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9324654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9325640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9325898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9325970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9326034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9327004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9327192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9327261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9327322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9328328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9328624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 866 624, EndOfFile: 3 863 594, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9328710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 866 624, EndOfFile: 3 863 594, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9328799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9328915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9329893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9330073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9330348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9331179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9331348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9331907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 866 624, EndOfFile: 3 863 594, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9332057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9333933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9334213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9334351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9334409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 112, Data: C:\Users\User\AppData\Local\Microsoft\Windows\INetCache</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9334609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9334739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner, Group, DACL, SACL, Label, Process Trust Label</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9335653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9335916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:29, LastAccessTime: 20.07.2018 1:33:29, LastWriteTime: 18.09.2017 4:09:15, ChangeTime: 20.07.2018 19:23:27, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9336019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9337019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\apppatch64\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9337274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\AppPatch\apppatch64\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:21:40, LastAccessTime: 20.07.2018 1:21:40, LastWriteTime: 18.09.2017 4:15:39, ChangeTime: 20.07.2018 19:23:27, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9337368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\apppatch64\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9337595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:11, LastWriteTime: 24.08.2018 12:38:31, ChangeTime: 24.08.2018 12:38:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9337861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9338945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9339233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9339346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9339402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 112, Data: C:\Users\User\AppData\Local\Microsoft\Windows\INetCache</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9339585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9339715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner, Group, DACL, SACL, Label, Process Trust Label</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9339817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:11, LastWriteTime: 24.08.2018 12:38:31, ChangeTime: 24.08.2018 12:38:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9340017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9341740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\sysmain.sdb</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9344331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9344583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:29, LastAccessTime: 20.07.2018 1:33:29, LastWriteTime: 04.03.2017 9:24:10, ChangeTime: 20.07.2018 19:24:49, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9344660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9345561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9345830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9345951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9346808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9346988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9347267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9348099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9348265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9349121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9349562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x6b830000, Image Size: 0x277000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9350362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74da0000, Image Size: 0xbe000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9351257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77560000, Image Size: 0x15f000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9352041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x774d0000, Image Size: 0x15000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9352931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77bb0000, Image Size: 0x2b000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9353720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74c30000, Image Size: 0x15a000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9354665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x75ce0000, Image Size: 0x13d9000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9355632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77cd0000, Image Size: 0x36000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9356607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x756c0000, Image Size: 0x56e000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9357408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74910000, Image Size: 0x212000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9358136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74830000, Image Size: 0xe0000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9359203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74b60000, Image Size: 0xc1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9360034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x747e0000, Image Size: 0x1f000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9360685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x747d0000, Image Size: 0xa000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9361361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x776c0000, Image Size: 0x5a000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9362062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x75390000, Image Size: 0x41000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9363162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x75040000, Image Size: 0x45000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9363985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x75560000, Image Size: 0x77000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9364960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x75c90000, Image Size: 0x46000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9365891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74b30000, Image Size: 0xd000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9366695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74e60000, Image Size: 0x88000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9367584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x774f0000, Image Size: 0xf000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9368545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77800000, Image Size: 0x94000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9369244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77780000, Image Size: 0x7b000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9370252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x770c0000, Image Size: 0x40b000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9370934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9383634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9383919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:06, LastAccessTime: 20.07.2018 1:34:06, LastWriteTime: 08.08.2017 8:16:23, ChangeTime: 20.07.2018 19:25:15, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9384011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9385005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9385288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9385457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9386440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9386626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9386911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9388122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9388322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9389042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9389543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74710000, Image Size: 0x16000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9390086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9393137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9393395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:45, LastAccessTime: 16.07.2016 14:42:45, LastWriteTime: 16.07.2016 14:42:45, ChangeTime: 19.07.2018 19:38:51, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9393475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9394442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9394711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9394830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9395683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9395863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9396140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9396971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9397135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9397913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9398434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x66680000, Image Size: 0x3000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9398675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9401080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9401329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:35:14, LastAccessTime: 20.07.2018 1:35:14, LastWriteTime: 13.02.2018 0:51:43, ChangeTime: 20.07.2018 19:23:48, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9401407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9402360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9402623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9402737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9403571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9403748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9404020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9404842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9405009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9405635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9406131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x700d0000, Image Size: 0x6a000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9406754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9409926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9410179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:32, LastAccessTime: 20.07.2018 1:33:32, LastWriteTime: 09.12.2016 13:00:58, ChangeTime: 20.07.2018 19:44:33, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9410256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9411218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9411486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9411603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9412439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9412617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9412894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9413714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9413877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9414515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9415027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74190000, Image Size: 0x1b000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9415459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9418039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9418288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:45, LastAccessTime: 16.07.2016 14:42:45, LastWriteTime: 16.07.2016 14:42:45, ChangeTime: 19.07.2018 19:38:51, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9418366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9419330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9419596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9419709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9420546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9420721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9420998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9421820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9421981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9422613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9423112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x67690000, Image Size: 0xf000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9423563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9427813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9428068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:29, LastAccessTime: 20.07.2018 1:33:29, LastWriteTime: 04.03.2017 9:24:10, ChangeTime: 20.07.2018 19:24:49, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9428151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9430329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9430553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:29, LastAccessTime: 20.07.2018 1:33:29, LastWriteTime: 04.03.2017 9:24:10, ChangeTime: 20.07.2018 19:24:49, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9430628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9431603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\570069006E0064006F00770073004500780063006C007500640065006400500072006F00630073000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9431714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\570069006E0064006F00770073004500780063006C007500640065006400500072006F00630073000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9431775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004E0075006D006200650072002D0041006C006C006F007700650064000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9431833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004E0075006D006200650072002D0041006C006C006F007700650064000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9431894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004C0061006E00670075006100670065002D0041006C006C006F007700650064000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9431947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004C0061006E00670075006100670065002D0041006C006C006F007700650064000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9432094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9432191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9432293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9432343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\EMPTY</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 120</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9432520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004C0061006E00670075006100670065002D0044006900730061006C006C006F007700650064000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9432587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004C0061006E00670075006100670065002D0044006900730061006C006C006F007700650064000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9432645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\EMPTY</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 120</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9432770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004C0061006E00670075006100670065002D0053004B0055000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9432836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79}\{59AEE675-B203-4D61-9A1F-04518A20F359}\4B00650072006E0065006C002D004D00550049002D004C0061006E00670075006100670065002D0053004B0055000000</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9433282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\NLS\Language</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9433352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\NLS\Language</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9433429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Language</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9433476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Language\InstallLanguageFallback</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9433662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Language</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9433753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9433817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9433889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9433939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: en-US</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9434044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9434108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9434188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US\Type</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 273</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9434449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US\AlternateCodePage</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9434576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9434623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: ru-RU</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9434712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9434773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9434850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU\Type</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 146</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9435064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU\DefaultFallback</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 12, Data: en-US</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9435188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU\en-US</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_MULTI_SZ, Length: 4, Data: </Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9435321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: DefaultFallback, Type: REG_SZ, Length: 12, Data: en-US</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9435380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: en-US, Type: REG_MULTI_SZ, Length: 4, Data: </Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9435429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>SUCCESS</Result>
<Detail>Index: 2, Name: LCID, Type: REG_DWORD, Length: 4, Data: 1049</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9435477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>SUCCESS</Result>
<Detail>Index: 3, Name: Type, Type: REG_DWORD, Length: 4, Data: 146</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9435524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 4, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9435568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU\AlternateCodePage</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9435707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\ru-RU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9435754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 2, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9435798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9435887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\PendingDelete</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9435953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\UILanguages\PendingDelete</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9436061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9436139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9436261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9436371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9436424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9436654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9436793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9436848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9436926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9436970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9437956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9438979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9439062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9439112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9439175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\MuiCached</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9439253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\MuiCached</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9439294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9439408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_MULTI_SZ, Length: 12, Data: ru-RU</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9439544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\MuiCached</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9439588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9439691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9439757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9439840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9439923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9439973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9440996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9441043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9441104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9441170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9441212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9441259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9441298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9443425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9443730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9443819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9443888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9445096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9445373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9445448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9445514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9446650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9446844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9446913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9446977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9448188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9448446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9448518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9448579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9449609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9449867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9449936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9449997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9451238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9451499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9451568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9451629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9452712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9452964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9453036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9453100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9454111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9454300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9454366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9454430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9455474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9455657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9455724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9455785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9456935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9457198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9457267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9457328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9458361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9458611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9458680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9458738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9459727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9459974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9460043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9460104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9461140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9461384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9461453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9461514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9462584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9462836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9462908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9462969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9463963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9464216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9464285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9464346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9465437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9465687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9465900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9465983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9467116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9467305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9467371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9467432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9468452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9468698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9468768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9468829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9469834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9470084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9470150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9470211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9471197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9471380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9471447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9471508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9472655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9472904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9472973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9473034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9474281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9474467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9474533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9474597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9475788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9476079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9476151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9476215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9477268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9477512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9477584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9477642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9478634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9478883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9478952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9479013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9480063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9480296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9480365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9480426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9481376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9481615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9481684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9481745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9482723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9482961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9483030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9483091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9484108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9484347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9484416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9484477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9485269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9485366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9485457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9485516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: 0006020E</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9490179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9490442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:49, LastAccessTime: 16.07.2016 14:42:49, LastWriteTime: 16.07.2016 14:42:49, ChangeTime: 20.07.2018 19:26:58, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9490530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9491558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9491846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9491974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9492835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9493016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9493298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9494121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9494287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9495226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 147 456, EndOfFile: 144 632, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9495429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9496011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9496759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74800000, Image Size: 0x25000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9498640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9498928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9499014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9499089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9501607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9501845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:49, LastAccessTime: 16.07.2016 14:42:49, LastWriteTime: 16.07.2016 14:42:49, ChangeTime: 20.07.2018 19:26:58, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9501926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9504472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9504912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:49, LastAccessTime: 16.07.2016 14:42:49, LastWriteTime: 16.07.2016 14:42:49, ChangeTime: 20.07.2018 19:26:58, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9504998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9505417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\f25bcd2e-2690-55dc-3bc4-07b65b1b41c9</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9505885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\GRE_Initialize</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9506026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9506106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9506170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9506353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9507852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Compatibility32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9507993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Compatibility32\MCLauncher</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 172</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9508107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Compatibility32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9508190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\IME Compatibility</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9511922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9512091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9512168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9512279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9512398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9512479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9512720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9521015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9521153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9521237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9521342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9521411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9522830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9522904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9522990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9523043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9523229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9523292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9523362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9523409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9523536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\MDMEnabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9523705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9523758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9523835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9523902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9525071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9525135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9525229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9525318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9525381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9525434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\PageAllocatorUseSystemHeap</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9525597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9525667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9525719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9525802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9525869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9525924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9525969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\PageAllocatorSystemHeapIsPrivate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9526093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9526157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9526210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9526287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9526354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9526406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9526445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\AggressiveMTATesting</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9526562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9526927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9526980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9527066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\OLE\Tracing</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9527135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\Tracing</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9527551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\1aff6089-e863-4d36-bdfd-3581f07440be</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9530343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\30336ed4-e327-447c-9de0-51b652c86108</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9530670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\b87cf16b-0bf8-4492-a510-d5f59626b033</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9531925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\30336ed4-e327-447c-9de0-51b652c86108</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9532164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\b87cf16b-0bf8-4492-a510-d5f59626b033</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9535932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9536228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:33, LastAccessTime: 20.07.2018 1:33:33, LastWriteTime: 22.03.2018 6:29:36, ChangeTime: 20.07.2018 19:26:57, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9536319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9537317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9537611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9537771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9538683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9538874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9539170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9540029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9540204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9540819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 966 656, EndOfFile: 962 760, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9540977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9541478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9541880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9541946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9542057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\OLEAUT</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9542478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9542534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9542617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\system\CurrentControlSet\control\NetworkProvider\HwOrder</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9542703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\control\NetworkProvider\HwOrder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9542794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\NetworkProvider\HwOrder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9543467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9543523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9543750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Setup</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9543855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9543925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9543983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\SourcePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9544149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9544648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\f3a71a4b-6118-4257-8ccb-39a33ba059d4</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9545432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\c69cb70a-3133-4cca-ab0e-046848effcda</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9547537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9555420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\System32\wow64.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\System32\wow64.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9555583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\System32\wow64win.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\System32\wow64win.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9555683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\System32\wow64cpu.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\System32\wow64cpu.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9555819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\edputil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\edputil.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9555918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\sfc.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\sfc.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9556010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\sfc_os.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\sfc_os.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9556104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\AppPatch\AcLayers.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\AppPatch\AcLayers.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9556243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\winspool.drv</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\winspool.drv</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9556340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\netutils.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9556431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\wkscli.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9556522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\netapi32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9556617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\iertutil.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9556711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\propsys.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9556802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\urlmon.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9556894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\secur32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9556985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9557076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\uxtheme.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9557168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\bcrypt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\bcrypt.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9557257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\cryptsp.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9557348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\winmmbase.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9557442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\winmm.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9557534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\version.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9557625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\mpr.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\mpr.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9557716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\apphelp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\apphelp.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9557802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\cryptbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\cryptbase.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9557888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\sspicli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\sspicli.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9557974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\imm32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9558063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ucrtbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\ucrtbase.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9558146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\combase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\combase.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9558229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\kernel.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\kernel.appcore.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9558315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\rpcrt4.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\rpcrt4.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9558401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32full.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\gdi32full.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9558492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\psapi.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9558575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\msvcrt.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\msvcrt.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9558658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\SHCore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\SHCore.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9558744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\clbcatq.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9558827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\ws2_32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9558913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\powrprof.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\powrprof.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9558999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\msasn1.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9559085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\KernelBase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\KernelBase.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9559171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\sechost.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\sechost.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9559251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\crypt32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9559334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\advapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\advapi32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9559418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\kernel32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\kernel32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9559503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9559587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\shlwapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\shlwapi.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9559672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\shell32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\shell32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9559756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\setupapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\setupapi.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9559842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\win32u.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\win32u.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9559927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\profapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\profapi.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9560011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\user32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\user32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9560091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\bcryptprimitives.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\bcryptprimitives.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9560174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\msvcp_win.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\msvcp_win.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9560260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\oleaut32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9560343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\ole32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9560426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\gdi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\gdi32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9560506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\comdlg32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9560592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\cfgmgr32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\cfgmgr32.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9560681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ntdll.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\SysWOW64\ntdll.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9560772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Windows\System32\ntdll.dll</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Windows\System32\ntdll.dll</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9561094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>Process Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Exit Status: 0, User Time: 0.2656250 seconds, Kernel Time: 0.3281250 seconds, Private Bytes: 81 195 008, Peak Private Bytes: 98 897 920, Working Set: 90 238 976, Peak Working Set: 104 038 400</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9561620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9562681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9562886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9563512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\Downloads\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9564435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:32,9564612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9566336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe.Local</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9567497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9567979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 3432</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9570383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9570566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:08, LastAccessTime: 16.07.2016 14:43:08, LastWriteTime: 16.07.2016 14:43:08, ChangeTime: 19.07.2018 19:37:26, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9570652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9571614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9571810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9572018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9572993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9573209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9573503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9574351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9574523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9575224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9575672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x613d0000, Image Size: 0xa3000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9576099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9577127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9577216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9577324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 544</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9577468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9581466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9581632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:08, LastAccessTime: 16.07.2016 14:43:08, LastWriteTime: 16.07.2016 14:43:08, ChangeTime: 19.07.2018 19:37:26, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9581718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcr90.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9582012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9582192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail>Filter: Windows, 1: Windows</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9582374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9583483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9583699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Windows\WinSxS</Path>
<Result>SUCCESS</Result>
<Detail>Filter: WinSxS, 1: WinSxS</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9583876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9584979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9585167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\MSVCR90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MSVCR90.dll, 1: msvcr90.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9585317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9667672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9680702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9680812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9680965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\PythonPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9681198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9681344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9681394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9681472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\PythonPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9682250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Session Manager</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9682342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9682439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9682491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 24</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9682699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9693335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\zlib.pyd</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9694444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9694690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9694829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9694989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9695865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9696056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9696375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9697217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9697394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9697724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9697865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9698001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9699572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9699641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9699907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\linecache</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9700087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9700140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9700234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\linecache</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9702035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9702254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9705077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9705390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:47, LastAccessTime: 20.07.2018 1:33:47, LastWriteTime: 30.03.2018 6:12:25, ChangeTime: 20.07.2018 19:25:55, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9705476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9706479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9706773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9706911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9707778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9707961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9708252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9709097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:32,9709266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0211829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0212220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0213818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0214068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0214215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0215157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0215351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0215655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0216517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0216694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0217501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 45 056, EndOfFile: 41 984, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0217664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0218262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0221014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0221288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:47, LastAccessTime: 20.07.2018 1:33:47, LastWriteTime: 30.03.2018 6:12:25, ChangeTime: 20.07.2018 19:25:55, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0221385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0222440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0222740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0222875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0223779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0223973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0224305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0225214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0225399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0226098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0226336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\tzres.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0227619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0227846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0227968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0228824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0229001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0229281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0230118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0230287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0230857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 45 056, EndOfFile: 41 984, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0231007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0231412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\tzres.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0231744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0232999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0233265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0233448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 127, Length: 22, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0233700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 394, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0233794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 404, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0233866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 436, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0233977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 450, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 460, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 492, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 508, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 518, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 550, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 566, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 576, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 608, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 626, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 636, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 668, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 683, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 693, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0234925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 725, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 745, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 755, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 787, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 804, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 814, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 846, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 870, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 880, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 912, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 931, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 941, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 973, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 984, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 994, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0235961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 026, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0236033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 040, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0236094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 050, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0236160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 082, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0236232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 096, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0236293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 106, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0236362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 138, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0236432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 149, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0236731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 159, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0236897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 191, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0237033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 207, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0237127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 217, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0237221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 249, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0237324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 260, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0237418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 270, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0237523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 302, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0237631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 316, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0237695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 326, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0237764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 358, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0237836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 377, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0237900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 387, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0237969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 419, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 437, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 447, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 479, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 491, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 501, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 533, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 549, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 559, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 591, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 614, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 624, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 656, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 678, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0238934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 688, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 720, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 743, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 753, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 785, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 800, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 810, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 842, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 853, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 863, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 895, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 921, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 931, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 963, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 986, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0239959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 223 996, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 028, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 052, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 062, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 094, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 115, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 125, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 157, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 180, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 190, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 222, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 249, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 259, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 291, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 318, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0240970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 328, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 360, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 375, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 385, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 417, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 437, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 447, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 479, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 505, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 515, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 547, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 572, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 582, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 614, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 637, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0241976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 647, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 679, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 709, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 719, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 751, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 773, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 783, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 815, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 842, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 852, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 884, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 911, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 921, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 953, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 978, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0242992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 224 988, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 020, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 043, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 053, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 085, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 109, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 119, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 151, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 175, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 185, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 217, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 241, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 251, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 283, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0243940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 307, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 317, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 349, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 373, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 383, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 415, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 439, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 449, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 481, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 505, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 515, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 547, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 571, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 581, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 613, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0244979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 637, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 647, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 679, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 703, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 713, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 745, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 769, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 779, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 811, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 835, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 845, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 877, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 900, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 910, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 942, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0245987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 965, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0246048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 225 975, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0246118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 007, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0246190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 030, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0246436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 040, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0246605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 072, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0247503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 095, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0247594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 105, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0247672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 137, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0247747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 160, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0247810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 170, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0247877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 202, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0247955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 225, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 235, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 267, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 290, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 300, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 332, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 355, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 365, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 397, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 420, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 430, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 462, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 485, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 495, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 527, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0248971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 550, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 560, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 592, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 615, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 625, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 657, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 680, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 690, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 722, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 745, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 755, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 787, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 810, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 820, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 852, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0249985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 875, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 885, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 917, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 940, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 950, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 226 982, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 005, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 015, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 047, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 070, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 080, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 112, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 135, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 145, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 177, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0250991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 200, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 210, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 242, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 265, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 275, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 307, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 330, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 340, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 372, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 395, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 405, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 437, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 460, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 470, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0251977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 502, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 532, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 542, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 574, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 604, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 614, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 646, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 670, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 680, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 712, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 736, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 746, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 778, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 803, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0252933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 813, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 845, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 869, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 879, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 911, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 932, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 942, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 227 974, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 001, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 011, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 043, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 070, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 080, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 112, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0253969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 132, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 142, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 174, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 196, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 206, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 238, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 266, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 276, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 308, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 338, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 348, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 380, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 410, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 420, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 452, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0254995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 485, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 495, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 527, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 557, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 567, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 599, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 631, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 641, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 673, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 701, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 711, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 743, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 770, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 780, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0255937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 812, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0256250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 840, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0256399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 850, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0256502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 882, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0256632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 910, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0256732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 920, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0256834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 952, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0256951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 980, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 228 990, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 022, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 050, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 060, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 092, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 120, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 130, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 162, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 190, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 200, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 232, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 259, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 269, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 301, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0257987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 328, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 338, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 370, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 397, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 407, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 439, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 466, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 476, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 508, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 535, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 545, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 577, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 604, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 614, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0258931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 646, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 673, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 683, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 715, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 742, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 752, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 784, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 807, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 817, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 849, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 873, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 883, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 915, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 939, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 949, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0259959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 229 981, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 006, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 016, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 048, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 076, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 086, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 118, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 148, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 158, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 190, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 220, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 230, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 262, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 292, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 302, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0260979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 334, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 361, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 371, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 403, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 430, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 440, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 472, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 501, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 511, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 543, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 571, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 581, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 613, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 640, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 650, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0261993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 682, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 712, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 722, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 754, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 783, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 793, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 825, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 847, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 857, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 889, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 913, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 923, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 955, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 980, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0262943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 230 990, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 022, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 048, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 058, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 090, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 120, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 130, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 162, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 198, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 208, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 240, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 264, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 274, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 306, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 333, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0263963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 343, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 375, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 407, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 417, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 449, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 481, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 491, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 523, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 554, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 564, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 596, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 621, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 631, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 663, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0264941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 690, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0265005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 700, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0265071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 732, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0265146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 764, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0265215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 774, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0265282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 806, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0265359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 840, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0265420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 850, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0265487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 882, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0265561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 906, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0265625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 916, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0265692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 948, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0265947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 975, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0266121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 231 985, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0266237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 017, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0266390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 044, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0266481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 054, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0266573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 086, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0266697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 110, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0266761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 120, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0266830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 152, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0266905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 179, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0266966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 189, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 221, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 248, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 258, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 290, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 313, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 323, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 355, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 378, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 388, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 420, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 447, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 457, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 489, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0267955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 515, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 525, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 557, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 585, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 595, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 627, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 642, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 652, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 684, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 701, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 711, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 743, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 762, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 772, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 804, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0268961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 818, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 828, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 860, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 875, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 885, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 917, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 929, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 939, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 971, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 983, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 232 993, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 025, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 040, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 050, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 082, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0269964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 095, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 105, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 137, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 152, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 162, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 194, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 204, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 214, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 246, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 267, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 277, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 309, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 329, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 339, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 371, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0270970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 391, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 401, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 433, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 453, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 463, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 495, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 510, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 520, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 552, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 569, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 579, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 611, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 625, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 635, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 667, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0271973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 691, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 701, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 733, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 747, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 757, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 789, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 803, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 813, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 845, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 861, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 871, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 903, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 913, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 923, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 955, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0272992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 973, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 233 983, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 015, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 026, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 036, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 068, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 082, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 092, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 124, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 140, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 150, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 182, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 198, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 208, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 240, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0273984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 257, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 267, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 299, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 313, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 323, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 355, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 373, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 383, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 415, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 429, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 439, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 471, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 485, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 495, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0274915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 527, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0275042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 537, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0275109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 547, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0275175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 579, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0275245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 591, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0275308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 601, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0275375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 633, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0275444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 646, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0275508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 656, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0275799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 688, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0275885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 702, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0275945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 712, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 744, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 767, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 777, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 809, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 830, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 840, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 872, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 894, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 904, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 936, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 966, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 234 976, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 008, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 034, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0276979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 044, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 076, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 104, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 114, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 146, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 172, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 182, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 214, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 238, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 248, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 280, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 304, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 314, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 346, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 370, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0277996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 380, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 412, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 436, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 446, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 478, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 494, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 504, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 536, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 552, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 562, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 594, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 610, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 620, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 652, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0278971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 677, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 687, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 719, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 755, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 765, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 797, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 829, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 839, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 871, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 900, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 910, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 942, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 973, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 235 983, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0279927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 015, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 047, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 057, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 089, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 118, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 128, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 160, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 190, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 200, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 232, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 265, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 275, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 307, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 335, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 345, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0280952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 377, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 409, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 419, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 451, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 473, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 483, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 515, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 529, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 539, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 571, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 582, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 592, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 624, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 643, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 653, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0281960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 685, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 706, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 716, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 748, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 765, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 775, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 807, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 818, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 828, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 860, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 872, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 882, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 914, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 928, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 938, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0282963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 970, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 988, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 236 998, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 030, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 044, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 054, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 086, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 104, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 114, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 146, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 161, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 171, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 203, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 219, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 229, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0283977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 261, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 277, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 287, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 319, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 336, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 346, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 378, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 391, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 401, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 433, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 449, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 459, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 491, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 508, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 518, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0284978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 550, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0285047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 563, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0285111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 573, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0285177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 605, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0285249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 630, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0285465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 640, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0285557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 672, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0285640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 693, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0285701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 703, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0285767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 735, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0285870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 758, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0285936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 768, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 800, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 821, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 831, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 863, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 886, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 896, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 928, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 951, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 961, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 237 993, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 017, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 027, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 059, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 081, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0286958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 091, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 123, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 144, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 154, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 186, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 202, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 212, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 244, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 259, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 269, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 301, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 319, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 329, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 361, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 381, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0287970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 391, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 423, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 451, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 461, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 493, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 518, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 528, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 560, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 575, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 585, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 617, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 632, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 642, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 674, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 690, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0288978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 700, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 732, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 747, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 757, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 789, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 805, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 815, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 847, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 862, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 872, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 904, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 916, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 926, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 958, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 969, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0289981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 238 979, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 011, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 026, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 036, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 068, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 082, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 092, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 124, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 143, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 153, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 185, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 206, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 216, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 248, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 268, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0290981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 278, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 310, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 334, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 344, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 376, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 399, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 409, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 441, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 456, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 466, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 498, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 521, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 531, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 563, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 579, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0291995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 589, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 621, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 638, Length: 511</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 648, Length: 501</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 680, Length: 469</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 698, Length: 451</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 708, Length: 441</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 740, Length: 409</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 755, Length: 394</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 765, Length: 384</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 797, Length: 352</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 817, Length: 332</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 827, Length: 322</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 859, Length: 290</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0292971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 873, Length: 276</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0293034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 883, Length: 266</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0293104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 915, Length: 234</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0293178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 939, Length: 210</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0293242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 949, Length: 200</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0293311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 239 981, Length: 168</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0293389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 007, Length: 142</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0293453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 017, Length: 132</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0293525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 049, Length: 100</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0293600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 066, Length: 83</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0293663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 076, Length: 73</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0293732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 108, Length: 41</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0293807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 240 127, Length: 22</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0293913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0295567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0295891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 131 729, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0296079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 131 755, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0296162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 131 772, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0296223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 132 796, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0296309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0297717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0297800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0297924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\os</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0298102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0298149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0298249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\os</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0299360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0299598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 183 461, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0299745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 183 487, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0299830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 183 497, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0299894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 188 617, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0299977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0302554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0302629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0302731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\ntpath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0302856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0302903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0302994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\ntpath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0304061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0304299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 162 672, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0304443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 162 698, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0304582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 162 712, Length: 4 096</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0304660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 166 808, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0304743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0306538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0306607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0306710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\stat</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0306829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0306876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0306965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\stat</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0308164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0308519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 469 343, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0308688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 469 369, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0308777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 469 381, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0308835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 469 893, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0308918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0310539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0310608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0310710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\genericpath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0310827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0310874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0310965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\genericpath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0312154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0312492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 087 485, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0312697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 087 511, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0312788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 087 530, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0312847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 088 042, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0312930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0313700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0313766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0313866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\warnings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0313988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0314035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0314124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\warnings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0315623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0315994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 569 927, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0316155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 569 953, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0316241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 569 969, Length: 4 096</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0316301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 574 065, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0316385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0317823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0317889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0317992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\types</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0318113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0318158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0318246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\types</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0319316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0319551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 539 979, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0319695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 540 005, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0319787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 540 018, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0319845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 541 042, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0319928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0322291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0322361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0322466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\UserDict</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0322585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0322632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0322749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\UserDict</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0323826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0324065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 792 187, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0324231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 792 213, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0357231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 792 229, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0357422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 794 789, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0357533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0358902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0358982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0359093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\_abcoll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0359240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0359287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0359378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\_abcoll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0360489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0360744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 795 741, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0360896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 795 767, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0360985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 795 782, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0361046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 800 902, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0361129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0363240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0363310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0363614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\abc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0363761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0363814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0363900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\abc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0364997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0365257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 814 511, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0365401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 814 537, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0365484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 814 548, Length: 1 536</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0365543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 816 084, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0365626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0366548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0366609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0366709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\_weakrefset</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0366823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0366870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0366961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\_weakrefset</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0367997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0368230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 811 950, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0368349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 811 976, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0368432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 811 995, Length: 2 048</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0368493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 814 043, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0368574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0376564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0376647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0376758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\copy_reg</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0376883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0376932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0377029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\copy_reg</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0378174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0378420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 855 680, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0378581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 855 706, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0378670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 855 722, Length: 1 536</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0378731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 857 258, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0378816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0379900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0379961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0380063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\zipextimporter</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0380182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0380229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0380318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\zipextimporter</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0381374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0381606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 435 931, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0381756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 435 957, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0381839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 435 979, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0381900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 437 003, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0381980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0506647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0506755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0506910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\encodings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0507104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0507154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0507257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\encodings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0508905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0509193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0509473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0511221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0511507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 911 751, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0511701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 911 777, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0511792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 911 803, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0511856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 912 827, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0511942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0513543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0514424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0515352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0515544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0515729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0516125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0516189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0516292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\codecs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0516411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0516458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0516544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\codecs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0517555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0517779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 838 198, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0517932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 838 224, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0518051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 838 238, Length: 5 632</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0518123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 843 870, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0518206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0523514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0523769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 913 209, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0523919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 913 235, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0524008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 913 260, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0524071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 915 820, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0524157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0526789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0527030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 080 354, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0527180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 080 380, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0527266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 080 403, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0527327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 080 915, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0527413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0534782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0535037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 078 280, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0535170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 078 306, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0535256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 078 333, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0535317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 078 845, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0535400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0542980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0543069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0543188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\random</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0543327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0543374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0543465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\random</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0544668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0544914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 245 504, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0545078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 245 530, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0545183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 245 544, Length: 6 656</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0545247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 252 200, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0545333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0547109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0547172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0547275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\__future__</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0547394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0547441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0547532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\__future__</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0548632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0549053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 794 803, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0549200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 794 829, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0549286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 794 847, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0549347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 795 359, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0549433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0550649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0550713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0550813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\hashlib</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0550932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0550979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0551068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\hashlib</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0552170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0552406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 102 055, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0552553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 102 081, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0552639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 102 096, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0552700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 104 656, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0552783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0554284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0554348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0554448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\_hashlib</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0554567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0554614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0554703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\_hashlib</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0555883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0556118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 786 760, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0556296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 786 786, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0557119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 786 802, Length: 381 952</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0558310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 168 754, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0558424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0615854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0616204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:55, LastAccessTime: 16.07.2016 14:42:55, LastWriteTime: 16.07.2016 14:42:55, ChangeTime: 20.07.2018 19:44:33, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0616309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0617564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0617874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0618060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0619088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0619293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0619598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0620443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0620617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0898925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0899582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x741b0000, Image Size: 0x13000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0900471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0902076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0902369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0902452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0902527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\cryptsp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0903259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0903333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0903464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0903644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0903713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0903904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0904054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0904181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0904336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0904419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0904472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0904572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0904677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0904733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0904871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0904998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0905126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0905248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0907916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0908179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:55, LastAccessTime: 16.07.2016 14:42:55, LastWriteTime: 16.07.2016 14:42:55, ChangeTime: 19.07.2018 19:38:42, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0908262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0909232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0909503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0909645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0910872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0911072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0911368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0912221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0912393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0913047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0913562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74060000, Image Size: 0x2f000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0914452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0915604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0915876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0915953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0916020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\rsaenh.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0916649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0916732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0916859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0916923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCacheMaxItems</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0917142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCachePurgeIntervalSeconds</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0917258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivateKeyLifetimeSeconds</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0917383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0917519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0917585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0917679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0917726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0917876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0918003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0918120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0918305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0918389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0918444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0918544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0919084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\000602xx</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 26, Data: kernel32.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0920497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\Globalization\Sorting\SortDefault.nls</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0920738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\Globalization\Sorting\SortDefault.nls</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0920863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0921749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0921938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0922223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0923071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0923243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0923824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\Globalization\Sorting\SortDefault.nls</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 3 371 008, EndOfFile: 3 368 788, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0923971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\Globalization\Sorting\SortDefault.nls</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0924212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\Globalization\Sorting\SortDefault.nls</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0924794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0924894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0924991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0925501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0933934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0934009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0934112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\zipfile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0934253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0934300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0934386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\zipfile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0935671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0935959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 585 497, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0936192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 585 523, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0936320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 585 538, Length: 15 360</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0936408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 600 898, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0936508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0940373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0940451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0940556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\struct</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0940681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0940728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0940819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\struct</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0941961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0942204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 480 378, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0942357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 480 404, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0942440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 480 418, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0942528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0943662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0943728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0943825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\shutil</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0943939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0943986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0944074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\shutil</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0945149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0945385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 260 406, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0945554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 260 432, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0945640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 260 446, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0945715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 265 566, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0945798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0947319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0947385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0947482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\fnmatch</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0947599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0947679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0947768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\fnmatch</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0948851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0949422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 084 943, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0949605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 084 969, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0949690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 084 984, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0949749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 086 008, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0949832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0950455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0950519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0950616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\re</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0950735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0950779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0950865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\re</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0951937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0952165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 252 457, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0952309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 252 483, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0952392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 252 493, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0952453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 255 053, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0952533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0953528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0953589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0953686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\sre_compile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0953802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0953849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0953935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\sre_compile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0954993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0955220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 443 297, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0955362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 443 323, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0955445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 443 342, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0955506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 448 462, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,0955592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1079439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1079519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1079641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\sre_parse</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1079799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1079846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1079943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\sre_parse</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1081223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1081514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 451 419, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1081710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 451 445, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1081807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 451 462, Length: 7 680</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1081882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 459 142, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1081974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1083977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1084043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1084148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\sre_constants</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1084270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1084317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1084409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\sre_constants</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1085520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1085999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 448 705, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1086152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 448 731, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1086237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 448 752, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1086298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 451 312, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1086382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1090133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1090210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1090321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\collections</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1090446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1090496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1090590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\collections</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1091726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1091964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 844 022, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1092122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 844 048, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1092236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 844 067, Length: 6 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1092299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 850 211, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1092383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1095015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1095087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1095192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\keyword</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1095311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1095558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1095738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\keyword</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1097023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1097267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 130 664, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1097425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 130 690, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1097516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 130 705, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1097602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1098334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1098397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1098497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\heapq</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1098616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1098661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1098749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\heapq</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1099822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1100049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 105 120, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1100190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 105 146, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1100279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 105 159, Length: 4 608</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1100353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 109 767, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1100434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1103736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1103808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1103916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\pwd</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1104047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1104094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1104185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\pwd</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1104435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1104484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1104562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\grp</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1104648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1104695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1104770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\grp</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1109530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1109604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1109710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\io</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1109829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1109879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1109967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\io</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1111159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1111408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 119 812, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1111563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 119 838, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1111655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 119 848, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1111713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 120 360, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1111796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1115442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1115522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1115633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\string</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1115758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1115808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1115899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\string</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1117060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1117301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 470 224, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1117453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 470 250, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1117545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 470 264, Length: 4 096</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1117606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 474 360, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1117692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1132184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1132265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1132378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\tempfile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1132503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1132556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1132647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\tempfile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1133825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1134068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 513 636, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1134224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 513 662, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1134384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 513 678, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1134645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 518 798, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1134758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1136465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1136531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1136637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\fcntl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1136759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1136809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1136894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\fcntl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1137371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1137421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1137498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\PySide</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1137584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1137631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1137706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\PySide</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1138809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1139042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 074, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1139188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 100, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1139277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 123, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1139335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 635, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1139418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1140823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1141701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1142660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1142862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1143081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1144466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1144694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 883, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1144829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 909, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1144915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 266 930, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1144976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 269 490, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1145054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1146173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1146237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1146339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\ctypes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1146458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1146505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1146594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\ctypes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1147647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1147874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 857 725, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1148027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 857 751, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1148112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 857 774, Length: 5 632</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1148173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 863 406, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1148268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1157125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1158034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1158979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1159181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1159369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1159837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1159904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1160006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\_ctypes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1160128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1160175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1160264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\_ctypes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1161353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1161583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 746 184, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1161760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 746 210, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1161849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 746 225, Length: 40 448</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1161982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 786 673, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1162065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1168008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77ac0000, Image Size: 0xec000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1170886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1171205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1171296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1171377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ole32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1172208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1172277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1172391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\OLE\Tracing</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1172507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\Tracing</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1172890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\1aff6089-e863-4d36-bdfd-3581f07440be</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1175746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1176012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:14, LastAccessTime: 20.07.2018 1:34:14, LastWriteTime: 21.06.2017 10:42:23, ChangeTime: 20.07.2018 19:26:57, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1176101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\oleaut32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1184792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1185047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 863 896, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1185202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 863 922, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1185296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 863 944, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1185357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 864 456, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1185443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1188829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1189078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 864 828, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1189208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 864 854, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1189300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 864 877, Length: 2 048</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1189360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 866 925, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1189444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1194323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1194569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 138 307, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1194752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 138 333, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1195758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 138 354, Length: 514 560</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1197057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 652 914, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1197176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1271605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1271981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 024 727, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1272211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 024 753, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1272466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 024 777, Length: 47 104</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1272641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 071 881, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1272735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1281371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1281692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 072 256, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1281878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 072 282, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1282111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 072 308, Length: 44 544</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1282293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 116 852, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1282413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1293032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1293237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:08, LastAccessTime: 16.07.2016 14:43:08, LastWriteTime: 16.07.2016 14:43:08, ChangeTime: 19.07.2018 19:37:26, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1293331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1294440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1294672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1294861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1295753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1295944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1296246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1297099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1297268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1298099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1298623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x6d180000, Image Size: 0x8e000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1299432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35\msvcp90.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1304206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1304452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 7 318 446, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1304638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 7 318 472, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1306605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 7 318 487, Length: 1 030 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1308982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 631, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1309085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1750596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74fd0000, Image Size: 0x63000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1753028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1753350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1753447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1753524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ws2_32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1754239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\d0f1a5c6-fc43-48ae-99bf-efb1c38be9d1</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1758835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1759273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:04, LastAccessTime: 16.07.2016 14:43:04, LastWriteTime: 16.07.2016 14:43:04, ChangeTime: 20.07.2018 19:29:06, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1759428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1760802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1761102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1761268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1762202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1762396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1762695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1763545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1763717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1764590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1765102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x746e0000, Image Size: 0x8000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1765756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1766909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1767180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1767255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1767324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\version.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1767759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1767873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1767973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1768028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1769433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\kernel32.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1769696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\kernel32.dll.mui</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1769826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1770702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1770887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1771173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1772018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1772189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1772771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\kernel32.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 958 464, EndOfFile: 957 440, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1772926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\kernel32.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1773564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\540dc156-e9d6-42dc-a225-29794149a495</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1774952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\kernel32.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1933547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1933647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1933777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\atexit</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1933949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1934001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1934104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\atexit</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1935749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1936320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 816 273, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1936567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 816 299, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1936658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 816 313, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1936716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 816 825, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1936805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1940955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe\PySide</Path>
<Result>PATH NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1942255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\KernelBase.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1942529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\KernelBase.dll.mui</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1942679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1943590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1943779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1944078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1945108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1945286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1945901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\KernelBase.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 958 464, EndOfFile: 957 952, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1946062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\KernelBase.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1947771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1948004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 517 646, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1948220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 517 672, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1948605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 517 695, Length: 111 616</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1948876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 629 311, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1948965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1968054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1968304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 117 325, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1968459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 117 351, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1981957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 117 368, Length: 4 961 280</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1994048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 078 648, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,1994186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2056540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2589895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2589984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2590070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2590109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2590175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\NetworkProvider\HwOrder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2590533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9247_none_5090cb78bcba4a35</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2590752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2590793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2590846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2590882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2590937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\kernel32.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2591150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\ru-RU\KernelBase.dll.mui</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,2591306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2981658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\WINMM.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2984130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2984601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:49, LastAccessTime: 16.07.2016 14:42:49, LastWriteTime: 16.07.2016 14:42:49, ChangeTime: 19.07.2018 19:41:04, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2984703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2985770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2986072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2986257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2987152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2987357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2987665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2988518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2988693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2989510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2990161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74230000, Image Size: 0x24000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2991003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2993336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\WINMMBASE.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2996425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2996619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:49, LastAccessTime: 16.07.2016 14:42:49, LastWriteTime: 16.07.2016 14:42:49, ChangeTime: 19.07.2018 19:41:04, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2996702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2997703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2997908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2998024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2998897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2999082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,2999368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3000207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3000379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3021579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3021757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3021826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3021862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3021901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3021939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3021973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{E25B5812-BE88-4bd9-94B0-29233477B6C3}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f3ce0f7c-4901-4acc-8648-d5d44b04ef8f}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B20DF75-1EDA-4039-8097-38798227D5B7}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52528A6B-B9E3-4add-B60D-588C2DBA842D}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3022978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9B74B6A3-0DFD-4f11-9E78-5F7800F2E772}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3023014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3023053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3023095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3023136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3023316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3023405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3023460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3023505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3023566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3023629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3024333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3024519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3024555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>97</ProcessIndex>
<Time_of_Day>12:38:33,3024848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>84</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3097479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3098293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x741f0000, Image Size: 0x23000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3099022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3101662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3101928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3102017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3102094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winmmbase.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3103283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3103574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3103646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3103710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3105713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3105995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 391 896, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3106231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 391 922, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3115271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 391 936, Length: 3 632 640</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3123461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 12 024 576, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3123583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3704572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77be0000, Image Size: 0xe5000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3705498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3708675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe.Local</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3709939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3712624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3712820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:35:27, LastAccessTime: 20.07.2018 1:35:27, LastWriteTime: 02.11.2016 14:04:46, ChangeTime: 20.07.2018 2:17:47, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3712917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3714023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3714236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3714438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3715328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3715527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3715832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3716846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3717020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3717791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3718253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x6dcd0000, Image Size: 0x94000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3718716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.14393.447_none_5507ded2cb4f7f4c\comctl32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3721387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3721705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3721791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3721866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\comdlg32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3723645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3724030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3783348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3783699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 927 812, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3783949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 927 838, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3785279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 927 856, Length: 390 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3786204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 7 318 000, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3786315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3862372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3862871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 653 138, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,3863123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 657 152, Length: 4 096, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4003718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 653 164, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4008023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 653 184, Length: 1 690 624</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4008949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 4 661 248, Length: 16 384, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4195158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 343 808, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4195538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4693225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4693624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 343 973, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4693842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 343 999, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4694363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 344 023, Length: 173 568</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4694743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 517 591, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4694840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4763458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4763594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4763760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\platform</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4763957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4764010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4764118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\platform</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4769252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4769601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 216 758, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4769833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 215 936, Length: 8 192, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4857089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 216 784, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4857305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 216 800, Length: 11 264</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4857455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 224 128, Length: 4 096, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4861295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 228 064, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4900914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4924192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4924298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4924458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\json</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4924661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4924710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4924819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\json</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4926442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4926869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 120 850, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4927057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 120 876, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4927151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 120 897, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4927212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 121 921, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4927295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4928875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4929764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4930731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4930933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4931152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4932274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4932493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 122 095, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4932645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 125 824, Length: 4 096, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4935843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 122 121, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4935970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 122 141, Length: 3 072</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4936042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 125 213, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4936757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4943597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4943849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 129 490, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4943982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 129 516, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4944071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 129 536, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4944135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 130 560, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4944218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4948704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4948950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 008 931, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4949127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 007 040, Length: 8 192, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4953123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 008 957, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4953247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 008 984, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4953314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 009 496, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4953884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4962861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4963124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 125 702, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4963266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 125 728, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4963360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 125 748, Length: 3 584</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4963424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 129 332, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4963509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4967870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4967959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4968078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\threading</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4968236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4968286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4968386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\threading</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4969596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4969837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 521 546, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4969998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 523 136, Length: 4 096, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4972760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 521 572, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4972904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 521 589, Length: 8 192</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4973021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 527 232, Length: 4 096, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4975747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 529 781, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4976381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4983227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4983305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4983416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\traceback</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4983549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4983596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4983693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\traceback</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4984901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4985283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 536 990, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4985472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 537 016, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4985563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 537 033, Length: 2 560</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4985627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 539 593, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4985713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4990146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4990223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4990334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\socket</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4990459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4990509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4990597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\socket</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4991769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4992010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 437 379, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4992163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 437 405, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4992282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 437 419, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4992345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 442 539, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4992431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4994102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4994171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4994271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\_socket</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4994387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4994434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4994520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\_socket</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4995914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4996147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 169 073, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4996712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 170 304, Length: 4 096, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4999795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 169 099, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,4999926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 169 114, Length: 20 992</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5000050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 174 400, Length: 16 384, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5002984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 190 106, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5003619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5011318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5011410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5011515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5011640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>ACCESS DENIED</Result>
<Detail>Desired Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5011795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5011892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5014067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5014130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5014327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5014438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5014540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5014607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 8, Data: 2.0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5014787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 8, Data: 2.0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5014959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5015025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5015255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5015311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog\3862E438</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5015408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5015496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Callout</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 70, Data: %SystemRoot%\System32\fwpuclnt.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5015632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Callout</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 70, Data: %SystemRoot%\System32\fwpuclnt.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5015945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5016006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5016103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 10</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5016629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 10</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5016793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5016851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000000A</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5016931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Next_Catalog_Entry_ID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1013</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5017056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Num_Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5017203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5017261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5017372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5017422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5017502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5017613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5017760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5017840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5017898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5017976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5018081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5018217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5018292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5018350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5018427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5018585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5018721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5018799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5018854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5018934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5019034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5019164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5021572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5021641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5021733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5021852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5021999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5022076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5022134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5022218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5022326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5022453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5022528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5022586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5022700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5022808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5022941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5023015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5023071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5023148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5023337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5023464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5023539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5023595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5023672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5023775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5023902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5024104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5024182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5024284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5024426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5024714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5024797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5024855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5024938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5025049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5025174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5025249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5025307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5025387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\PackedCatalogItem</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5025487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\PackedCatalogItem</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5025614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5025659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5025805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5025866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5025952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5026318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5026476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5026534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\00000014</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5026612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Num_Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 6</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5026756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5026811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5026916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5026966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5027041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\napinsp.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5027171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\napinsp.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5027382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5027509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5027634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5027756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5027883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: A2 CB 4A 96 BC B2 EB 40 8C 6A A6 DB 40 16 1C AE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5028008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\AddressFamily</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5028119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\SupportedNameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 37</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5028244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5028363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5028487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\StoresServiceClassInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5028609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5028734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5028864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5028942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5029000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5029083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5029208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5029330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5029452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5029576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5029695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5029823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: CE 89 FE 03 6D 76 76 49 B9 C1 BB 9B C4 2C 7B 4D</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5029942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\AddressFamily</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5030050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\SupportedNameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 39</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5030183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5030305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5030427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\StoresServiceClassInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5030546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5030668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5030798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5030876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5030934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5031011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5031133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5031255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5031377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5031499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5031618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5031740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: CD 89 FE 03 6D 76 76 49 B9 C1 BB 9B C4 2C 7B 4D</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5031867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\AddressFamily</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5031975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\SupportedNameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 38</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5032095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5032211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5032333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\StoresServiceClassInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5032452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5032588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5032715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5032826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5032887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5032967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\NLAapi.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5033098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\NLAapi.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5033228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5033350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5033480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5033599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5033807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: 3A 24 42 66 A8 3B A6 4A BA A5 2E 0B D7 1F DD 83</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5033954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\AddressFamily</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5034064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\SupportedNameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 15</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5034186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5034311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5034433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\StoresServiceClassInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5034552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5034674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5034801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5034882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5034943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5035020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\System32\mswsock.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5035148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 68, Data: %SystemRoot%\System32\mswsock.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5035272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5035397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5035525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5035646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5035774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: 40 9D 05 22 9E 7E CF 11 AE 5A 00 AA 00 A7 11 2B</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5035896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\AddressFamily</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5036004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\SupportedNameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5036126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5036248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5036367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\StoresServiceClassInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5036489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5036611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5036738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5036813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5036874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5036951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\System32\winrnr.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5037137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\LibraryPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\System32\winrnr.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5037264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5037389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5037517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5037636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5037760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderId</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: EE 37 26 3B 80 E5 CF 11 A5 55 00 C0 4F D8 D4 AC</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5037885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\AddressFamily</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5037993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\SupportedNameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 32</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5038112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5038234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5038359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\StoresServiceClassInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5038481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5038600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderInfo</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5038725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5038766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5038816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5038930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5038982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5039065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock2\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5039143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5039218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5039268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Ws2_32NumHandleBuckets</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5039392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5041118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5041177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5041273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\functools</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5041393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5041437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5041526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\functools</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5042966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5043249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 086 051, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5043454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 086 077, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5043728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 086 094, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5043806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 087 118, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5043894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5045161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5045224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5045327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\_ssl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5045454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5045501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5045590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\_ssl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5046856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5047092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 190 545, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5047216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 190 571, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5048491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 190 583, Length: 590 848</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5048895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 276 800, Length: 507 904, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5154983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 781 431, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5155858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5227735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x753e0000, Image Size: 0x17d000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5228888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x751d0000, Image Size: 0xe000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5231761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5232110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5232204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5232284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\msasn1.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5233453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5233728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5233803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5233869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\crypt32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5250454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5250553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5250689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\subprocess</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5250872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5250922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5251027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\subprocess</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5252335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5252626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 480 566, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5252856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 480 592, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5252950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 480 610, Length: 10 240</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5253086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 486 272, Length: 8 192, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5257330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 490 850, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5257901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5265850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5265933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5266049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\win32com</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5266188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5266237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5266332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\win32com</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5267576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5267833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 385 857, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5268149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 383 872, Length: 8 192, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5271114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 385 883, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5271247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 385 908, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5271316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 386 932, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5271892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5277500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5278622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5279611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5279816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5280038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5280423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5280489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5280594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\win32api</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5280716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5280764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5280852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\win32api</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5282057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5282287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 876 773, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5282437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 876 799, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5282526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 876 815, Length: 39 936</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5282650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 6 916 751, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5282733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5289111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5289355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 909, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5289521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 935, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5289615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 955, Length: 42 496</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5290873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 391 451, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5290973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5306109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\secur32.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5308585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5308879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:01, LastAccessTime: 16.07.2016 14:43:01, LastWriteTime: 16.07.2016 14:43:01, ChangeTime: 19.07.2018 19:38:51, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5308973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5309976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5310276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5310453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5311328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5311517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5311819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5312664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5312836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5313586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5314174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x73ae0000, Image Size: 0xa000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5314897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5316055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5316329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5316410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5316479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\secur32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5317509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5317581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5317690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\pythoncom</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5317820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5317870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5317958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\pythoncom</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5319186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5319418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 079 147, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5319576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 079 173, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5319673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 079 192, Length: 142 848</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5319961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 17 222 040, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5320050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5347512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rpcss.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5352191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5352507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:04, LastAccessTime: 16.07.2016 14:43:04, LastWriteTime: 16.07.2016 14:43:04, ChangeTime: 19.07.2018 19:40:16, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5352615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5353660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5353956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5354131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5355150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5355361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5355693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5357478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5357663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5358525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5359123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74110000, Image Size: 0x75000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5360406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5361608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5361905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5361996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5362077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\uxtheme.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5402247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5402474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:59, LastAccessTime: 20.07.2018 20:11:59, LastWriteTime: 20.07.2018 13:54:12, ChangeTime: 20.07.2018 20:09:33, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5402582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5403577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5403796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5403965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5405023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5405245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5405572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5406453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5406627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5407514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5408057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x60750000, Image Size: 0x17c000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5408556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5408750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5408866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5409079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5410054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5410279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:59, LastAccessTime: 20.07.2018 20:11:59, LastWriteTime: 20.07.2018 13:54:12, ChangeTime: 20.07.2018 20:09:33, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5411052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5412052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74d90000, Image Size: 0x6000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5412562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5415507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\NETAPI32.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5417879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5418167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:49, LastAccessTime: 16.07.2016 14:42:49, LastWriteTime: 16.07.2016 14:42:49, ChangeTime: 19.07.2018 19:37:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5418261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5419269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5419560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5419693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5420580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5420768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5421079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5421943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5422117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5422821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5423397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x71140000, Image Size: 0x13000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5423965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5427548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\NETUTILS.DLL</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5429892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5430160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:55, LastAccessTime: 16.07.2016 14:42:55, LastWriteTime: 16.07.2016 14:42:55, ChangeTime: 19.07.2018 19:37:42, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5430260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5431269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5431557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5431687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5432568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5432756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5433067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5434067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5434327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5435053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5435621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x70ca0000, Image Size: 0xb000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5436109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5438796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\WKSCLI.DLL</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5441126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5441392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:55, LastAccessTime: 16.07.2016 14:42:55, LastWriteTime: 16.07.2016 14:42:55, ChangeTime: 19.07.2018 19:41:08, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5441486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5442481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5442764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5442894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5443894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5444085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5444398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5445274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5445446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5446135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5446667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x70cb0000, Image Size: 0x10000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5447177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5448637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5448937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5449033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5449117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\psapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5450233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5450505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5450585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5450660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\netapi32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5451724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5451979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5452056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5452128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\netutils.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5453162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5453536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5453655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5453727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\wkscli.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5454824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5455010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5455087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5455159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\safemon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5466729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5466829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5466965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5467106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5467208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5467294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe\Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 84, Data: C:\Program Files (x86)\360\Total Security</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5467530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5469868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5470045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:30, LastAccessTime: 23.08.2018 15:02:29, LastWriteTime: 23.08.2018 15:02:29, ChangeTime: 23.08.2018 15:02:29, FileAttributes: DA</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5470134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5472547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5472722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:30, LastAccessTime: 20.07.2018 20:11:30, LastWriteTime: 20.07.2018 20:11:30, ChangeTime: 20.07.2018 20:11:30, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5472805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5474024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5474271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>LockFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Exclusive: False, Offset: 0, Length: 4 294 967 295, Fail Immediately: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5474365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 152, EndOfFile: 146, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5474567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 146, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5475099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>UnlockFileSingle</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 4 294 967 295</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5475196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5477490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5477673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:36, LastAccessTime: 20.07.2018 20:11:36, LastWriteTime: 20.07.2018 13:54:11, ChangeTime: 20.07.2018 20:09:20, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5477756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5479964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5480114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:36, LastAccessTime: 20.07.2018 20:11:36, LastWriteTime: 20.07.2018 13:54:11, ChangeTime: 20.07.2018 20:09:20, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5480194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5481252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5481446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>LockFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Exclusive: False, Offset: 0, Length: 4 294 967 295, Fail Immediately: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5481527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 12 288, EndOfFile: 8 350, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5481701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 8 350, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5482167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>UnlockFileSingle</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 4 294 967 295</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5482264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5482845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5483023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5483170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5483244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\ru-RU</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 532</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5483430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5483530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5483605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5483688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5483743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\ru-RU</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 532</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5483879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5483959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\ru-RU</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 90</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5484109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\ru</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {0000004A-57EE-1E5C-00B4-D0000BB1E11E}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5490135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5490315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:30, LastAccessTime: 20.07.2018 20:11:30, LastWriteTime: 20.07.2018 20:11:30, ChangeTime: 20.07.2018 20:11:30, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5490412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5491454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5491661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>LockFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Exclusive: False, Offset: 0, Length: 4 294 967 295, Fail Immediately: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5491756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 152, EndOfFile: 146, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5491994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 146, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5492287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>UnlockFileSingle</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 4 294 967 295</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5492384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\config.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5495003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5495180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:36, LastAccessTime: 20.07.2018 20:11:36, LastWriteTime: 20.07.2018 13:54:11, ChangeTime: 20.07.2018 20:09:20, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5495269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5497491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5497643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 20:11:36, LastAccessTime: 20.07.2018 20:11:36, LastWriteTime: 20.07.2018 13:54:11, ChangeTime: 20.07.2018 20:09:20, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5497726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5498704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5498895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>LockFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Exclusive: False, Offset: 0, Length: 4 294 967 295, Fail Immediately: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5498976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 4 096, EndOfFile: 3 052, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5499153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 3 052, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5499607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>UnlockFileSingle</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 4 294 967 295</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5499699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5500693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5500887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>LockFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Exclusive: False, Offset: 0, Length: 4 294 967 295, Fail Immediately: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5500965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 4 096, EndOfFile: 3 052, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5501137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 3 052, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5501392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>UnlockFileSingle</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 4 294 967 295</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5501483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\i18n\ru\safemon\wdk.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5505558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5505644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5505780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5505899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5505991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5506057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe\Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 84, Data: C:\Program Files (x86)\360\Total Security</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5506262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5507587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5507811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>LockFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Exclusive: False, Offset: 0, Length: 4 294 967 295, Fail Immediately: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5507897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 12 288, EndOfFile: 8 350, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5508088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 8 350, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5508606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>UnlockFileSingle</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 4 294 967 295</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5508703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Program Files (x86)\360\Total Security\safemon\wd.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5509764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5509842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5509961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5510097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5510449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5510529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5510662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5510728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5510908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 30, Data: Common AppData</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5511094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5511235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5511357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5511476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5511598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5511720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5511839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5511958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5512075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5512197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5512460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5512593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5512712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5512839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5512964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5513086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5513205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5513388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5513510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5513712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5513793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5513901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5514108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5514169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5514272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5514385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5514463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5514521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 52, Data: %SystemDrive%\ProgramData</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5514676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 52, Data: %SystemDrive%\ProgramData</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5514862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5515161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\FileSystem\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5515250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\FileSystem</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5515336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\FileSystem</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5515388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\FileSystem\LongPathsEnabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5515546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\FileSystem</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5516602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\ProgramData</Path>
<Result>NAME COLLISION</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5520902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\ProgramData</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5521176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\ProgramData</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:47:48, LastAccessTime: 20.07.2018 20:20:30, LastWriteTime: 20.07.2018 20:20:30, ChangeTime: 20.07.2018 20:20:30, FileAttributes: HDNCI</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5521265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\ProgramData</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5521553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5521625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5521747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5521883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5521941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5522151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5533536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\urlmon.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5535949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5536248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:59, LastAccessTime: 20.07.2018 1:34:59, LastWriteTime: 30.03.2018 5:58:40, ChangeTime: 20.07.2018 19:24:44, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5536337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5537334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5537633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5537802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5538669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5538866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5539168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5540008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5540177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5540958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5541570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x72cc0000, Image Size: 0x195000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5542617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5544945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\iertutil.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5547197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5547452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:35:05, LastAccessTime: 20.07.2018 1:35:05, LastWriteTime: 30.03.2018 6:32:00, ChangeTime: 20.07.2018 19:25:12, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5547535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5548499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5548768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5548887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5549730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5549910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5550189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5551015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5551181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5551932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5552456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x725e0000, Image Size: 0x22b000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5553173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5555913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5556207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5556296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5556371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\iertutil.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5557559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5557817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5557889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5557955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\urlmon.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5558991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\0bca4784-8257-51a0-d9ec-24fe1fe4c90d</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5559856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\ff32ada1-5a4b-583c-889e-a3c027b201f5</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5562762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5563034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 435 714, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5563253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 435 740, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5563341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 435 772, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5563430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5564161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe\win32com\</Path>
<Result>PATH NOT FOUND</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5565098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5565943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5566877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5567068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5567275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5568686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5568905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 387 475, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5569051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 387 501, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5569143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 387 533, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5569215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 392 653, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5569292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5571368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe\win32com\</Path>
<Result>PATH NOT FOUND</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5572329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5573182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>NOT A DIRECTORY</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5574086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5574277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Filter: MCLauncher.exe, 1: MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5574460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5575620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5575839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 400 491, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5575986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 400 517, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5576072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 400 548, Length: 6 656</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5576138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 407 204, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5576216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5578305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5578391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5578505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\winerror</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5578657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5578704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5578801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\winerror</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5579904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5580134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 347 472, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5580305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 347 498, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5580394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 347 514, Length: 37 888</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5580674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 359 296, Length: 24 576, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5644621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 385 402, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5644937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5654930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5655194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 392 977, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5655343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 393 003, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5655432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 393 032, Length: 7 168</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5655496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 400 200, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5655593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5657715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5657790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5657901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\pywintypes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5658045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5658092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5658186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\pywintypes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5659621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5659862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 909, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5660045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 935, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5660170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 348 955, Length: 42 496</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5660430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 8 391 451, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5660516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5669958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5670202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 407 375, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5670368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 407 401, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5670459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 407 433, Length: 6 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5670531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 413 577, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5670617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5672332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5672402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5672512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\glob</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5672640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5672687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5672776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\glob</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5673937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5674166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 095 792, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5674377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 097 152, Length: 4 096, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5779794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 095 818, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5780024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 095 830, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5780093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 096 854, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5781027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5924969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5925282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 387 081, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5925476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 387 107, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5925564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 387 143, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5925653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5929221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5929310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5929438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\helpers</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5929607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5929656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5929756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\helpers</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5931025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5931272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 601 095, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5931430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 601 121, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5931726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 601 136, Length: 93 184</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,5931956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 621 440, Length: 73 728, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6001342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 694 320, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6002165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6023772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\OneDrive\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6024853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6025102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Desktop\*</Path>
<Result>SUCCESS</Result>
<Detail>Filter: *, 1: .</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6025393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>0: .., 1: desktop.ini, 2: MCLauncher.lnk, 3: ProcessMonitor.zip, 4: Uninstall Tool.lnk, 5: Yandex.lnk, 6: µTorrent.lnk, 7: Помощник по обновлению до Windows 10.lnk</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6025590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>NO MORE FILES</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6025681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6026715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6026906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Desktop\*</Path>
<Result>SUCCESS</Result>
<Detail>Filter: *, 1: .</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6027072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>0: .., 1: desktop.ini, 2: MCLauncher.lnk, 3: ProcessMonitor.zip, 4: Uninstall Tool.lnk, 5: Yandex.lnk, 6: µTorrent.lnk, 7: Помощник по обновлению до Windows 10.lnk</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6027236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>NO MORE FILES</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6027316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6030081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6030258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:11, LastWriteTime: 24.08.2018 12:38:31, ChangeTime: 24.08.2018 12:38:31, AllocationSize: 01.01.1601 3:00:01, EndOfFile: 01.01.1601 3:00:01, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6030341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6032710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6032865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6032943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6034065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6034276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6035096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6035267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6035348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6035436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6035520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6035567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6035653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\wscript.shell</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6035774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\wscript.shell</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6035979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6036052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6036112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6036212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WScript.Shell\CLSID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6036298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6036351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6036456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6036511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6036589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WScript.Shell\CLSID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6036656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WScript.Shell\CLSID\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {72C24DD5-D70A-438B-8A42-98424B88AFB8}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6036761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6036811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6040177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6040493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:56, LastAccessTime: 16.07.2016 14:42:56, LastWriteTime: 16.07.2016 14:42:56, ChangeTime: 20.07.2018 19:29:04, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6040581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6041601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6041897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6042069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6042961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6043158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6043452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6044305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6044480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6045244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6045859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x6cda0000, Image Size: 0x81000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6046524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6048189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6048475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6048555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6048627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\sxs.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6050780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6050957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6051040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6051098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6051198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\wscript.shell</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6051326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\wscript.shell</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6051423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6051472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6051539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6051641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WScript.Shell\CLSID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6051722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6051777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6051849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6051907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6051988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WScript.Shell\CLSID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6052049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WScript.Shell\CLSID\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {72C24DD5-D70A-438B-8A42-98424B88AFB8}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6052143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6052193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6052539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6052619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6053107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6053168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\COM3</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6053262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\COM3</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6053307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\COM3\Com+Enabled</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6053484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\COM3</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6054082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x74ef0000, Image Size: 0x84000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6056113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6056404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6056487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6056559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\clbcatq.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6057895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6057989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6058064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6058116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6058235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6058415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6058634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6058684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6058748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6059000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6059177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6059241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6059324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6059446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6059504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6059610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6059684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: Windows Script Host Shell Object</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6059754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6059806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6059892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6059956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: Windows Script Host Shell Object</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6060017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6060072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6060158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6060241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6060294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6060405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6060463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6060543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6060610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6060748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6060818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6060915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6060992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 60, Data: C:\Windows\SysWOW64\wshom.ocx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6061053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6061106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6061189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6061253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 60, Data: C:\Windows\SysWOW64\wshom.ocx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6061311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6061366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6061444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6061507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Apartment</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6061671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6061724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6061793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6061895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6061995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x100</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6062990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6063064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings\Software\Microsoft\Ole\FeatureDevelopmentProperties</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6063148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6063211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6063261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Ole\FeatureDevelopmentProperties</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6063355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6063433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6063480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6063555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\OLE</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6063635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6063688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6063732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\MaxSxSHashCount</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6063868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6064289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6064361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6064436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6064483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6064577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6064694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6064777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6064824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6064885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6064979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6065062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6065115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6065187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6067802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6068082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:02, LastAccessTime: 16.07.2016 14:43:02, LastWriteTime: 16.07.2016 14:43:02, ChangeTime: 20.07.2018 2:17:50, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6068173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6069354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6069653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6069814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6070733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6070938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6071249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6072113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6072288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6073349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6073867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x70e90000, Image Size: 0x24000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6074413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6076942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6077214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:02, LastAccessTime: 16.07.2016 14:43:02, LastWriteTime: 16.07.2016 14:43:02, ChangeTime: 20.07.2018 2:17:50, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6077297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6078294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6078746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6078876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6079763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6079948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6080236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6081173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6081347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6082328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6082794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x6dca0000, Image Size: 0x2b000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6083223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6084894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6085179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6085276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6085345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\scrrun.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6086492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6086756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6086839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6086905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6087734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Session Manager</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6087847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6087936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6087991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 24</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6088324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6089199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Rpc\Extensions</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6089316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc\Extensions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6089401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc\Extensions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6089457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 24, Data: combase.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6089631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc\Extensions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6089933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6089994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6090083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Rpc</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6090163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6090224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6090285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc\MaxRpcSize</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6090432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6090701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6090773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6090848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6090889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName\ComputerName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: WIN-0UOTFKKVN1S</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6091039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6091114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\Setup</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6091183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SYSTEM\Setup</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6091222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SYSTEM\Setup\OOBEInProgress</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6091360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SYSTEM\Setup</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6091424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\Setup</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6091482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SYSTEM\Setup</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6091521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SYSTEM\Setup\SystemSetupInProgress</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6091648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SYSTEM\Setup</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6091770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6091837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6092275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6092327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6092416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\Rpc</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6092488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Rpc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6092909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6092959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6093036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Rpc</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6093103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6093158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6093203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc\IdleTimerWindow</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6093338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Rpc</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6093657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6093740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6093793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6093859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6093929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6093973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6094967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\419</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\419</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\19</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\19</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6095954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6096987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6097040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6097101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6097156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6097234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6097292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 60, Data: C:\Windows\SysWOW64\wshom.ocx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6097358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6098904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6099267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 64, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6099525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 248, Length: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6099603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 252, Length: 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6099669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 496, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6099747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 536, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6099805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 576, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6099863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 616, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6099918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 656, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6099991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 528, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6100060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 544, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6100126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 87 904, Length: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6100190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 552, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6100254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 87 888, Length: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6100309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 87 890, Length: 14</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6100381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 600, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6100445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 616, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6100514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 872, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6100570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 888, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6100636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 87 488, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6100703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 126 976, EndOfFile: 125 952, NumberOfLinks: 3, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6100802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6100933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6101869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6102063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6102359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6103215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6103387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6104199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 126 976, EndOfFile: 125 952, NumberOfLinks: 3, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6107393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6107889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6108222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6108266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6108305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6109408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6109499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6109591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6109646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\en-US</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 532</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6109796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\CustomLocale</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6109879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6109942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6110012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6110056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\en-US</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 532</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6110172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6110244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\en-US</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 90</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6110380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\en</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 90</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6111655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6111754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6111821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6111893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6111968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6112990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6113929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6114007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6114082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6114131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6114192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6114248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6114325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6114397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6114447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6114511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6114566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6114644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6114705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\stdole2.tlb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6114774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6115882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6116245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 64, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6116561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 184, Length: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6116650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 188, Length: 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6116719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 432, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6116788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 472, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6116860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 024, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6116916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 040, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6116982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 272, Length: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6117046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 048, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6117110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 256, Length: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6117165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 258, Length: 14</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6117240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 088, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6117304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 104, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6117373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 160, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6117428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 176, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6117492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 224, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6117556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 20 480, EndOfFile: 18 432, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6117658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6117938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6118930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6119124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6119420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6120290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6120468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6121047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 20 480, EndOfFile: 18 432, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6121199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6121543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6121604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6121642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6121684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6131303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6131411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6131500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6131556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6131677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6131830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Shortcut</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6132963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6133024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Shortcut</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6133085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6133140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6133226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6133304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6133359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6133453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6133509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6133595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6133656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6133794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6133866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6133969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6134041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: C:\Windows\SysWOW64\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6134099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6134154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6134237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6134296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: C:\Windows\SysWOW64\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6134357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6134412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6134495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6134553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Both</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6134722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6134778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6134844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6134949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6135044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6135096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6135166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6135221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6135304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6135379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6135429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6135506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6135673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6135734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6135800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6135847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6135933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6136024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6136108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6136149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6136207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6136293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6136371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6136423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6136493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6138465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Desktop\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6138903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Desktop\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 972, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6140011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6140078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6140189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6140299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6140385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6140460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6140635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6140721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6140779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6140862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6140970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6141017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6141158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6141241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6141294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6141383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6141460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6141518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6141563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6141693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6141759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6141812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6141890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6141970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6142014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6142136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6142460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6142513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6142602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6142677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6142735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6142776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6142901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6142970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6143965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6144962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6145040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6145081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6145195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6145353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6145403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6145494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6145816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6145863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6145940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6146034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6146076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\ValidateRegItems</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6146300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6146367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6146420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6146503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6146583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6146625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\MonitorRegistry</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6146760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6147209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6147265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6147353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6147434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6147495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6147544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6147677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6147744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6147797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6147874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6147954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6147996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6148115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6148727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6148819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6148872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6148941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6149010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6149057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6149143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6149273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6149365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6149412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6149481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6149572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6149642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6149769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6149838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6149941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6150021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6150132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6150199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6150298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6150376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6150484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6150550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6150650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6150728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1581568</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6150872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6150963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6151988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6152127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6152337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6152390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6152479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6152573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6152620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\ValidateRegItems</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6152750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6152822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6152872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6152958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6153036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6153077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\MonitorRegistry</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6153196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6153692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6153750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6153839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6153919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6153983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6154025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6154158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6154227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6154280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6154360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6154440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6154482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6154596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6154690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6154740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6154817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6154897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6154961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6155014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6155078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellState</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 36, Data: 24 00 00 00 34 28 00 00 00 00 00 00 00 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6155219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellState</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 36, Data: 24 00 00 00 34 28 00 00 00 00 00 00 00 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6155349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6155452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6155501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6155590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6155665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6155720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6155765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6155889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6155956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6156008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6156083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6156161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6156202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6156316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6156394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6156443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6156527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6156601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6156657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6156696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6156989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6157061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6157114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6157192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6157275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6157319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6157438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6157516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6157568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6157651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6157723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6157779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6157820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6157942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6158976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6159051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6159128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6159170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6159283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6159366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6159430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6159510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6159643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6159763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6159885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6160006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6160126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6160245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6160367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6160486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6160605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6160724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6160840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6160951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6161070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6161187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6161306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowStatusBar</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6161433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6161757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6161827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6161896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6161943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Directory\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6162968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Folder\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6163949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AllFilesystemObjects\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\Directory\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Directory\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Directory\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6164971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6165049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6165104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6165187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6165251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Folder\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6165376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6165437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6165534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6165614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6165667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Folder\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6165733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6165789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6165866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6165924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\AllFilesystemObjects\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6166043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6166104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6166199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6166282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6166334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AllFilesystemObjects\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6166406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6166459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6166661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6166742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6166786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\Directory\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6166897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Directory\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Directory\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Folder\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6167969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Folder\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\AllFilesystemObjects\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AllFilesystemObjects\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6168939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Directory\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Folder\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AllFilesystemObjects\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6169969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\Directory\IsShortcut</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6170080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Directory\IsShortcut</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6170194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6170249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6170310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6170407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6170474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Folder\IsShortcut</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6170593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6170654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6170745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6170809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\AllFilesystemObjects\IsShortcut</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6170936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6170997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6171075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6171147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6171186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\Directory\AlwaysShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6171288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Directory\AlwaysShowExt</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 2, Data: </Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6171410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6171468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6171529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6171607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6171673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6171712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\Directory\NeverShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6171815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Directory\NeverShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6171917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Directory</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6171970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6172028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6172122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Folder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6172189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Folder\NeverShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6172308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6172369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6172460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AllFilesystemObjects</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6172527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\AllFilesystemObjects\NeverShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6172662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\Directory</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6172715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Folder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6172757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\AllFilesystemObjects</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6175754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6176042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:17, LastAccessTime: 20.07.2018 1:34:17, LastWriteTime: 06.03.2018 9:03:35, ChangeTime: 20.07.2018 19:24:46, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6176134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6177325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6177619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6177760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6178652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6178843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6179143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6180002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6180173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6180860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6181434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x728e0000, Image Size: 0x14f000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6182140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6183980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6184271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6184354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6184426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6185551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6185620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6185739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KindMap</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6185850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6185928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6186102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: program</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6186335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6186388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6186457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6186529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6186579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6186662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6186767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6186853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6186897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6186956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6187053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6187122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\.exe\Content Type</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 50, Data: application/x-msdownload</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6187285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6187887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6187964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6188036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6188086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6188183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6188308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6188399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6188443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6188507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6188607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6188698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6188754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6188826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6188889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6188945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 48, Data: Memory Mapped Cache Mgr</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 48, Data: Memory Mapped Cache Mgr</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6189978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\system32\propsys.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\system32\propsys.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\system32\propsys.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6190995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6191075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6191139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Both</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6191294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6191344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6191411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6191513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6191610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6191666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6191732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6191788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6191868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6191948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6191998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6192070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6192195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6192256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6192322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6192369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6192452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6192547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6192627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6192669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6192727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6192813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6192896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6192948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6193015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6197495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6197753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:17, LastAccessTime: 20.07.2018 1:34:17, LastWriteTime: 06.03.2018 9:03:35, ChangeTime: 20.07.2018 19:24:46, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6197844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6200202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6200440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:17, LastAccessTime: 20.07.2018 1:34:17, LastWriteTime: 06.03.2018 9:03:35, ChangeTime: 20.07.2018 19:24:46, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6200526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6203130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\System32\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6203388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Windows\System32\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:24:02, LastAccessTime: 20.07.2018 1:24:02, LastWriteTime: 06.03.2018 9:08:30, ChangeTime: 20.07.2018 19:29:33, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6203465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\System32\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6207178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6207422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:17, LastAccessTime: 20.07.2018 1:34:17, LastWriteTime: 06.03.2018 9:03:35, ChangeTime: 20.07.2018 19:24:46, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6207505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6209799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6210029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:17, LastAccessTime: 20.07.2018 1:34:17, LastWriteTime: 06.03.2018 9:03:35, ChangeTime: 20.07.2018 19:24:46, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6210106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6212603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\System32\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6212841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Windows\System32\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:24:02, LastAccessTime: 20.07.2018 1:24:02, LastWriteTime: 06.03.2018 9:08:30, ChangeTime: 20.07.2018 19:29:33, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6212919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\System32\propsys.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6214545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6214617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6214733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6214841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6214919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6214977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6215315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6215431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6215515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6215642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6215783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6215850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6215997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6216096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6216168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6216243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6216293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6216376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6216484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6216565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6216623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6216684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6216786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6216853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\.exe\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: exefile</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6216961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\CurVer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\CurVer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6217986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6218972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6219039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6219119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6219197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6219247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe\ShellEx\IconHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6219380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6219432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6219515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6219573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6219709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6219773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6219873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6219953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\SystemFileAssociations\.exe\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe\DocObject</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6220950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6221064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6221125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6221219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6221300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6221352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6221413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6221469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6221546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6221604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\SystemFileAssociations\.exe\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6221721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6221784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6221879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6221956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6222009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe\BrowseInPlace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6222150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6222205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6222283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6222341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\.exe\Content Type</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 50, Data: application/x-msdownload</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6222494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6222555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6222652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6222732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6222785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\exefile\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6222851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6222906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6222984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6223056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6223109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe\Clsid</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6223214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6223267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6223341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6223397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\IsShortcut</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6223519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6223582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6223674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6223740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\SystemFileAssociations\.exe\IsShortcut</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6223862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6223926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6224017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6224078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\AlwaysShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6224195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6224256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6224353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6224416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\SystemFileAssociations\.exe\AlwaysShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6224541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6224602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6224693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\exefile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6224874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\exefile\NeverShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6225070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6225170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6225292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\SystemFileAssociations\.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6225364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\SystemFileAssociations\.exe\NeverShowExt</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6225519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6225574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\exefile</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6225622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\SystemFileAssociations\.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6225832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6225885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6225985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6226070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6226137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6226181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NormalizeLinkNetPidls</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6226309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6226381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6226433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6226516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6226602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6226647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NormalizeLinkNetPidls</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6226763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6227356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6227414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6227508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6227605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6227677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6227730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6227816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6227863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6228007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: AppData</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6228146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6228259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6228431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: AppData\Roaming</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6228561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6228669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6228774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6228877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6228980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6229085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6229187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6229293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6229395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6229500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6229603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6229705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6229808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6229910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6230013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6230118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6230257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6230320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6230409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6231318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6231390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6231515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6231567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6231645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6231739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6231828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6231878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6231950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6232041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6232088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6232132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 60, Data: %USERPROFILE%\AppData\Roaming</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6232454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6233576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6233637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6233725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6233842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6233911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6233969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6234055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6234100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Data</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6234266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Data</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 370, Data: D6 0D 00 00 0D F0 AD BA 41 00 00 00 08 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6234415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6234487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6234698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6234831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6234933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6235005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6235061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6235138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6235183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6235319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6235892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 11876</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6236078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6236136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6236219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6236316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6236380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6236435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6236515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6236563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6236704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6236787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6236856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6236928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6236975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6237053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Drive\shellex\FolderExtensions</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6237155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6237255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6237311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6237377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6237474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Drive\shellex\FolderExtensions</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6237546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: {fbeb8a05-beee-4442-804e-409d6c4515e9}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6237624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6237682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6237746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6237795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6237862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6237945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6238023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6238064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6238125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6238211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6238272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 32</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6238424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6238496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 1, Length: 288</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6238557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\Drive\shellex\FolderExtensions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6238807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6238862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6238951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Explorer</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6239034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6239136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6239183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6239256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Explorer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6239497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6239763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryRemoteProtocolInformation</Operation>
<Path>C:\</Path>
<Result>INVALID PARAMETER</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6239865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail>Filter: Users, 1: Users</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6240070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6241597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>NAME COLLISION</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6244531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6244750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: DACL</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6244838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6245797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6245971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>SUCCESS</Result>
<Detail>Information: DACL</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6246043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6247196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\cversions.1.db</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6247528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\cversions.1.db</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6247686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6248612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6248814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6249110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6249967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6250141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6250878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\cversions.1.db</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 16 384, EndOfFile: 16 384, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6251036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\cversions.1.db</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6251299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\cversions.1.db</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6252831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6253053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 135 168, EndOfFile: 134 416, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6253247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6253372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6254255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6255513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6255818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6256716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6256890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6257588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 135 168, EndOfFile: 134 416, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6257741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6257985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6259844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6260057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 176, EndOfFile: 174, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6260162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 174, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6260550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:47:50, LastAccessTime: 16.07.2016 14:45:35, LastWriteTime: 16.07.2016 14:45:35, ChangeTime: 19.07.2018 19:43:16, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6260650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6264551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6264770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryRemoteProtocolInformation</Operation>
<Path>C:\Users</Path>
<Result>INVALID PARAMETER</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6264867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>Filter: User, 1: User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6265036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6266194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6266396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryRemoteProtocolInformation</Operation>
<Path>C:\Users\User</Path>
<Result>INVALID PARAMETER</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6266482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail>Filter: AppData, 1: AppData</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6266645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6267748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6267950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryRemoteProtocolInformation</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>INVALID PARAMETER</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6268036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData\Roaming</Path>
<Result>SUCCESS</Result>
<Detail>Filter: Roaming, 1: Roaming</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6268180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6268563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6268635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6268756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6268895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6268978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6269036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6269142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6269200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6269377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: Desktop</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6269524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6269646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6269757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: Desktop</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6269887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6269998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6270108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21769</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6270239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-183</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6270369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6270480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6270588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6270696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6270804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6270923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6271048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6271159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6271280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6271388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6271510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6271621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6271771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6271840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6271945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6272148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6272206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6272314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6272366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6272450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6272549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6272646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6272696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6272771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6272943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6272993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6273037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 44, Data: %USERPROFILE%\Desktop</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6273306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6274904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Desktop\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6275140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Desktop\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 288, EndOfFile: 282, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6275245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Desktop\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 282, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6334216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6334394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Properties</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6334746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6334959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6335056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Properties</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6335375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6335746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Desktop\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:13, LastAccessTime: 19.07.2018 20:08:13, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6335859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Desktop\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6336632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6336704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6336826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6336968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6337051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6337112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6337214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6337278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6337447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Libraries</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6337597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6337735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6337849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 56, Data: Microsoft\Windows\Libraries</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6337982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6338092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6338203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6338311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6338419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6338525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6338636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6338741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6338849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6338957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6339156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6339267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6339392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6339500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6339608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6339713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6339863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6339929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6340035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6340256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6340317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6340436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6340489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6340561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6340664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6340763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6340813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6340888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6340979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6341027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6341076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6341384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6341448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6341545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6341597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6341667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6341711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 60, Data: %USERPROFILE%\AppData\Roaming</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6342204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6342647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6342708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6342814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6342916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6342985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6343041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6343124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6343176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6343326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: Local Documents</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6343467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6343584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6343692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Documents</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6343822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6343933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{d3162b92-9365-467a-956b-92703aca08af}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6344063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6344174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21770</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6344304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-112</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6344434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6344545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6344650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6344758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6344936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6345041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6345166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6345271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6345376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6345482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6345603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6345709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6345853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6345917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6346011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6346171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6346230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6346321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6346374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6346446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6346537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6346623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6346673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6346745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6346828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6346872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6346919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{F42EE2D3-909F-4907-8871-4C22FC0BF756}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6347149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6347202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6347299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6347388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6347454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6347507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6347590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6347637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6347773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: Profile</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6347911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6348025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6348130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6348236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6348341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6348446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6348551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6348657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6348759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6348867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6348972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6349078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6349180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6349286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6349391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6349496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6349599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6349704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6349809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6349948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6350011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6350103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6350236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6350288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6350377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6350482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6350554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6350596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6350751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6350890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6350976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6352713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Documents\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6352976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Documents\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 408, EndOfFile: 402, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6353084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Documents\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 402, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6353563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Documents\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:14, LastAccessTime: 19.07.2018 20:08:14, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6353666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Documents\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6354165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6354228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6354347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6354455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6354527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6354588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6354691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6354749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6354910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 24, Data: Local Music</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6355054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6355173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6355284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 12, Data: Music</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6355414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6355525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{3dfdf296-dbec-4fb4-81d1-6a3438bcf4de}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6355652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12689</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6355791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21790</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6355924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-108</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6356054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6356165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6356273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6356378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6356486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6356594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6356716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6356824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6356932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6357038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6357159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6357268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6357417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6357486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6357586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6357755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6357813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6357913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6357963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6358038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6358132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6358223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6358273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6358348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6358431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6358478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6358525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{A0C69A99-21C8-4671-8703-7934162FCF1D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6358775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6358830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6358930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6359019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6359085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6359127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6359276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6359415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6359501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6360822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Music\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6361044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Music\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 504, EndOfFile: 504, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6361149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Music\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 504, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6361850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Music\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:14, LastAccessTime: 19.07.2018 20:08:14, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6361983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Music\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6362496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6362562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6362678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6362786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6362861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6362919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6363022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6363080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6363244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 30, Data: Local Pictures</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6363390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6363510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6363620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: Pictures</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6363748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6363861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{24ad3ad4-a569-4530-98e1-ab02f9417aa8}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6363994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12688</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6364127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21779</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6364258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-113</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6364435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6364546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6364657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6364762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6364867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6364975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6365097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6365205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6365310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6365419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6365540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6365646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6365793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6365862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6365959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6366125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6366186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6366283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6366333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6366408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6366502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6366590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6366640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6366712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6366798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6366845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6366895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{0DDD015D-B06C-45D5-8C4C-F59713854639}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6367158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6367214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6367311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6367402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6367469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6367513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6367660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6367798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6367882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6369242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Pictures\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6369475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Pictures\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 504, EndOfFile: 504, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6369580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Pictures\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 504, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6370034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Pictures\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:13, LastAccessTime: 19.07.2018 20:08:13, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6370134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Pictures\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6370647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6370710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6370827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6370935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6371010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6371068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6371292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6371417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6371650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 26, Data: Local Videos</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6371813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6371935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6372046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 14, Data: Videos</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6372179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6372350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{f86fa3ab-70d2-4fc7-9c99-fcbf05467f3a}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6372483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\InfoTip</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-12690</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6372619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21791</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6372752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-189</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6372880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6372993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6373099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6373207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6373315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6373423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6373545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6373653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6373761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6373869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6373985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6374151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6374301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6374370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6374481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6374653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6374711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6374808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6374861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6374938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6375032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6375127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6375174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6375251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6375337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6375387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6375434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6375689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6375742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6375841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6375930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6375999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6376046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6376188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6376326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6376420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6377756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Videos\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6377980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Videos\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 504, EndOfFile: 504, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6378086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Videos\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 504, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6378529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Videos\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:09, LastAccessTime: 19.07.2018 20:08:09, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6378629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Videos\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6379116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6379180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6379296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6379407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6379482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6379540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6379643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6379698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6379859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: Local Downloads</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6380006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6380125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6380235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Downloads</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6380366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\ParsingName</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6380477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 176, Data: shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{088e3905-0323-4b02-9826-5d99428e115f}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6380607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6380718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21798</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6380851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 80, Data: %SystemRoot%\system32\imageres.dll,-184</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6381111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6381238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6381349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6381460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6381568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6381673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6381795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6381964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6382078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6382183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6382302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6382410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6382560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6382629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6382743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6382912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6382970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6383064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6383117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6383192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6383283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6383375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6383424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6383499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6383585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6383629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6383682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6383942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6383998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6384098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6384184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6384250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6384294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6384441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6384582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6384666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6386020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Downloads\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6386248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\Downloads\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 288, EndOfFile: 282, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6386350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\Downloads\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 282, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6386760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Downloads\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:08:15, LastAccessTime: 19.07.2018 20:08:15, LastWriteTime: 20.07.2018 19:29:33, ChangeTime: 20.07.2018 19:29:33, FileAttributes: HSA</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6386860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Downloads\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6387389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6387453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6387569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6387680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6387755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6387813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6387907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6387960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6388123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: OneDrive</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6388265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\ParentFolder</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {5E6C858F-0E22-4760-9AFE-EA3317B67173}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6388398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6388511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\RelativePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 18, Data: OneDrive</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6388639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 94, Data: shell:::{018D5C66-4533-4307-9B53-224DE2ED1FE6}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6388774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6388885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 98, Data: @%SystemRoot%\System32\SettingSyncCore.dll,-1024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6389015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Icon</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 82, Data: %SystemRoot%\system32\imageres.dll,-1040</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6389146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6389256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6389364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6389473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\LocalRedirectOnly</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6389594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6389702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6389811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6389916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6390027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\DefinitionFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 64</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6390143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6390265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6390373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6390517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6390581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6390678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6391035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6391102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6391207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6391257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6391332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6391429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6391520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6391567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6391642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6391725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6391772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6391822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6392082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6392138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6392235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6392323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6392387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6392431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6392576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000\ProfileImagePath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 28, Data: C:\Users\User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6392717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3477790013-1571897634-1299942168-1000</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6392800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6394080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\OneDrive\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6394304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\OneDrive\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 96, EndOfFile: 95, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6394404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\OneDrive\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 95, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6394792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\OneDrive\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:26:50, LastAccessTime: 19.07.2018 20:26:50, LastWriteTime: 23.08.2018 20:16:07, ChangeTime: 23.08.2018 20:16:07, FileAttributes: HS</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6394892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\OneDrive\desktop.ini</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6395390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6395457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6395571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6395679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6395751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6395809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6395903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6395958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6396116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 34, Data: MyComputerFolder</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6396258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6396377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6396488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6396596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\ParsingName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 82, Data: ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6396723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6396834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6396939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6397047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6397153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6397261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6397366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6397471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6397579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6439473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6439642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6439886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6440091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6440257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6440373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6440545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6440634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\PropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6440761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6578948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 7688</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6598880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6598982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6599118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6599309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6599395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6599459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6599578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6599644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}\Data</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6599802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}\Data</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 370, Data: D6 0D 00 00 0D F0 AD BA 01 00 00 00 08 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6599971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6600052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6600104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6600190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6600284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6600345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6600401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6600476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6600523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6600670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-100000000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6601551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6601612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6601700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6601797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6601858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6601914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6601997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6602047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Data</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6602216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Data</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 370, Data: D6 0D 00 00 0D F0 AD BA 41 00 00 00 08 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6602365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6602434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6602484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6602565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6602651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6602711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6602764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6602833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6602872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6603119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6604155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6604216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6625943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6626125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6626228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6626295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6626408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6626472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}\Data</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6626638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}\Data</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 3 542, Data: D6 0D 00 00 00 00 00 00 01 00 00 00 10 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6626799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6626882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6626937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6627029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6627120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6627181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6627236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6627311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6627356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6627494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{24d09a14-8b74-11e8-8e46-806e6f6e6963}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6628256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6628328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6628420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6628519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6628586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6628641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6628722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6628771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6668346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6670637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 622 464, Length: 32 768, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6766823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6766986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6767094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6767155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6767322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6767557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6767723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6767779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6767865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6767992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6768086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6768144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6768233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6768305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6768361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6768452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6768530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 70, Data: Property System Both Class Factory</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6768602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6768657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6768740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6768807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 70, Data: Property System Both Class Factory</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6768865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6768920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6769009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6769089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6769142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6769228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6769286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6769369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6769433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6769591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6769660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6769760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6769840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\system32\propsys.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6769904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6769959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6770045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6770106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\system32\propsys.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6770197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6770292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6770378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6770441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\system32\propsys.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6770519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6770574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6770655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6770718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Both</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6770909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6770965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6771031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6771137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6771236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6771292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6771561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6771666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6771824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6771971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6772034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6772134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6772334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6772397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6772467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6772516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6772602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6772696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6772782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6772827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6772885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6772976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6773057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6773109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6773187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6775608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Desktop\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6776614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6776730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6776794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6776863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6776938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6776985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6777961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\419</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\419</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\19</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\19</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6778933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6779953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6780005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6780066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6780122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6780196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6780257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 60, Data: C:\Windows\SysWOW64\wshom.ocx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6780327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6780382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6780421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6780460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6780498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6782690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6782756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6782870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6783025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6783081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: DelegateFolders</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6783164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6783227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6783297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6783341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6783413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6783527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6783687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6783759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6783812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6783878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6783984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: {031E4825-7B94-4dc3-B131-E946B44C8DD5}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 2, Name: {04731B67-D933-450a-90E6-4ACD2E9408FE}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 3, Name: {0875DCB6-C686-4243-9432-ADCCF0B9F2D7}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 4, Name: {11016101-E366-4D22-BC06-4ADA335C892B}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 5, Name: {12F0008F-2113-482A-80B3-FD5E91C12313}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 6, Name: {138508bc-1e03-49ea-9c8f-ea9e1d05d65d}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 7, Name: {26EE0668-A00A-44D7-9371-BEB064C98683}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6784987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 8, Name: {4336a54d-038b-4685-ab02-99bb52d3fb8b}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 9, Name: {450D8FBA-AD25-11D0-98A8-0800361B1103}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 10, Name: {5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 11, Name: {59031a47-3f72-44a7-89c5-5595fe6b30ee}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 12, Name: {5b934b42-522b-4c34-bbfe-37a3ef7b9c90}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 13, Name: {645FF040-5081-101B-9F08-00AA002F954E}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 14, Name: {64693913-1c21-4f30-a98f-4e52906d3b56}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 15, Name: {89D83576-6BD1-4c86-9454-BEB04E94C819}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 16, Name: {9343812e-1c37-4a49-a12e-4b2d810d956b}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 17, Name: {98F275B4-4FFF-11E0-89E2-7B86DFD72085}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 18, Name: {a00ee528-ebd9-48b8-944a-8942113d46ac}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 19, Name: {B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 20, Name: {BD7A2E7B-21CB-41b2-A086-B309680C6B7E}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 21, Name: {daf95313-e44d-46af-be1b-cbacea2c3065}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 22, Name: {e345f35f-9397-435c-8f95-4e922c26259e}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 23, Name: {ED228FDF-9EA8-4870-83b1-96b02CFE0D52}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 24, Name: {EDC978D6-4D53-4b2f-A265-5805674BE568}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 25, Name: {F02C1A0D-BE21-4350-88B0-7367FC96EF3C}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6785926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 26, Length: 288</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6786120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6786208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6786281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x100</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6786336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6786414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6786502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6786555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6790752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6790902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6790966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx\AllowDevelopmentWithoutDevLicense</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 65535</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6791312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6791431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6791606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6791661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock\AllowDevelopmentWithoutDevLicense</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 24</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6791816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6793717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6793805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6793886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6793938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6794030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AppID\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6794152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AppID\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6794246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6794323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6794376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\AppID\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6794443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\AppID\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6794531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6794578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6794656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\OLE\AppCompat</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6794739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\AppCompat</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6794819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\AppCompat</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6794869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\AppCompat\RaiseDefaultAuthnLevel</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6795024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\AppCompat</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6795096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6795149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6795232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6795304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6795362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6795412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\DefaultAccessPermission</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6798349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rpcss.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6800890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6802361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6802472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6802569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\AnonymousAppContainerImpersonationLevelCheck</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 80</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6802685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6802751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6802815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6802873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa\EveryoneIncludesAnonymous</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6802970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Lsa</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6803998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6804084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6804162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6804217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6804320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6804453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6804555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6804602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6804671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6804780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6804868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6804924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6805004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6805065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6805154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6805226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {00000320-0000-0000-C000-000000000046}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6805309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6805353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6805528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6805600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6805669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x100</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6805724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6805791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6805860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6805904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6808240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 3256</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6809528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 8664</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6810254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 11880</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6810570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6810789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6810886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6810939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6811052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6811182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6811290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6811343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6811407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6811518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}\ProxyStubClsid32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6811606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6811662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6811750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6811811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6811897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}\ProxyStubClsid32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6811966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}\ProxyStubClsid32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6812052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6812102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{CD17328B-E4EF-4215-A92D-62A914658F82}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6812196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6812255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6812321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6812368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6812454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6812573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6812662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6812703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6812767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6812859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6812953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: PSFactoryBuffer</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: PSFactoryBuffer</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6813945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\ActXPrxy.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\ActXPrxy.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6814972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6815056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6815117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Both</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6815269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6815319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6815382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6815485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6815585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6815637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6815707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6815759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6815845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6815923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6815973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6816951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6819619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6819943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:30, LastAccessTime: 20.07.2018 1:33:30, LastWriteTime: 02.03.2018 11:14:37, ChangeTime: 20.07.2018 19:25:48, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6820040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6821469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6821832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6822012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6822960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6823157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6823459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6824301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6824473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6825235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6825814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x67500000, Image Size: 0x186000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6826656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6827814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6828094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6828180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6828249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\actxprxy.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6832693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6832790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Notify, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6833743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6833843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6833904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6834003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6834117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6834172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: {018D5C66-4533-4307-9B53-224DE2ED1FE6}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6834258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 1, Length: 288</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6834386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6834452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Notify, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6834884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6834993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6835048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6835150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6835270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6835314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: {F5FB2C77-0E2F-4A16-A381-3E560C68BC83}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6835394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 1, Length: 288</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6835505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6835563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Notify, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6836073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6836142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6836198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6836281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6836425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6836480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6836583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6836635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\Desktop\NameSpace</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6836721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6836771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\Desktop\NameSpace\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6836838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6836926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6836973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6837062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6837145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6837198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders\StorageDelegateSuppressionPolicy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6837350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6837414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6837467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6837553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6837636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6837680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders\StorageDelegate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6837805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6837902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6837971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6838040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6838087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6838181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6838309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6838489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6838542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6838603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6838708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6838780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6838902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6838971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6839076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6839157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6839270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6839337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6839436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6839514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6839625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6839869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6839982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6840065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 513</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6840218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6840315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6840367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6840448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6840561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6840606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6840694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6840800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6840847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6840913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6841002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6841049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6841124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6841196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6841265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6841309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{208D2C60-3AEA-1069-A2D7-08002B30309D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6841453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6841534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6841600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6841667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6841714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6841805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6841919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6842074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6842118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6842179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6842274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6842340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 36</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6842473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6842542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6842642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6842720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6842830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6842897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6842994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6843071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6843180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6843243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6843340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6843415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 131602</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6843551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6843637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6843687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6843767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6843897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6843941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1048576</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6844077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6844146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6844199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6844274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6844374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6844418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6844498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6844568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6844629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6844670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{871C5380-42A0-1069-A2EA-08002B30309D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6844798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6844872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6844939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6845005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6845052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6845141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6845249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6845388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6845432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6845496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6845587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6845654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 4, Data: 40 01 00 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6845781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6845848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6845950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6846028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6846136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6846199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6846299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6846374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6846482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6846546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6846643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6846718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6846851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6846934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6846986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{645FF040-5081-101B-9F08-00AA002F954E}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6847989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6848061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6848125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6848191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6848239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6848324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6848433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6848565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6848610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6848674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6848765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6848831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2684354564</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6848959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6849025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6849125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6849203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6849314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6849377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6849652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6849762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6849984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6850070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6850172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6850250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4609</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6850389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6850480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6850530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6850610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6850713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6850760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6850843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6850934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6850979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{26EE0668-A00A-44D7-9371-BEB064C98683}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6851984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6852073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6852117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6852184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6852278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6852345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4035182893</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6852472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6852541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6852641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6852719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6852829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6852890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6852990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6853068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6853176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6853242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6853342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6853417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 5243433</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6853552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6853638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6853688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6853766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6854223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6854301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6854395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6854506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6854553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6854619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6854705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6854749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6854821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6854882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6854946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6854990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{59031A47-3F72-44A7-89C5-5595FE6B30EE}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6855121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6855195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6855259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6855328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6855376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6855461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6855569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6855725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6855769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6855827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6855919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6855985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2961178893</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6856112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6856179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6856279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6856359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6856467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6856534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6856633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6856708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6856819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6856883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6856980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6857057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 270880</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6857185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6857271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6857323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6857401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6857501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6857545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6857628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6857719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6857767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6857830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6857911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6857955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{031E4825-7B94-4DC3-B131-E946B44C8DD5}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6858999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6859094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6859249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 538443776</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6859501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6859570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6859675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6859759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6859872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6859939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6860038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6860116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6860227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6860293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6860393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6860468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6860604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{04731B67-D933-450a-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6860689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6860739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6860817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6860922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6860969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{04731B67-D933-450A-90E6-4ACD2E9408FE}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6861953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6862000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6862089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6862197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6862355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6862413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6862490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6862601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6862681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 538443776</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6862834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6862914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6863033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6863128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6863258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6863335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6863454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6863540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6863662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6863743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6863862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6863950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\FolderValueFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6864114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6864189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6864294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6864377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\WantsFORDISPLAY</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6864491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6864557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6864657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6864734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\HideFolderVerbs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6864843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6864906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6865006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6865081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\UseDropHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6865186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6865250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6865350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6865427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\WantsFORPARSING</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 2, Data: </Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6865549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6865613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6865712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6865787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\WantsParseDisplayName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6865895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6865962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6866059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6866136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\QueryForOverlay</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6866242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6866305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6866402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6866480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\MapNetDriveVerbs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6866582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6866646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6866743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6866821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\QueryForInfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6866923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6866990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6867087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6867161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\HideOnDesktopPerUser</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6867270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6867333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6867430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6867505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\WantsAliasedNotifications</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6867613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6867677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6867774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6867851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\WantsUniversalDelegate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6867954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6868018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6868117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6868192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\NoFileFolderJunction</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6868297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6868361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6868458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6868533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\PinToNameSpaceTree</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6868716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6868779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6868879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6869292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\HasNavigationEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6869439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6869522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6869655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6869752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\EnableThumbnails</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6869882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6869965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6870090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6870187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\NoDefaultToFS</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6870314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6870398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6870522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6870619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\ParseDisplayNameNeedsURL</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6870749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6870835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6870965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6871062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\BlockNewFile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6871195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6871279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6871414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6871520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\NoInitRequired</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6871661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6871755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6871891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6871991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\SafeRootForMTA</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6872104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6872171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6872270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6872345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\WantsSendToTarget</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6872456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6872520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6872614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6872692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\NoLocalizedNameInTarget</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6872822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6872919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6872971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6873052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6873160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6873207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6873290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6873390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6873437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6873503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6873584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6873628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6873700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6873764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6873830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6873875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6874008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6874085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6874152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6874224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6874271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6874359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6874473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6874625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6874670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6874733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6874822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6874891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 538443776</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6875027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6875094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6875193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6875271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6875385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6875448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6875548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6875626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6875734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6875797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6875894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6875969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6876108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6876194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6876246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6876321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6876429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6876473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6876554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6876651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6876695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6876764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6876842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6876889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6876958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6877022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6877083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6877127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{11016101-E366-4D22-BC06-4ADA335C892B}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6877255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6877327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6877396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6877462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6877510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6877595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6877706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6877848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6877889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6877953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6878041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6878105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 4, Data: 00 00 10 A0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6878235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6878299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6878399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6878476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6878585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6878648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6878920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6879031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6879155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6879219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6879321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6879399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\FolderValueFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6879510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6879574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6879673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6879748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\WantsFORDISPLAY</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6879856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6879920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6880017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6880094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\HideFolderVerbs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6880197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6880261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6880358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6880435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\UseDropHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6880538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6880604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6880701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6880776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\WantsFORPARSING</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6880881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6880945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6881039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6881114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\WantsParseDisplayName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6881219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6881286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6881380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6881455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\QueryForOverlay</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6881560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6881624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6881724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6881798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\MapNetDriveVerbs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6881906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6881970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6882064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6882142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\QueryForInfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6882247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6882311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6882408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6882485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\HideOnDesktopPerUser</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6882591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6882654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6882751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6882829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\WantsAliasedNotifications</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6882934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6882998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6883095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6883170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\WantsUniversalDelegate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6883278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6883342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6883436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6883513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\NoFileFolderJunction</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6883619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6883682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6883779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6883854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\PinToNameSpaceTree</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6883957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6884020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6884117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6884192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\HasNavigationEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6884297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6884361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6884455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6884530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\EnableThumbnails</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6884635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6884699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6884796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6884871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\NoDefaultToFS</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6884976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6885040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6885137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6885212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\ParseDisplayNameNeedsURL</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6885317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6885381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6885478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6885552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\BlockNewFile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6885658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6885721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6885818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6885893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\NoInitRequired</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6885999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6886062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6886159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6886234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\SafeRootForMTA</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6886339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6886403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6886497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6886572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\WantsSendToTarget</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6886680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6886744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6886841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6886916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder\NoLocalizedNameInTarget</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{12F0008F-2113-482A-80B3-FD5E91C12313}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6887955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6888015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6888063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{12F0008F-2113-482A-80B3-FD5E91C12313}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6888190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6888265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6888329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6888395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6888445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6888534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6888642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6888946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6889027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6889124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6889271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6889384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 538181632</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6889592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6889689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6889833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6889944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6890110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6890213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6890373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6890492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6890645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6890711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6890819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6890902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\FolderValueFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6891013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6891077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6891174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6891252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\WantsFORDISPLAY</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6891357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6891423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6891520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6891595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\HideFolderVerbs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6891700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6891764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6891861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6891939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\UseDropHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6892044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6892108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6892205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6892282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\WantsFORPARSING</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6892387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6892454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6892551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6892623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\WantsParseDisplayName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6892728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6892792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6892889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6892964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\QueryForOverlay</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6893072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6893135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6893232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6893304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\MapNetDriveVerbs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6893410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6893474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6893568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6893643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\QueryForInfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6896383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6896457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6896577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6896662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\HideOnDesktopPerUser</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6896779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6896845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6896942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6897023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\WantsAliasedNotifications</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6897131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6897194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6897289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6897366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\WantsUniversalDelegate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6897474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6897535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6897632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6897707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\NoFileFolderJunction</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6897812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6897876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6897973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6898048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\PinToNameSpaceTree</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6898153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6898217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6898316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6898391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\HasNavigationEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6898616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6898740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6898895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6899012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\EnableThumbnails</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6899161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6899228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6899333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6899414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\NoDefaultToFS</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6899524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6899585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6899685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6899760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\ParseDisplayNameNeedsURL</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6899865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6899929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6900026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6900101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\BlockNewFile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6900206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6900270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6900364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6900439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\NoInitRequired</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6900544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6900605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6900705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6900779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\SafeRootForMTA</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6900957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6901021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6901117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6901192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\WantsSendToTarget</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6901298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6901361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6901458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6901533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder\NoLocalizedNameInTarget</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6901663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6901766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6901818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6901902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6902943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6903010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6903079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6903126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6903218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6903328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6903478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6903525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6903583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6903677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6903744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4036231437</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6903880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6903946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6904046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6904124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6904234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6904304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6904401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6904478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6904586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6904653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6904750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6904822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6904957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6905972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{4336A54D-038B-4685-AB02-99BB52D3FB8B}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6906102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6906177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6906240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6906310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6906357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6906442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6906553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6906686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6906731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6906792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6906883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6906950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4035969341</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6907080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6907146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6907243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6907324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\CallForAttributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 131136</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6907443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6907506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6907603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6907681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6907786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6907853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6907950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6908024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 524840</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6908157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6908241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6908440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6908579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6908742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6908811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6908911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{450D8FBA-AD25-11D0-98A8-0800361B1103}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6909994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6910102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6910244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6910288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6910349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6910446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6910512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 32</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6910643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6910706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6910809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6910889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6910997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6911061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6911161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6911236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6911341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6911407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6911504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6911579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6911709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6911795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6911845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6911923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6912981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6913050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6913097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6913186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{5B934B42-522B-4C34-BBFE-37A3EF7B9C90}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6913297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5B934B42-522B-4C34-BBFE-37A3EF7B9C90}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6913427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6913471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6913532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6913624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6913690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4035969285</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6913820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6913887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6913984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6914064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6914172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6914236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6914333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6914408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6914516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6914580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6914677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6914751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 5242920</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6914884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6914968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{5B934B42-522B-4C34-BBFE-37A3EF7B9C90}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{5B934B42-522B-4C34-BBFE-37A3EF7B9C90}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6915882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{5B934B42-522B-4C34-BBFE-37A3EF7B9C90}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6916006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6916079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6916145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6916214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6916261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6916347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{64693913-1C21-4F30-A98F-4E52906D3B56}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6916455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1C21-4F30-A98F-4E52906D3B56}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6916577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6916622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6916680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6916771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6916838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 537919488</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6916965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6917032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6917129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6917209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6917317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6917383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6917480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6917555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6917663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6917730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6917827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6917902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6918134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{64693913-1c21-4f30-a98f-4e52906d3b56}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6918231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6918284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6918364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{64693913-1C21-4F30-A98F-4E52906D3B56}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6918467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6918511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6918591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{64693913-1C21-4F30-A98F-4E52906D3B56}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6918686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6918730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6918796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6918877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6918921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6918993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6919054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6919112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6919157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{64693913-1C21-4F30-A98F-4E52906D3B56}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6919284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6919356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6919420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6919489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6919536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6919622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6919736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6919871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6919913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6919974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6920065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6920132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 538181632</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6920265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6920331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6920428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6920506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6920614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6920678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6920775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6920852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6921007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6921071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6921171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6921248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6921379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{89D83576-6BD1-4c86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6921464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6921514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6921592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6921692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6921736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6921816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6921908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6921955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{89D83576-6BD1-4C86-9454-BEB04E94C819}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6922944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6923074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6923118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6923177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6923268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6923335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 538181632</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6923459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6923526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6923626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6923700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6923808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6923875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6923972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6924047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6924155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6924218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6924318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6924390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6924520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9343812e-1c37-4a49-a12e-4b2d810d956b}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6924604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6924653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6924731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6924831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6924875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6924958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{9343812E-1C37-4A49-A12E-4B2D810D956B}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6925978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6926091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6926230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6926274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6926332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6926424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6926490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 538443776</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6926618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6926684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6926784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6926864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6926970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6927036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6927133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6927208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6927313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6927377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6927474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6927551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6927737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6927931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6927984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{98F275B4-4FFF-11E0-89E2-7B86DFD72085}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6928984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6929059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6929122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6929192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6929236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6929322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{A00EE528-EBD9-48B8-944A-8942113D46AC}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6929433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{A00EE528-EBD9-48B8-944A-8942113D46AC}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6929568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6929610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6929668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6929762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6929829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 538443776</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6929953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6930020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6930120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6930197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6930303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6930369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6930466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6930544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6930649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6930713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6930812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6930887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{a00ee528-ebd9-48b8-944a-8942113d46ac}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{A00EE528-EBD9-48B8-944A-8942113D46AC}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{A00EE528-EBD9-48B8-944A-8942113D46AC}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6931973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6932015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{A00EE528-EBD9-48B8-944A-8942113D46AC}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6932139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6932211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6932272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6932342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6932389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6932475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6932586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6932716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6932760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6932821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6932912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6932979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2961441036</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6933153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6933220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6933320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6933397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder\CallForAttributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1048576</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6933519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6933583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6933680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6933757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6933863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6933926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 270880</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6934999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6935071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6935132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6935190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6935231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6935356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6935428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6935492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6935558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6935608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6935694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6935802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6935932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6935977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6936038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6936126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6936190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 538181632</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6936317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6936381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6936481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6936556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6936664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6936727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6936824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6936899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6937005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6937068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6937168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6937240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6937367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6937453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6937586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6937692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6937797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6937844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6937927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6938961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6939088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6939265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6939307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6939371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6939465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6939531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 538443776</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6939659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6939725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6939828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6939905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6940011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6940077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6940174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6940252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6940357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6940421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6940518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6940595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6940725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{daf95313-e44d-46af-be1b-cbacea2c3065}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6940811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6940861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6940939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6941983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6942050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6942100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6942185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6942294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6942438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6942482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6942543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6942632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6942701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 538443776</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6942828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6942895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6942992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6943072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6943183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6943247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6943344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6943421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6943524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6943590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6943687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6943765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6943892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{e345f35f-9397-435c-8f95-4e922c26259e}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6943978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6944890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{E345F35F-9397-435C-8F95-4E922C26259E}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6945011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6945084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6945147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6945216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6945264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6945352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6945460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6945554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6945596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6945657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6945743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6945812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 537919792</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6945940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6946006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6946103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6946183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6946291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6946355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6946452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6946530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6946632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6946699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6946796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6946873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6947004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6947247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6947303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6947383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6947488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6947533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6947616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6947710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6947754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6947821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6947898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6947943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{EDC978D6-4D53-4B2F-A265-5805674BE568}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4B2F-A265-5805674BE568}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6948987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6949079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6949148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 537919488</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6949273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6949339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6949439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6949516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6949624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6949688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6949788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6949863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6949968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6950032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6950129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6950206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6950336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{EDC978D6-4D53-4b2f-A265-5805674BE568}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6950420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6950469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6950544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{EDC978D6-4D53-4B2F-A265-5805674BE568}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6950644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6950688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6950769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{EDC978D6-4D53-4B2F-A265-5805674BE568}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6950863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6950907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6950974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6951051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6951096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6951168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6951226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6951284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6951326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{EDC978D6-4D53-4B2F-A265-5805674BE568}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6951450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6951522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6951586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6951653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6951700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6951785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6951891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6952021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6952065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6952123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6952212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6952281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2953052260</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6952406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6952473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6952570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6952647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6952755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6952819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6952916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6952991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6953096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6953160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6953259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6953334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1057344</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6953464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6953550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6953600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6953675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6953780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6953825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6953905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6953999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6954922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6955052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6955096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6955157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6955232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6955326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 4034920525</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6955462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6955529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6955612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6955698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6955808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6955875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6955955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6956038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6956144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6956207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6956288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6956371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6956498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6956584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6956634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6956709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6956806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6956853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6956933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6957108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6957230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6957329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6957437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6957482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6957557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6957626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6957690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6957734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{018D5C66-4533-4307-9B53-224DE2ED1FE6}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6957864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6957944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6958008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6958080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6958125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6958213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6958316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6958454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6958499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6958560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6958654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6958717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2952790016</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6958850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6958917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6959017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6959089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder\CallForAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6959197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6959263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6959360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6959429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder\RestrictedAttributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6959532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6959596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6959695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6959765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder\FolderValueFlags</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1040</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6959895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6959981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\ShellFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6960895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6961017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6961560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6961627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6961693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6961743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6961834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6961937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6962037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6962086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6962150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6962242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6962308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {20D04FE0-3AEA-1069-A2D8-08002B30309D}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6962538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6962605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6962671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6962718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6962804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6962912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6963020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6963062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6963120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6963206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6963281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6963369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6963425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6963505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6963571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32\LoadWithoutCOM</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6963702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6963862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6963926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6963995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6964984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: This PC</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: This PC</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6965954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6966021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6966120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6966195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6966251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6966306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6966386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6966447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6966514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6966566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6966650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6966710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: %SystemRoot%\system32\windows.storage.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6966769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6966943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6967054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6967134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: Apartment</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6967292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6967339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6967406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6967506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6967603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6967658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6967722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6967774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6967855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6967932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6967982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6968057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6968268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6968326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6968389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6968437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6968517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6968611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6968686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6968730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6968786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6968872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6968952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6969005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6969071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6969320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6969367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6969451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6969545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6969592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\ValidateRegItems</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6969736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6969808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6969858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6969944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6970024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6970068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\MonitorRegistry</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6970190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6970334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6970406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6970575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6970675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6970728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6971013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6971085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6971185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6971265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag\HideNonRemovableDrives</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6971404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6971473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6971573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6971648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag\HideNonRemovableDrives</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6971853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6971922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6972019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6972091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag\AllowChildAliasRegistration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6972210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6972279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6972376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6972448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag\UseRemovableStorageRegPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6972562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6972631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6972728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6972800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag\UseRemovableDrivesRegPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6972928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6972994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6973091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6973163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag\UseRemovableDrivesRegPath</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6973327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6973376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6973462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\RemovableDrives</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6973570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6973615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6973687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\RemovableDrives</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6973762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6973825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6973917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6973986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag\NoDelegateSearchRoot</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6974102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6974172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6974269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6974343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag\HideNonStorageServiceMountedDrives</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6974460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6974529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6974626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6974698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag\ForceAllDrivesRemovable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6974812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6974881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6974978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6975050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag\ShowAllOpticalDevices</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6975188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6975236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{F5FB2C77-0E2F-4A16-A381-3E560C68BC83}\Instance\InitPropertyBag</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6975427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6975477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6975565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\RemovableDrives</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6975670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6975718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6975787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\RemovableDrives</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6975900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6975945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6976022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\RemovableDrives\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6976103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6976147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6976214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\RemovableDrives\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6976327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6976377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6976479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6976529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\MyComputer\RemovableDrives</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6976831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6976920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\MyComputer\RemovableDrives\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6977014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6977100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6977153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6977239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\RemovableDrives\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6977333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6977380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6977452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\RemovableDrives\DelegateFolders</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6977809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6977856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6977931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6978039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6978103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6978156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6978239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6978286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6978436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6978956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6979353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 9:04:24, LastAccessTime: 23.08.2018 15:22:34, LastWriteTime: 23.08.2018 15:22:34, ChangeTime: 23.08.2018 15:22:34, FileAttributes: HSD</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6979444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6982018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6982198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:11, LastWriteTime: 24.08.2018 12:38:31, ChangeTime: 24.08.2018 12:38:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6982276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6984159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6984268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6984392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6984514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6984572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6984647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6984750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6984797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6984863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6984955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6985002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6985174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6985226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6985312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6985384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6985476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6985567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6985614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6985683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6985766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6985814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6985877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6985958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6986005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6986190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6986254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6998547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Desktop\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6998738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Desktop\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:14, LastAccessTime: 24.08.2018 12:30:14, LastWriteTime: 24.08.2018 12:30:14, ChangeTime: 24.08.2018 12:30:14, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,6998827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Desktop\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7000162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7000420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7000583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7002149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7002315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7003243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7003429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7003722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7004556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7004725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7005116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7005216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7006413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7006590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7006856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7007690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7007853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7008122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7008258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7008582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 32 768, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7034783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7037385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Desktop\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7037543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\Desktop\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:14, LastAccessTime: 24.08.2018 12:30:14, LastWriteTime: 24.08.2018 12:30:14, ChangeTime: 24.08.2018 12:30:14, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7037620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Desktop\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7038612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\Desktop\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read/Write, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: A, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Overwritten</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7040305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7041189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7041372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7710944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\Desktop\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 972, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7711964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\Desktop\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7712160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7713305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7713507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7750519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7750593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7750707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\App Paths\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7750893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7750940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7751037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\MCLauncher.exe</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7751156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7752802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\windows.storage.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 495 488, Length: 32 768, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7762180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7762612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7763164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7763272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7763357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7763413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7763515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\wscript.shell</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7763648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\wscript.shell</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7763751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7763801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7763870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7763978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WScript.Shell\CLSID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7764058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7764114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7764194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7764255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7764335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WScript.Shell\CLSID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7764396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WScript.Shell\CLSID\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {72C24DD5-D70A-438B-8A42-98424B88AFB8}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7764493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7764543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7764951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\wscript.shell</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\wscript.shell</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WScript.Shell\CLSID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WScript.Shell\CLSID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WScript.Shell\CLSID\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {72C24DD5-D70A-438B-8A42-98424B88AFB8}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7765987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7766031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7766375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7766458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7766510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7766569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7766632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7766677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7766743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7766821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7766868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7766904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7766967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7767031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7767087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7767488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7767621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7767704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7767804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7767907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7767995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\419</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\419</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\19</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\19</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7768979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7769979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7770051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7770101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7770162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7770217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7770292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7770353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 60, Data: C:\Windows\SysWOW64\wshom.ocx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7770422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7771616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 64, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 248, Length: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 252, Length: 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 496, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 536, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 576, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 616, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 656, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 528, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 544, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 87 904, Length: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 552, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 87 888, Length: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 87 890, Length: 14</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7772991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 600, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7773054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 616, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7773124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 872, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7773179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 888, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7773240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 87 488, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7773304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 126 976, EndOfFile: 125 952, NumberOfLinks: 3, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7773415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7773578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7774517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7774711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7774999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7775844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7776016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7776645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 126 976, EndOfFile: 125 952, NumberOfLinks: 3, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7776792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7777340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7777435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7777485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7777523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7778922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7779945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7780914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\stdole2.tlb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7781984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7783073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7783419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 64, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7783560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 184, Length: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7783635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 188, Length: 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7783702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 432, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7783771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 472, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7783840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 024, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7783896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 040, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7783962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 272, Length: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7784020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 048, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7784084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 256, Length: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7784139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 258, Length: 14</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7784211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 088, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7784275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 104, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7784344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 160, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7784400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 176, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7784461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 224, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7784522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 20 480, EndOfFile: 18 432, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7784619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7784741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7785647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7785832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7786123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7787101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7787270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7787841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 20 480, EndOfFile: 18 432, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7787993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7788284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7788345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7788384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7788425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7790714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7791257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 976, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7791465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 976, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7920684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7921800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7922022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7922108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7922213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7922299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7922349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7922432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7922532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7922612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7922656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7922726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7922789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7922850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7922975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7923327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7923404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7923499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7923609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7923709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7923762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7923845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7923903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7923997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\419</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\419</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\19</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\19</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7924981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7925989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7926064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7926133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 60, Data: C:\Windows\SysWOW64\wshom.ocx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7926211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7926275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7926314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7926350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7926388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7928270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7928336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7928425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7928572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7928652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7928710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7928804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7928860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7929051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7929541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7929960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 9:04:24, LastAccessTime: 23.08.2018 15:22:34, LastWriteTime: 23.08.2018 15:22:34, ChangeTime: 23.08.2018 15:22:34, FileAttributes: HSD</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7930051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7932727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7933090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:11, LastWriteTime: 24.08.2018 12:38:31, ChangeTime: 24.08.2018 12:38:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7933171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7938606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7938800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:31, LastAccessTime: 24.08.2018 12:30:31, LastWriteTime: 24.08.2018 12:30:31, ChangeTime: 24.08.2018 12:30:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7938886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7940208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7940477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7940654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7941155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7941327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7942239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7942430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7942962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7943846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7944020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7944430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7944541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7945815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7945987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7946253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7947073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7947237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7947508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 17 244 160, EndOfFile: 17 240 149, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7947647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7948193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7950498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7950672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:31, LastAccessTime: 24.08.2018 12:30:31, LastWriteTime: 24.08.2018 12:30:31, ChangeTime: 24.08.2018 12:30:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7950750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7951811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read/Write, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: A, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Overwritten</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7954180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7955194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:33,7955379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7590214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 976, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7591139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MCLauncher.lnk</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7591973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7593447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7593661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7602781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7603380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7604125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7604277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7604397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7604480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7604610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\wscript.shell</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7604773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\wscript.shell</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7604901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7604959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7605034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7605158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WScript.Shell\CLSID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7605242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7605297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7605386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7605447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7605527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WScript.Shell\CLSID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7605588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WScript.Shell\CLSID\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {72C24DD5-D70A-438B-8A42-98424B88AFB8}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7605688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7605737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7606269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7606333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7606400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7606447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7606519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\wscript.shell</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7606602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\wscript.shell</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7606668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7606710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7606763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7606846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WScript.Shell\CLSID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7606918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7606970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7607034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7607087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7607159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WScript.Shell\CLSID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7607217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WScript.Shell\CLSID\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {72C24DD5-D70A-438B-8A42-98424B88AFB8}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7607286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WScript.Shell\CLSID</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7607328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WScript.Shell</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7607746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7607829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7607885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7607943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7608965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\419</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\419</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\19</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\19</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7609938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7610960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7611010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7611071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7611126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7611201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7611265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 60, Data: C:\Windows\SysWOW64\wshom.ocx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7611328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7612797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7613182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 64, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7613326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 248, Length: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7613395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 252, Length: 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7613465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 496, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7613548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 536, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7613606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 576, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7613661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 616, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7613717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 656, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7613786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 528, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7613844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 544, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7613911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 87 904, Length: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7613972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 552, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7614035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 87 888, Length: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7614091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 87 890, Length: 14</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7614166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 600, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7614229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 616, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7614296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 872, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7614351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 86 888, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7614412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 87 488, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7614476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 126 976, EndOfFile: 125 952, NumberOfLinks: 3, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7614589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7614742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7615689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7615881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7616171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7617019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7617191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7617831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 126 976, EndOfFile: 125 952, NumberOfLinks: 3, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7617986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7618291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7618355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7618393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7618435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7619937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7620981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7621045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7621136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7621219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7621269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7621341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7621402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7621485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7621560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7621610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7621682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7621743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7621823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7622084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7622178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7622330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7622389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7622436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7622499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7622596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7622682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7622732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7622801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7622857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7622937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7623012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7623062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7623126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7623181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7623259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7623322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\stdole2.tlb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7623394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7624511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7624868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 64, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 184, Length: 4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 188, Length: 20</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 432, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 472, Length: 40</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 024, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 040, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 272, Length: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 048, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 256, Length: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 258, Length: 14</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 088, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 104, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 160, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 176, Length: 8</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 224, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7625965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 20 480, EndOfFile: 18 432, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7626062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7626187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7627099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7627287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7627572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7628415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7628584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7629160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 20 480, EndOfFile: 18 432, NumberOfLinks: 2, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7629312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7629606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7629664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7629706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7629744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7632548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdater.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7633058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdater.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 910, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,7633288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdater.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 910, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8068127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdater.lnk</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8069103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8069291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8069366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8069452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8069529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8069576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8069660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8069759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8069834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8069878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8069950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8070014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8070075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8070191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8070297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8070347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8070419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8070513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8070599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8070649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8070726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8070784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8071064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\419</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8071217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8071308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\419</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8071419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8071496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8071588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\19</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8071663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8071713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\19</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8071773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8071826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8071904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8071973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8072990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8073062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8073112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8073178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8073236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8073314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8073378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 60, Data: C:\Windows\SysWOW64\wshom.ocx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8073452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8073513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8073552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8073591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8073627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\TypeLib</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8075392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8075450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8075544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8075686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8075760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8075818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8075915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8075971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}\Generation</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8076145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{110924bd-0000-0000-0000-501f00000000}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8076536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8076888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 9:04:24, LastAccessTime: 23.08.2018 15:22:34, LastWriteTime: 23.08.2018 15:22:34, ChangeTime: 23.08.2018 15:22:34, FileAttributes: HSD</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8076977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8079476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdate.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8084748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdater.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8084925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdater.lnk</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:31, LastAccessTime: 24.08.2018 12:30:31, LastWriteTime: 24.08.2018 12:30:31, ChangeTime: 24.08.2018 12:30:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8085008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdater.lnk</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8086244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdate.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8088402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdater.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8088552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdater.lnk</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:31, LastAccessTime: 24.08.2018 12:30:31, LastWriteTime: 24.08.2018 12:30:31, ChangeTime: 24.08.2018 12:30:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8088630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdater.lnk</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8089594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdater.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read/Write, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: A, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Overwritten</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8093528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdater.lnk</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 910, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8093949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLUpdater.lnk</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8094110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8095096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8095298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8167219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\stdole2.tlb</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8167638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\wshom.ocx</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8170746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8171203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8171289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8174168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8174437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:55, LastAccessTime: 16.07.2016 14:42:55, LastWriteTime: 16.07.2016 14:42:55, ChangeTime: 19.07.2018 19:37:26, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8174517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8175478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8175750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8175891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8176744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8176933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8177215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8178038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8178207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8179116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8179609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x73ff0000, Image Size: 0x4e000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8180909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8182122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8182402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8182480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8182552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\mswsock.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8183192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8183266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8183369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8183488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8183599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8183654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Parameters\Transports</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_MULTI_SZ, Length: 64, Data: vmbus, Psched, Tcpip, Tcpip6, irda</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8183834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Parameters\Transports</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_MULTI_SZ, Length: 64, Data: vmbus, Psched, Tcpip, Tcpip6, irda</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8183978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8184062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8184114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8184195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8184272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8184358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8184405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock\Mapping</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 44, Data: 03 00 00 00 03 00 00 00 22 00 00 00 01 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8184544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock\Mapping</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 44, Data: 03 00 00 00 03 00 00 00 22 00 00 00 01 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8184674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8184749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8184801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8184876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8184948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8185031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8185073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock\Mapping</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8185195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock\Mapping</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8185294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock\Mapping</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 152, Data: 0C 00 00 00 03 00 00 00 17 00 00 00 01 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8185419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8185486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8185538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8185610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8185682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8185757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8185824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8185876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Psched</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8185948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Psched\WinSock 2.0 Provider ID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: E0 A9 60 9D 7A 33 D0 11 BD 88 00 00 C0 82 E6 9A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8186084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Psched</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8186126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8186192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8186239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8186311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8186380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8186502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8186544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\Mapping</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 104, Data: 08 00 00 00 03 00 00 00 02 00 00 00 01 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8186671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\Mapping</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 104, Data: 08 00 00 00 03 00 00 00 02 00 00 00 01 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8186796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8186885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8186935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Tcpip</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Tcpip\WinSock 2.0 Provider ID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: A0 1A 0F E7 8B AB CF 11 8C A3 00 80 5F 48 A1 92</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Tcpip</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8187890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\MinSockaddrLength</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8188173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\MaxSockaddrLength</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8188320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\UseDelayedAcceptance</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8188450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8190694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 10188</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8220018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8220203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8220284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8221464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\settings.config</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8221949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\settings.config</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8222054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\settings.config</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:31:41, ChangeTime: 24.08.2018 12:31:41, FileAttributes: A, AllocationSize: 136, EndOfFile: 131, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x210000000206e7, EaSize: 0, Access: Generic Read, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8222226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\settings.config</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8222292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\settings.config</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:31:41, ChangeTime: 24.08.2018 12:31:41, FileAttributes: A, AllocationSize: 136, EndOfFile: 131, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x210000000206e7, EaSize: 0, Access: Generic Read, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8222442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\settings.config</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 131, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8222664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\settings.config</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 131, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8223029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\settings.config</Path>
<Result>END OF FILE</Result>
<Detail>Offset: 131, Length: 4 096</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8223154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\settings.config</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8224398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8224473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8224587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\design</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8224744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8224792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8224888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\design</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8226094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8226354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 217 536, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8226556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 217 562, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8228158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 217 576, Length: 571 904</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8229263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 789 480, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8229366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8266585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8266738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8266923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\libs_all</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8267134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8267184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8267295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\libs_all</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8269450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8269777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 694 338, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8270004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 694 364, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8270110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 694 380, Length: 51 712</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8270259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 746 092, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8270351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8280870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8280956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8281073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\backports_abc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8281208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8281258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8281358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\backports_abc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8347378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8347480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8347619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\ssl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8347782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8347835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8347932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\ssl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8349619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8349952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 459 491, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8350176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 459 517, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8350267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 459 528, Length: 9 728</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8350345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 469 256, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8350431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8352930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8352994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8353099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\textwrap</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8353215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8353262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8353354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\textwrap</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8354662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8354897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 519 006, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8355038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 519 032, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8355127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 519 048, Length: 2 048</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8355185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 2 521 096, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8355268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8361873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8361951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8362059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\contextlib</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8362184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8362233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8362325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\contextlib</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8363453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8363688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 850 368, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8363854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 850 394, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8364079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 850 412, Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8364162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 851 436, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8364248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8367024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8367096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8367201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\base64</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8367331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8367378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8367470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\base64</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8368575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8368802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 817 075, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8368947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 817 101, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8369032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 817 115, Length: 3 072</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8369091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 820 187, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8369171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8378325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8378408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8378519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Python\PythonCore\MCLauncher\Modules\select</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8378646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8378699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8378790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Python\PythonCore\MCLauncher\Modules\select</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8380034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8380275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 874 992, Length: 4 096, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8380472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 874 816, Length: 8 192, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8561730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 875 018, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8561944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 875 032, Length: 5 120</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8562013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 3 880 152, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8563088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8570552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8570760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8571037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8571214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8571281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8571361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8571488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8571535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8571602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8571716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8571774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8571990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8572968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8578207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 10340</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8737550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x75090000, Image Size: 0x135000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8740210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8740556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8740662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8740756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\msctf.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8753462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8753758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 12.10.2016 7:39:13, LastAccessTime: 12.10.2016 7:39:13, LastWriteTime: 15.09.2016 20:13:51, ChangeTime: 20.07.2018 2:17:39, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8753872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8755093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8755407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8755581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8756551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8756756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8757091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8757980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8758160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8758958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8759427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x72b90000, Image Size: 0x1f000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8760058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8761939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8762236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8762325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8762408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\dwmapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8766990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\qt.conf</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8776895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>D:\Qt\qt-4.8.7-msvc2008-x32\plugins</Path>
<Result>PATH NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8780228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8780402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8780488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8782835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8783001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 9:04:24, LastAccessTime: 24.08.2018 12:33:31, LastWriteTime: 24.08.2018 12:33:31, ChangeTime: 24.08.2018 12:33:31, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: RD</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8783076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8785578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8785736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:06:01, LastAccessTime: 20.07.2018 19:30:20, LastWriteTime: 20.07.2018 19:30:20, ChangeTime: 20.07.2018 19:30:20, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8785811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8788058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8788218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:06:02, LastAccessTime: 19.07.2018 20:06:03, LastWriteTime: 19.07.2018 20:06:03, ChangeTime: 19.07.2018 20:06:03, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: HD</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8788290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8790485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8790626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 19.07.2018 20:06:02, LastAccessTime: 24.08.2018 12:31:43, LastWriteTime: 24.08.2018 12:31:43, ChangeTime: 24.08.2018 12:31:43, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8790698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8792909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8793239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8793347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8795641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8795785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: D</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8795857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8798505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Session Manager</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8798658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8798769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8798832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 24</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8799046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8972225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wintab32.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8976397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\Tablet PC\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8976708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\Tablet PC</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8976774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\Tablet PC\IsTabletPC</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8977004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\Tablet PC</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8981855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 4264</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8984681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\bearer</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8994437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8994520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8994653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8994863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8994930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0\Type</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8995104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8995240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8995379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8995500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8995877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8995952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8996063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8996110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8996262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8996401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8996526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8996697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8996786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8996839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8996933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8997168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8997218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8997296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Cryptography\DESHashSessionKeyBackward</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,8997387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9010046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\4hvbhn</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read/Write, Disposition: Create, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Created</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9013035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryStandardInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\4hvbhn</Path>
<Result>SUCCESS</Result>
<Detail>AllocationSize: 0, EndOfFile: 0, NumberOfLinks: 1, DeletePending: False, Directory: False</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9013310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Local\Temp\4hvbhn</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9013412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\4hvbhn</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:38:52, LastAccessTime: 24.08.2018 12:38:52, LastWriteTime: 24.08.2018 12:38:52, ChangeTime: 24.08.2018 12:38:52, FileAttributes: A, AllocationSize: 0, EndOfFile: 0, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1100000003e881, EaSize: 0, Access: Generic Read/Write, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9013537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Local\Temp\4hvbhn</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9013606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\4hvbhn</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:38:52, LastAccessTime: 24.08.2018 12:38:52, LastWriteTime: 24.08.2018 12:38:52, ChangeTime: 24.08.2018 12:38:52, FileAttributes: A, AllocationSize: 0, EndOfFile: 0, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1100000003e881, EaSize: 0, Access: Generic Read/Write, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9013883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\4hvbhn</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 4, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9014277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\4hvbhn</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9014440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9015446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9015654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9070239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\4hvbhn</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Delete, Disposition: Open, Options: Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9072298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAttributeTagFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\4hvbhn</Path>
<Result>SUCCESS</Result>
<Detail>Attributes: A, ReparseTag: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9072433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>SetDispositionInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\4hvbhn</Path>
<Result>SUCCESS</Result>
<Detail>Delete: True</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9072600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9073888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9074099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9076556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\4hvbhn</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9079321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Write, Read Attributes, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Created</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9082097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9082197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:38:52, LastAccessTime: 24.08.2018 12:38:52, LastWriteTime: 24.08.2018 12:38:52, ChangeTime: 24.08.2018 12:38:52, FileAttributes: A, AllocationSize: 0, EndOfFile: 0, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1200000003e881, EaSize: 0, Access: Generic Write, Read Attributes, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9082441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 790 528, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9085339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>WriteFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 790 528, Length: 1 482, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9085583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9085729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9088320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9088533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9091542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 7348</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9097327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9097501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:38:52, LastAccessTime: 24.08.2018 12:38:52, LastWriteTime: 24.08.2018 12:38:52, ChangeTime: 24.08.2018 12:38:52, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9097585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9098671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9099042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Time Zones\Russian Standard Time\Dynamic DST</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read, Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9099385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Russian Standard Time\Dynamic DST</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read, Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9099505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Russian Standard Time\Dynamic DST</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9099771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Russian Standard Time\Dynamic DST\FirstEntry</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2010</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9099964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Russian Standard Time\Dynamic DST\LastEntry</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2015</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9100092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Russian Standard Time\Dynamic DST\2018</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 4 094</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9100333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Russian Standard Time\Dynamic DST\2015</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 44, Data: 4C FF FF FF 00 00 00 00 C4 FF FF FF 00 00 00 00 62 00 00 00 FC 2E 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9100527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Russian Standard Time\Dynamic DST</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9104367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\iconengines</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9107146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\iconengines</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9120827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\wintab32.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9123415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9123891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9123982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9125454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9127847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\imageformats</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9128241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 16 384, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9128490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 16 384, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9300367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 16 384, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9562648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>END OF FILE</Result>
<Detail>Offset: 16 400, Length: 16 368</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9562897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9563019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, FileAttributes: A, AllocationSize: 20 480, EndOfFile: 16 400, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x2100000002039d, EaSize: 0, Access: Generic Read, Position: 16 400, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9563180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9563249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, FileAttributes: A, AllocationSize: 20 480, EndOfFile: 16 400, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x2100000002039d, EaSize: 0, Access: Generic Read, Position: 16 400, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9563490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9575293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9575467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9575573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9575636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9575805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9576013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9576346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9576404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9576470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9576592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9576684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9576742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9576867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9576928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9577013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9577088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {00000320-0000-0000-C000-000000000046}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9577196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}\ProxyStubClsid32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9577249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\Interface\{00000160-0000-0000-C000-000000000046}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9578543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9578604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9578701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Ole\Extensions</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9578817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\Extensions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9578900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\Extensions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9578958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\Extensions\DragDropExtension</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 78, Data: {9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9579252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9579327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9579396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9579443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9579537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9579701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9579798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9579842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9579911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\(Default)</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InprocServer32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9580970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9581053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9581117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32\InprocServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9581241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9581308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9581408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9581488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 78, Data: %SystemRoot%\system32\dataexchange.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9581546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9581601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9581682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9581743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 78, Data: %SystemRoot%\system32\dataexchange.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9581812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9581867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9581948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9582009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32\(Default)</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 78, Data: %SystemRoot%\system32\dataexchange.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9582070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9582122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9582200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Maximum Allowed</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9582264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32\ThreadingModel</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 10, Data: Both</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9582424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9582480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9582546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9582649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9582748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9582801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InprocHandler32</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9582865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9582918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9583001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9583078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9583128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InprocHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9583200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9583405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9583466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9583530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9583580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\Software\Classes</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9583660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9583751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9583832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9583873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9584087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9584195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9584297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x401</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9584350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\TreatAs</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9584427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCR\WOW6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9587361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9587583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 12.10.2016 7:39:13, LastAccessTime: 12.10.2016 7:39:13, LastWriteTime: 15.09.2016 19:56:42, ChangeTime: 20.07.2018 2:17:43, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9587672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9588672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9588899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9589076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9589996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9590190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9590492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9591326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9591495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9592227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9592759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x6c4b0000, Image Size: 0x44000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9593493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9596355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9596629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:39, LastAccessTime: 20.07.2018 1:33:39, LastWriteTime: 21.06.2017 10:28:29, ChangeTime: 20.07.2018 19:25:22, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9596712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9597696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9597964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9598089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9598934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9599111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9599388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9600217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9600386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9601043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9601483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x707f0000, Image Size: 0x230000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9602162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9605071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9605337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:38, LastAccessTime: 20.07.2018 1:33:38, LastWriteTime: 21.06.2017 10:27:41, ChangeTime: 20.07.2018 19:25:26, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9605420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9606387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9606653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9606772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9607614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9607792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9608074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9608905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9609072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9609717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9610149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x6c390000, Image Size: 0x113000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9610778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9613288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9613651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:40, LastAccessTime: 20.07.2018 1:33:40, LastWriteTime: 21.06.2017 10:28:24, ChangeTime: 20.07.2018 19:24:44, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9613737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9614737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9615012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9615128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9615970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9616148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9616422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9617239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9617405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9618045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9618480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x70340000, Image Size: 0x83000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9619062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9621933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9622232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9622331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9622420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\dxgi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9623756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9624033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9624119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9624202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\d3d11.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9625365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9625637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9625720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9625800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\dcomp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9626950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9627155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9627241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9627319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\DataExchange.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9628438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\03bbe5b8-c788-4d0b-b47e-5b5731398a89</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9629698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\86cc27ea-6f87-47f7-8b43-3473527d4a87</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9630319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\93112de2-0aa3-4ed7-91e3-4264555220c1</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9630541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9630604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9630712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\Dwm</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9631147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Ole\Extensions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9633948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9634142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:28, LastAccessTime: 20.07.2018 1:34:28, LastWriteTime: 22.03.2018 6:31:52, ChangeTime: 20.07.2018 19:45:28, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9634223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9635220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9635425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9635550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9636406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9636586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9636866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9637697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9637863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9638509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9638947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x6c290000, Image Size: 0xf1000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9639611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9641484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9641687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9641761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9641831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\twinapi.appcore.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9705703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9705795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9705922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\Compatibility\MCLauncher.exe</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9734506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9734597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9734725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9734869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9734949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\EnableAnchorContext</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9735146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9735783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9735855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9735966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\KnownClasses</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9765262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9765409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:38:52, LastAccessTime: 24.08.2018 12:38:52, LastWriteTime: 24.08.2018 12:38:52, ChangeTime: 24.08.2018 12:38:52, FileAttributes: A, AllocationSize: 794 624, EndOfFile: 792 010, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1200000003e881, EaSize: 0, Access: Generic Read, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9766090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9766173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:38:52, LastAccessTime: 24.08.2018 12:38:52, LastWriteTime: 24.08.2018 12:38:52, ChangeTime: 24.08.2018 12:38:52, FileAttributes: A, AllocationSize: 794 624, EndOfFile: 792 010, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1200000003e881, EaSize: 0, Access: Generic Read, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9767969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 792 010, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9769667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9769753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:38:52, LastAccessTime: 24.08.2018 12:38:52, LastWriteTime: 24.08.2018 12:38:52, ChangeTime: 24.08.2018 12:38:52, FileAttributes: A, AllocationSize: 794 624, EndOfFile: 792 010, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1200000003e881, EaSize: 0, Access: Generic Read, Position: 792 010, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:52,9769889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4216672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4216910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4217012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4218109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4233228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4233461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4233553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4234655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4234874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4235065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4238628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4238839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4239157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4240008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4240185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4240598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4241016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x12000000, Image Size: 0x58000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,4241210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 310 784, Length: 12 288, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5273294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 251 904, Length: 4 096, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5503553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5506121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5506315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5506395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5507343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5507534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5507672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5508515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5508698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5508977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5509795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5509958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5510332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5510731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x11000000, Image Size: 0x155000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5510914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 314 816, Length: 9 216, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5622338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 943 616, Length: 16 384, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,5956658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6165401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\LIBEAY32.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6167080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6167332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6167418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6167495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6167855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\ssleay32.dll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 1 024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6168894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6169091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6169163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6169227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\ssleay32.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6173676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\libeay32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 1 294 336, Length: 8 192, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6177696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Control\Session Manager</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6177849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value, Enumerate Sub Keys</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6177965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6178023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 24</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6178212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Control\Session Manager</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6202005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6202088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6202210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\Rpc</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6202318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Rpc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6442030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6442365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:55, LastAccessTime: 16.07.2016 14:42:55, LastWriteTime: 16.07.2016 14:42:55, ChangeTime: 19.07.2018 19:39:17, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6442457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6443609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6443911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6444100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6445022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6445216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6445518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6446366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6446535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6447350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6447829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x70c30000, Image Size: 0x1c000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6448444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6449993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6450275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6450364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6450441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\srvcli.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6450998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6451079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6451184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\LanmanWorkstation\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6451311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\LanmanWorkstation\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6451439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\LanmanWorkstation\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6451497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\RpcCacheTimeout</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6451763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\LanmanWorkstation\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6454728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6454794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6454902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6455074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6455135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6455309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6455445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6455564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6455708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6455791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6455847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6455944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6456044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6456099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6456229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6456354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6456470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6456587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6456911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6456974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6457069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6457113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6457249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6457371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6457495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 74, Data: 89c16905-77a2-4a80-ba7d-623b3fd0da77</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6457648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\Cryptography</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6457728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6457778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6457869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6458072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6458207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6458254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:53,6458338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Intel Hardware Cryptographic Service Provider</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6686111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6686227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6686621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Services\crypt32</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6686798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\crypt32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6686959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\crypt32</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6687028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\crypt32\DiagLevel</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6687203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\crypt32\DiagMatchAnyMask</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6687352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\crypt32</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6687435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6687541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6687629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Services\crypt32</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6687704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\crypt32</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6687809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\crypt32</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6688618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 4804</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6688857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6688945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6689053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6689250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6689339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: EncodingType 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6689449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6689513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6689713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6689768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6689868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: #16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6689954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\cryptnet.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: FuncName, Type: REG_SZ, Length: 36, Data: LdapProvOpenStore</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: Ldap</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\cryptnet.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: FuncName, Type: REG_SZ, Length: 36, Data: LdapProvOpenStore</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 2, Length: 288</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6690993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6691031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6691067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: EncodingType 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6691145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6691320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6691558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6691649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6691755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6691799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 2, Length: 288</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6691849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6692602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6692755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6692838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6692918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6693079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6693156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6693240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\SystemCertificates\ROOT\PhysicalStores</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6693395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6693647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6693730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6693802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6693938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6694013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6694098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKCU\Software\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6694326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6694392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6694436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6694578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6694686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6694802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6694888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6695334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6695417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6695492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6695647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6695725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6695805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKCU\Software\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6696010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6696179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6696271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6696345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6696503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6696578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6696653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6696800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6696858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6696933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6697002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6697063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6697168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6697229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6697456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6697512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6697567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\Certificates</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6697670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6697728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6697908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6697958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6698013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CRLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6698071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6698127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6698288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6698337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6698393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CTLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6698515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6698598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6698673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6698994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6699074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6699155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6699282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6699385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKeySecurity</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6699493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 24, Data: 18 00 00 00 01 00 00 00 E0 A9 4A DB 82 1F D4 01</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6699664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 24, Data: 18 00 00 00 01 00 00 00 E0 A9 4A DB 82 1F D4 01</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6699806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6699850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6699955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6699994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6700099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6700183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6700274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\ROOT\PhysicalStores</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6700368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\PhysicalStores</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6700521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6700595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6700676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\ROOT</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6700748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6700845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6700903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6701197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6701302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6701399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6701471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6701706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6701781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6701864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\ROOT</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6701934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6702028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6702116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6702177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6702263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6702319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6702393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 9, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6702446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 9, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6702502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: 18F7C1FCC3090203FD5BAA2F861A754976C8DD25</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6702585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6702637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6702723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6702876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6702995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 924, Data: 19 00 00 00 01 00 00 00 10 00 00 00 E5 3D 34 CE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6703133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6703277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6703360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6703449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6703565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6703626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: EncodingType 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6703718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6703776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6703890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6703945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllDecodeObjectEx</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: EncodingType 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: 1.2.840.113549.1.9.16.1.1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: EssReceiptDecodeEx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: 1.2.840.113549.1.9.16.2.1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6704987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: FuncName, Type: REG_SZ, Length: 52, Data: EssReceiptRequestDecodeEx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Index: 2, Name: 1.2.840.113549.1.9.16.2.11</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: FuncName, Type: REG_SZ, Length: 58, Data: EssKeyExchPreferenceDecodeEx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Index: 3, Name: 1.2.840.113549.1.9.16.2.12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6705984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: EssSignCertificateDecodeEx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Index: 4, Name: 1.2.840.113549.1.9.16.2.2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: EssSecurityLabelDecodeEx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Index: 5, Name: 1.2.840.113549.1.9.16.2.3</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6706932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: EssMLHistoryDecodeEx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Index: 6, Name: 1.2.840.113549.1.9.16.2.4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: FuncName, Type: REG_SZ, Length: 46, Data: EssContentHintDecodeEx</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 7, Length: 288</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 2, Length: 288</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6707896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\msasn1</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6708311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: 245C97DF7514E7CF2DF8BE72AE957B9E04741E85</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6708408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6708472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6708561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6708699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6708813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 907, Data: 19 00 00 00 01 00 00 00 10 00 00 00 7F DF F5 07</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6708951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6709071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 2, Name: 3B1EFD3A66EA28B16697394703A72CA340A05BD5</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6709162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6709223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6709309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6709436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6709544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 835, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6709677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6709846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 3, Name: 7F88CD7223F3C813818C994614A89C99FA3B5247</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6709938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6709996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6710079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6710198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6710303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 228, Data: 19 00 00 00 01 00 00 00 10 00 00 00 07 D3 4D ED</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6710431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6710567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 4, Name: 8F43288AD272F3103B6FB1428485EA3014C0BCFE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6710655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6710816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6710943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6711060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6711162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 835, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6711293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6711428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 5, Name: 92B46C76E13054E104F230517E6E504D43AB10B5</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6711517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6711581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6711658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6711775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6711885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 255, Data: 09 00 00 00 01 00 00 00 0C 00 00 00 30 0A 06 08</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6712016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6712146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 6, Name: A43489159A520F0D93D032CCAF37E7FE20A8B419</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6712232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6712293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6712373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6712492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6712597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 310, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6712728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6712844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 7, Name: BE36A4562FB2EE05DBB3D32323ADF445084ED656</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6712930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6712988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6713071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6713193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6713296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 935, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6713423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6713539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 8, Name: CDD4EEAE6000AC7F40C3802C171E30148030C072</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6713623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6713684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6713764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6713886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6713988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 729, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6714991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6715083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6715174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\AuthRoot</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6715243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6715368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6715451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6715509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6715592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6715648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6715717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 25, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6715767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 25, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6715817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: 02FAF3E291435468607857694DF5E45B68851868</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6715900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6715953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6716036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6716177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6716288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 538, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6716421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6716557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: 039EEDB80BE7A03C6953893B20D2D9323A4C2AFD</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6716651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6716712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\039EEDB80BE7A03C6953893B20D2D9323A4C2AFD</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6716789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\039EEDB80BE7A03C6953893B20D2D9323A4C2AFD\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6716925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\039EEDB80BE7A03C6953893B20D2D9323A4C2AFD\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6717033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\039EEDB80BE7A03C6953893B20D2D9323A4C2AFD\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 505, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6717163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\039EEDB80BE7A03C6953893B20D2D9323A4C2AFD</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6717282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 2, Name: 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6717377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6717438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6717515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6717637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6717742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 348, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6717870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6717983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 3, Name: 07E032E020B72C3F192F0628A2593A19A70F069E</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6718072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6718133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6718211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6718333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6718438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 484, Data: 53 00 00 00 01 00 00 00 65 00 00 00 30 63 30 21</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6718565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6718693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 4, Name: 2796BAE63F1801E277261BA0D77770028F20EEE4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6718784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6718845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6718925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6719061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6719166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 512, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6719297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6719413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 5, Name: 3679CA35668772304D30A5FB873B0FA77BB70D54</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6719504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6719565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6719646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6719770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6719876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 698, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6720009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6720150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 6, Name: 3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6720241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6720300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6720386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6720613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6720732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 2 448, Data: 19 00 00 00 01 00 00 00 10 00 00 00 6D 00 C0 25</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6720865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6721017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 7, Name: 4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6721114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6721175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6721253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6721377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6721483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 624, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6721610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6721729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 8, Name: 51501FBFCE69189D609CFAF140C576755DCC1FDF</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6721815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6721876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6721951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6722078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6722184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 808, Data: 59 00 00 00 01 00 00 00 16 00 00 00 52 00 53 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6722314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6722436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 9, Name: 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6722524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6722585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6722663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6722785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6722893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 362, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6723020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6723134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 10, Name: 6252DC40F71143A22FDE9EF7348E064251B18118</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6723223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6723284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6723361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6723561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6723669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 136, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6723799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6723907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 11, Name: 742C3192E607E424EB4549542BE1BBC53E6174E2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6723993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6724054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6724134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6724250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6724353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 054, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 00 10 C5</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6724480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6724594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 12, Name: 75E0ABB6138512271C04F85FDDDE38E4B7242EFE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6724683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6724746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6724824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6724940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6725046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 477, Data: 0B 00 00 00 01 00 00 00 5C 00 00 00 47 00 6F 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6725170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6725298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 13, Name: 91C6D6EE3E8AC86384E548C299295C756C817B81</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6725384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6725445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6725522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6725641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6725747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 441, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6725877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6725993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 14, Name: 97817950D81C9670CC34D809CF794431367EF474</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6726085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6726146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6726226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6726353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6726459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 986, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 00 10 C5</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6726589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6726689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 15, Name: A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6726777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6726838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6726918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6727035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6727137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 340, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6727265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6727381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 16, Name: AD7E1C28B064EF8F6003402014C3D0E3370EB58A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6727473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6727536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6727611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6727733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6727908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 529, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6728035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6728162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 17, Name: B1BC968BD4F49D622AA89A81F2150152A41D829C</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6728248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6728309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6728387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6728506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6728609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 364, Data: 0B 00 00 00 01 00 00 00 30 00 00 00 47 00 6C 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6728766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6728891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 18, Name: D23209AD23D314232174E40D7F9D62139786633A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6728983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6729044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6729124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6729246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6729348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 197, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6729476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6729609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 19, Name: D4DE20D05E66FC53FE1A50882C78DB2852CAE474</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6729703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6729764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6729847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6729966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6730069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 387, Data: 09 00 00 00 01 00 00 00 3E 00 00 00 30 3C 06 08</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6730196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6803984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 20, Name: D69B561148F01C77C54578C10926DF5B856976AD</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6804195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6804300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6804447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6804702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6804818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 334, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6804990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6805134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 21, Name: DAC9024F54D8F6DF94935FB1732638CA6AD77C13</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6805237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6805306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6805397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6805530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6805636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 218, Data: 09 00 00 00 01 00 00 00 42 00 00 00 30 40 06 08</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6805774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6805904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 22, Name: DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6806001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6806068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6806148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6806284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6806392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 222, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6806525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6806652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 23, Name: DE3F40BD5093D39B6C60F6DABC076201008976C9</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6806744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6806808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6806888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6807013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6807118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 944, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6807248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6807389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Index: 24, Name: DF3C24F9BFD666761B268073FE06D1CC8D4F82A4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6807484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6807547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6807628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6807750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6807855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 1 349, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6807991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6808121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6808198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6808265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6808359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6808415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6808464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6808517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6808572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6808808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6808861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6808916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6808966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6809110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6809212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6809320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\ROOT</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6809409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6809567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6809645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6809708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6809800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6809847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6809902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6809958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\ROOT\PhysicalStores</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6810905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\ROOT\PhysicalStores</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6811066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6811144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6811229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\ROOT</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6811299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6811398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6811454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6811548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6811626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6811706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\ROOT</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6811775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6811867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6811944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6812980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6813058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6813138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6813208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6813305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6813377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6813435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6813518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6813720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6813825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6813875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6813933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6813994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6814047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6814114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6814158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6814219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6814271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6814321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6814385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6814432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6814485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6814532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6814972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6815067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6815141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6815310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6815388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6815471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6815604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6815687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6815743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6815829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6815878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6815950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6815998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6816056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6816108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6816161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6816225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6816272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6816322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6816380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6816430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6816493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6816541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs</Path>
<Result>SUCCESS</Result>
<Detail>Query: Cached, SubKeys: 0, Values: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6816590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6816632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6816671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6846346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6846438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6846496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6846573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6847219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6847468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\SystemCertificates\Root</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6848366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 7560</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,6995499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 6884</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7010469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 12412</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7012203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 6492</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7054415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7054634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, FileAttributes: A, AllocationSize: 188 416, EndOfFile: 184 608, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1700000002037f, EaSize: 0, Access: Generic Read, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7055028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7055111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, FileAttributes: A, AllocationSize: 188 416, EndOfFile: 184 608, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1700000002037f, EaSize: 0, Access: Generic Read, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7055546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 184 608, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7055959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 184 608, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7059267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7059389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7059519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7059674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7059848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7059915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Parameters\Transports</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_MULTI_SZ, Length: 64, Data: vmbus, Psched, Tcpip, Tcpip6, irda</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7060114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Parameters\Transports</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_MULTI_SZ, Length: 64, Data: vmbus, Psched, Tcpip, Tcpip6, irda</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7060275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7060364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7060450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7060538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7060619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7060746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7060802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock\Mapping</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 44, Data: 03 00 00 00 03 00 00 00 22 00 00 00 01 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7060951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock\Mapping</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 44, Data: 03 00 00 00 03 00 00 00 22 00 00 00 01 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7061087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7061164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7061245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7061322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7061394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7061514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7061563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock\Mapping</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7061691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock\Mapping</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7061796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock\Mapping</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 152, Data: 0C 00 00 00 03 00 00 00 17 00 00 00 01 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7061926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7061996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7062079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7062156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7062231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7062450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7062555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7062622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Psched</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7062710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Psched\WinSock 2.0 Provider ID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: E0 A9 60 9D 7A 33 D0 11 BD 88 00 00 C0 82 E6 9A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7062854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Psched</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7062899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7062968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7063051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7063129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7063198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7063317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7063367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\Mapping</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 104, Data: 08 00 00 00 03 00 00 00 02 00 00 00 01 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7063550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\Mapping</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 104, Data: 08 00 00 00 03 00 00 00 02 00 00 00 01 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7063680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7063755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7063832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7063907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7063977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7064132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7064184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock\Mapping</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 104, Data: 08 00 00 00 03 00 00 00 17 00 00 00 01 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7064328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock\Mapping</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 104, Data: 08 00 00 00 03 00 00 00 17 00 00 00 01 00 00 00</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7064456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7064520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7064597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7064675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7064744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7064841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7064913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7064974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Tcpip6</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7065065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Tcpip6\WinSock 2.0 Provider ID</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_BINARY, Length: 16, Data: C0 B0 EA F9 D4 26 D0 11 BB BF 00 AA 00 6C 34 E4</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7065201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Tcpip6</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7065240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7065312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7065390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7065467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7065534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7065631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7065680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock\MinSockaddrLength</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 28</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7065908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock\MaxSockaddrLength</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 28</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7066024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock\UseDelayedAcceptance</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7066151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7069651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7070014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:33:40, LastAccessTime: 20.07.2018 1:33:40, LastWriteTime: 06.03.2018 9:17:29, ChangeTime: 20.07.2018 19:25:18, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7070102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7071161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7071460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7071645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7072815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7073025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7073344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7074241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7074416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7075269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7075776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x73f30000, Image Size: 0x7d000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7076821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x77d10000, Image Size: 0x7000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7077272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7079046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7079342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7079428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7079500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\nsi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7080628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7080894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7080968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7081032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\dnsapi.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7082102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\9ca335ed-c0a6-4b4d-b084-9c9b5143aff0</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7085171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7085440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 20.07.2018 1:34:27, LastAccessTime: 20.07.2018 1:34:27, LastWriteTime: 04.03.2017 10:02:53, ChangeTime: 20.07.2018 19:25:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7085523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7086523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7086812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7086956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7087850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7088042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7088341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7089194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7089372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7090081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7090516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x73f00000, Image Size: 0x2f000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7091156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7092893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7093173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7093253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7093322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\IPHLPAPI.DLL</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7094458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7094588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7094710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7094974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7095187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7095284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7095370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7095456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7095536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7095655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7095730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7095810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7095905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7095993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7096173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: WIN-0UOTFKKVN1S</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7096384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: WIN-0UOTFKKVN1S</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7096564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7096617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7096694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7096780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7096866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7097043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7097215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7097298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7097378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7097450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7097523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7097617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7097686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7097761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7097844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7097910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7098013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: WIN-0UOTFKKVN1S</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7098171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: WIN-0UOTFKKVN1S</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7098312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7098359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7098428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7098509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7098589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7098758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7098922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7098999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7099077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7099149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7099215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7099310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7099376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7099454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7099537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7099600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7099722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7099800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7099880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\System\DNSClient</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7099944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\System\DNSClient</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7100058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 2, Data: </Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7100204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 2, Data: </Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7100371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7100418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7100670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7100753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7100828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7100897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>ACCESS DENIED</Result>
<Detail>Desired Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7101024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7101113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7101556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7101642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7101720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7101792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7101897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7101961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 8, Data: 2.0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7102122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 8, Data: 2.0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7102263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AutodialDLL</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: C:\Windows\System32\rasadhlp.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7102388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AutodialDLL</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 66, Data: C:\Windows\System32\rasadhlp.dll</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7102523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\WinSock2\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7105067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7105349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:43:00, LastAccessTime: 16.07.2016 14:43:00, LastWriteTime: 16.07.2016 14:43:00, ChangeTime: 19.07.2018 19:38:37, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7105435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7106424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7106707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7106834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7107718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7107907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7108195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7109051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7109225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7109882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7110306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x73ab0000, Image Size: 0x8000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7110946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7112231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7112503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7112578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7112644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\rasadhlp.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7113221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7113329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7113431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7113639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7113838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7113927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7114010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7114096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7114174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7114282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7114356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7114434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7114523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7114592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7114706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: WIN-0UOTFKKVN1S</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7114875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: WIN-0UOTFKKVN1S</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7115030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7115080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7115149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7115232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7115315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7115487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7115659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7115736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7115817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7115891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7115961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7116058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7116124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7116199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7116285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7116348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7116470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7116545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7116628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\System\DNSClient</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7116692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\System\DNSClient</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7116800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 2, Data: </Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7116950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 2, Data: </Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7117094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7117141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7117216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7117296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7117376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7117545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7117709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7117786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7117864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7117936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7118005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7118102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7118169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7118244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7118324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7118388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7118490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: WIN-0UOTFKKVN1S</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7118637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: WIN-0UOTFKKVN1S</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7118775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7118823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7118897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7118978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7119058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7119224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCreateKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7119385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7119463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7119540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7119612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7119679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DnsCache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7119773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7119839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7119914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7119995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7120058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7120180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7120255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7120327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DNS</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7120396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\DNS</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7120496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryAdapterName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7120662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableAdapterDomainName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7120779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseDomainNameDevolution</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7120881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\UseDomainNameDevolution</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7121144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DomainNameDevolutionLevel</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7121252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\PrioritizeRecordData</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7121352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\PrioritizeRecordData</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7121452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AllowUnqualifiedQuery</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7121549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\AllowUnqualifiedQuery</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7121649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AppendToMultiLabelName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7121820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenBadTlds</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7121920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenUnreachableServers</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7122017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenDefaultServers</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7122111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DynamicServerQueryOrder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7122205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\FilterClusterIp</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7122302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\WaitForNameErrorOnAll</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7122399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseEdns</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7122496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsSecureNameQueryFallback</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7122591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableDAForAllNetworks</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7122688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DirectAccessQueryOrder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7122784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryIpMatching</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7122881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseHostsFile</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7122976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AddrConfigControl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7123070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableSmartNameResolution</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7123167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\PreferLocalOverLowerBindingDNS</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7123264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryNetBTFQDN</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7123358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableSmartProtocolReordering</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7123452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UdpRecvBufferSize</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7123549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableParallelAandAAAA</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7123643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableCoalescing</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7123738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\FilterVPNTrigger</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7123835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableMultiHomedRouteConflicts</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7123929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationEnabled</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7124092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableDynamicUpdate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7124192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterPrimaryName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7124289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterAdapterName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7124389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\EnableAdapterDomainNameRegistration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7124491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterReverseLookup</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7124591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableReverseAddressRegistrations</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7124691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterWanAdapters</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7124854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableWanDynamicUpdate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7124954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationTtl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7125051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DefaultRegistrationTTL</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7125151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationRefreshInterval</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7125250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DefaultRegistrationRefreshInterval</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7125350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationMaxAddressCount</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7125444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\MaxNumberOfAddressesToRegister</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7125544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UpdateSecurityLevel</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7125638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\UpdateSecurityLevel</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7125738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UpdateTopLevelDomainZones</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7125835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7125935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationOverwrite</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7126026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCacheSize</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7126120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCacheTtl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7126214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxNegativeCacheTtl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7126314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AdapterTimeoutLimit</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7126408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ServerPriorityTimeLimit</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7126503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCachedSockets</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7126597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableServerUnreachability</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7126691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxNegativeNXDomainCacheTtl</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7126785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableMulticast</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7126879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastResponderFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7126976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastSenderFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7127073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastSenderMaxTimeout</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7127168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsTest</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7127262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseCompartments</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7127356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\CacheAllCompartments</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7127453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseNewRegistration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7127547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ResolverRegistration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7127641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ResolverRegistrationOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7127735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\NewDhcpSrvRegistration</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7127880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DirectAccessPreferLocal</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7127977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableIdnEncoding</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7128071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableIdnMapping</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7128165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ShortnameProxyDefault</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7128262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutHistoryLength</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7128362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutRecalculationInterval</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7128492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7128583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7128664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\System\Setup</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Query Value</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7128788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SYSTEM\Setup</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7128838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SYSTEM\Setup\SystemSetupInProgress</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7128985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SYSTEM\Setup</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7129038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsQueryTimeouts</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7129148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQueryTimeouts</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7129257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsQuickQueryTimeouts</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7129359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQuickQueryTimeouts</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7129470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Tcpip\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7129511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\System\CurrentControlSet\Services\Dnscache\Parameters</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7134820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7135119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:55, LastAccessTime: 16.07.2016 14:42:55, LastWriteTime: 16.07.2016 14:42:55, ChangeTime: 20.07.2018 2:17:48, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7135205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7136222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7136507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Result>FILE LOCKED WITH ONLY READERS</Result>
<Detail>SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7136632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7137524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7137712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7138003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7138868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7139042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7139710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFileMapping</Operation>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Result>SUCCESS</Result>
<Detail>SyncType: SyncTypeOther</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7140137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Load Image</Operation>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Result>SUCCESS</Result>
<Detail>Image Base: 0x73a50000, Image Size: 0x49000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7141200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7142361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7142641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7142721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QuerySecurityFile</Operation>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Result>SUCCESS</Result>
<Detail>Information: Owner</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7142788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\FWPUCLNT.DLL</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7145329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7145437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7145633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7145816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7145905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7145991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7146154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7146232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7146307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7146448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7146506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7146692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7146742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7146863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7146935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7147091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7147229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7147307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7147384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7147515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7147592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7147664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7147786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7147839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7147902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7147947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7153912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 12232</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7525391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7525538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, FileAttributes: A, AllocationSize: 188 416, EndOfFile: 184 608, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x1700000002037f, EaSize: 0, Access: Generic Read, Position: 184 608, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7525738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\font.ttf</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7782219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54030 -&gt; 104.31.12.175:http</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,7787539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54030 -&gt; 104.31.12.175:http</Path>
<Result>SUCCESS</Result>
<Detail>Length: 255, startime: 40858746, endtime: 40858746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8037546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8037884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8039278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8043783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8043982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8044237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8044470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8044558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8044641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8044810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8044880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8044954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8045101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8045162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8045359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8045409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8045525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8045597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8045744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8045877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8045952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8046024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8046151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8046218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8046287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8046403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8046456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8046667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8046711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8053829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 517, startime: 40858749, endtime: 40858749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8060957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 517, startime: 40858749, endtime: 40858749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8066881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 517, startime: 40858749, endtime: 40858749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8109531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8109835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8112905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8113096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8114013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8114146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8116205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8116341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8117147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8117272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8118903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8119034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8119710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8119829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8121558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8121688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8122347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8122469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8124309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8124470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8125201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8125345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8127168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8127323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8128088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8128218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8129772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8129908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8130598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8130720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8132310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8132438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8133114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8133236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8134837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8134995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8144570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8144767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8147274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8147451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8148330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8148488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8150305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8150463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8151164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8151336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8153275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8153439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8154164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8154311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8156325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8156486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8157187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8157334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8159162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8159309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8159969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8160091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8161686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8161819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8162451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8162573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8164030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8164163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8164831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8165069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8166740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8166876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8167535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8167657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8169206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8169336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8169982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8170106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8171796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8171929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8172575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8172694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8174209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8174351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8175232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8175379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8177166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8177310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8178080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8178218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8180149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8180313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8190969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8191132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8193191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8193343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8194085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8194224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8195908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8196053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8196748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8196900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8198610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8198737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8199399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8199518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8201231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8201380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8202123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8202261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8203987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8204131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8205021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8205162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8207162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8207312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8208088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8208232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8209997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8210160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8210939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8211086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8212939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8213105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8213878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8214283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8216120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8216261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8216951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8217084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8218865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8219015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8219721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8219849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8221774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8221932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8222672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8222780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8224340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8224445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8224980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8225071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8226279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8226374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8227997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8228097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8229324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8229421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8229942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8230031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8231250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8231344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8231873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8231962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8233416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8233574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8241063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8241193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8242443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8242551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8243249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8243363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8244598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8244695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8245216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8245305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8246491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8246585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8247095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8247183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8248555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8248652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8249186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8249275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8250450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8250541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8251045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8251134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8252517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8252613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8253240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8253331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8254567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8254661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8259196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8259321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8260532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8260640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8263144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8263255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8264455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8264555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8265098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8265192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8266455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8266552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8267070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8267159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8268469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8268566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8271107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8271215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8272370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8272470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8273141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8273232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8274581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8274678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8275199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8275285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8276573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8276668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8277183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8277274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8278518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8278612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8285209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8285342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8286542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8286647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8287198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8287290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8288606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8288706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8289232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8289321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8290498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8290590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8291099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8291188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8295058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8295161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8295698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8295787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8297078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8297175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8297718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8297807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8299092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8299189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8299702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8299791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8301176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8301270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8301785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8302026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8303603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8303703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8304221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8304312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8305537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8305631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8306135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8306224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8307482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8307576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8308094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8308183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8309385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8309479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8309978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8310064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8311236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8311330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8315876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8315993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8317248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8317350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8319894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8319999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8321207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8321312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8322038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8322132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8323387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8323482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8324014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8324102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8325402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8325499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8326036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8326125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8327352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8327446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8327956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8328045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8329538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8329638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8330167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8330256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8331608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8331705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8334619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8334730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8335877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8335980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8336506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8336597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8337952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8338049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8338590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8338681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8339942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8340036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8340548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8340637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8342014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8342108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8342623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8342712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8343942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8344036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8344538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8344627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8345873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8345968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8346475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8346563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8347799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8347890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8348397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8348486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8349708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8349802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8350331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8350719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8351664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54030 -&gt; 104.31.12.175:http</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8351777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54030 -&gt; 104.31.12.175:http</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8351938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54030 -&gt; 104.31.12.175:http</Path>
<Result>SUCCESS</Result>
<Detail>Length: 187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8351957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54030 -&gt; 104.31.12.175:http</Path>
<Result>SUCCESS</Result>
<Detail>Length: 187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8355983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8356102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8356662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8356759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8357989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8358086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8359535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8359637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8360956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8361075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8364730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8364841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8366140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8366245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8366786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8366877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8368171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8368268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8368789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8368880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8370116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8370373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8371216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8371307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8372559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8372656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8373172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8373260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8374599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8374695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8375230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8375319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8376615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8376710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8377261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8377350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8378596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8378693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8379217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8379306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8380899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8380996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8381517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8381605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8382835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8382930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8383434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8383522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8384733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8384830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8385346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8385434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8386817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8386911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8387457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8387545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8388897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8388992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8389515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8389601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8391047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8391142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8393632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8393735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8394907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8395012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8395549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8395638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8396960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8397057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8397569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8397658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8398824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8398916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8404764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8404892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8406025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8406130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8406673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8406765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8407959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8408056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8408574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8408663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8410253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8410353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8410885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8410973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8412503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8412602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8413126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8413217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8414594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8414691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8416683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8416783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8418052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8418152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8423117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8423238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8424421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8424527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8425081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8425172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8426433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8426530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8427065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8427153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8428425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8428702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8429331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8429425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8430672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8430766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8431312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8431401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8432631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8432728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8433260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8433348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8434603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8434698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8435224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8435310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8436656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8436753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8437280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8437368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8438961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8439061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8439607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8439696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8441136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8441233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8441760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8441851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8443225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8443319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8443843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8443932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8445253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8445348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8445874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8445963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8447234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8447328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8447844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8447930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8449260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8449354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8449880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8449969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8451202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8451296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8451808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8451897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8455554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8455654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8456200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8456288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8457704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8457959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8458516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8458605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8459821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8459915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8460419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8460508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8461744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8461838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8462375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8462464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8463703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8463797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8464312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8464401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8465683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8465778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8469219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8469335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8470532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8470634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8471172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8471263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8472538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8472635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8473147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8473236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8474472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8474569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8475098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8475186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8476350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8476444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8482697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8482825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8484110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8484219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8489291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8489433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8489660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8489870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8489970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8490059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8490217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8490289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8490364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8490510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8490577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8490787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8490840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8490951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8491026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8491173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8491308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8491394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8491469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8491599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8491669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8491738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8491860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8491915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8491982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8492026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8948542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8948656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8949091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8949506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 16.07.2016 14:42:49, LastAccessTime: 16.07.2016 14:42:49, LastWriteTime: 16.07.2016 14:42:49, ChangeTime: 19.07.2018 19:41:04, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8949614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Windows\SysWOW64\winmm.dll</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,8951075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 9476</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9091780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9091897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9093008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9093066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9093185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9093202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9095288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 512, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9095324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 512, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9095401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9095418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9165715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 158, startime: 40858760, endtime: 40858760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9165826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 158, startime: 40858760, endtime: 40858760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9238213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9238321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9241233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9241277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9243147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9243175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9282558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 158, startime: 40858761, endtime: 40858761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9935269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9935385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:54,9942126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 291, startime: 40858768, endtime: 40858768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,0090382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,0090495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,0097098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 292, startime: 40858770, endtime: 40858770, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,0243250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,0243372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,0792697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,0792810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,0823610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 291, startime: 40858777, endtime: 40858777, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,0825409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 291, startime: 40858777, endtime: 40858777, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1045363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1045471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1072279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 291, startime: 40858779, endtime: 40858779, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1525028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1525147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1526128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1526155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1668983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1669094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1671036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1671338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1671388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1671491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1671510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1678206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1678243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1679805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 517, startime: 40858785, endtime: 40858785, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1816294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1816397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1816566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1816582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1817782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1817809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1819644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1819788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1819838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1827695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 517, startime: 40858787, endtime: 40858787, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1828922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 291, startime: 40858787, endtime: 40858787, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1965358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1965472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1965622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1965638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1966539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1966564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1966644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,1966658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2110106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2110220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2111544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2111578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2113082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1240, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2113118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1240, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2114570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2114620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2116035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2116071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2117390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2117426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2256242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2256350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2257733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2257766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2267585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2267629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2269572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2269616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2269705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2269721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2402220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2402331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2402497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2402517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2533634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2533756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2533938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2533952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2548977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2549063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2552219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2552274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2552385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2552399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2677614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2677711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2681748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2681781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2683349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2683374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2683457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2683471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2691932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2691968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2697906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2697961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2701555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2701588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2824052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2824166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2834184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2834253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2834395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2834411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2836212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2836243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2902456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 158, startime: 40858797, endtime: 40858798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,2902611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 158, startime: 40858797, endtime: 40858798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,3794272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,3794374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,3794566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:55,3794607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:57,9236210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Delete, Disposition: Open, Options: Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:57,9238681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAttributeTagFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail>Attributes: A, ReparseTag: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:57,9238839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>SetDispositionInformationFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail>Delete: True</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:57,9239036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:57,9240033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:57,9240238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:57,9241765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Local\Temp\d.htm</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:38:57,9246017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 7348, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:24,7220200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 12412, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:24,7222924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 6492, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:32,9572733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 3432, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:35,1528970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:35,1529098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:35,1533752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54027 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:35,1813318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:35,1813443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:35,1817865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54029 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:35,2519479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:35,2519590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:35,2527134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54028 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:40,8256179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54030 -&gt; 104.31.12.175:http</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:55,2514611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:55,2514705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:55,2520812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54031 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:55,2658428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:55,2658536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:39:55,2663634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54032 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:40:03,0969625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54075 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:40:03,2790254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54075 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:40:03,2790503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54075 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:40:03,2796588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54075 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40865597, endtime: 40865597, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:40:03,2799297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54075 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40865597, endtime: 40865597, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:40:33,3267951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54115 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:40:33,3841959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54075 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:40:33,4908932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54115 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:40:33,4909062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54115 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:40:33,4913922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54115 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40868618, endtime: 40868618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:40:33,4917227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54115 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40868618, endtime: 40868618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:40:36,4085472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 11880, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:41:03,5343409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54160 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:41:03,6280983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54115 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:41:03,7459197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54160 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:41:03,7459327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54160 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:41:03,7466134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54160 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40871643, endtime: 40871643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:41:03,7470349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54160 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40871643, endtime: 40871643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:41:33,8011810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54199 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:41:33,8883523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54160 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:41:33,9867903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54199 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:41:33,9868036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54199 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:41:33,9876553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54199 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40874667, endtime: 40874667, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:41:33,9881869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54199 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40874667, endtime: 40874667, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:42:04,0485117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54251 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:42:04,0918106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54199 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:42:04,2979342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54251 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:42:04,2979425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54251 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:42:04,2991424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54251 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40877698, endtime: 40877699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:42:04,2996032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54251 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40877698, endtime: 40877699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:42:34,3682133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54286 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:42:34,4852770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54251 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:42:34,6229874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54286 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:42:34,6230002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54286 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:42:34,6232695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54286 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40880731, endtime: 40880731, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:42:34,6238859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54286 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40880731, endtime: 40880731, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:43:04,6990330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54327 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:43:04,7281086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54286 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:43:04,9596576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54327 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:43:04,9596709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54327 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:43:04,9599361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54327 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40883765, endtime: 40883765, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:43:04,9605160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54327 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40883765, endtime: 40883765, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:43:35,0355411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54365 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:43:35,1114289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54327 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:43:35,2176777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54365 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:43:35,2176918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54365 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:43:35,2180745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54365 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40886790, endtime: 40886790, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:43:35,2187527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54365 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40886790, endtime: 40886790, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:05,3031357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54397 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:05,4580072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54365 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:05,5287693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54397 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:05,5287823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54397 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:05,5294938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54397 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40889821, endtime: 40889822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:05,5299238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54397 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40889821, endtime: 40889822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:34,6910673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:34,6910878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:34,6911019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x100</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:34,6911108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:34,6911222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:34,6911352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:34,6911416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Software\Classes\Local Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:35,5883793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54442 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:35,7949492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54397 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:35,7953856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54442 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:35,7953964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54442 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:35,7959799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54442 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40892848, endtime: 40892848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:44:35,7963644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54442 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40892848, endtime: 40892848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:45:05,8607677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54478 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:45:05,9964230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54442 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:45:06,1090191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54478 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:45:06,1090332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54478 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:45:06,1096350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54478 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40895880, endtime: 40895880, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:45:06,1099993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54478 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40895880, endtime: 40895880, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:45:36,2009596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54493 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:45:36,2590873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54478 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:45:36,4837574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54493 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:45:36,4837701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54493 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:45:36,4842987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54493 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40898917, endtime: 40898917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:45:36,4846254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54493 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40898917, endtime: 40898917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:46:06,5542230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54528 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:46:06,7558161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54493 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:46:06,8623259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54528 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:46:06,8623378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54528 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:46:06,8628401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54528 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40901955, endtime: 40901955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:46:06,8631396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54528 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40901955, endtime: 40901955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:46:36,9268453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54562 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:46:37,1160572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54528 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:46:37,1163849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54562 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:46:37,1163941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54562 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:46:37,1167930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54562 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40904980, endtime: 40904980, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:46:37,1171175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54562 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40904980, endtime: 40904980, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:47:07,1623881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54583 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:47:07,2600485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54562 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:47:07,3830949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54583 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:47:07,3831076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54583 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:47:07,3836010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54583 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40908007, endtime: 40908007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:47:07,3838562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54583 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40908007, endtime: 40908007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:47:37,4518111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54605 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:47:37,5573606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54583 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:47:37,6702917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54605 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:47:37,6703081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54605 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:47:37,6706857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54605 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40911036, endtime: 40911036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:47:37,6709450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54605 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40911036, endtime: 40911036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:48:07,7362903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54627 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:48:07,9335789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54627 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:48:07,9335919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54627 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:48:07,9336551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54605 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:48:07,9341768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54627 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40914062, endtime: 40914062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:48:07,9343250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54627 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40914062, endtime: 40914062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:48:37,9927223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54642 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:48:38,0787687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54627 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:48:38,1778747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54642 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:48:38,1778861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54642 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:48:38,1782948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54642 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40917086, endtime: 40917086, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:48:38,1784430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54642 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40917086, endtime: 40917086, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:49:08,2634150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54661 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:49:08,3492854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54642 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:49:08,4559224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54661 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:49:08,4559351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54661 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:49:08,4563152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54661 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40920114, endtime: 40920114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:49:08,4564418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54661 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40920114, endtime: 40920114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:49:38,5973836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54749 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:49:38,7196343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54661 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:49:38,9120999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54749 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:49:38,9121073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54749 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:49:38,9125855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54749 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40923160, endtime: 40923160, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:49:38,9127163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54749 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40923160, endtime: 40923160, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:50:09,0153811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54768 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:50:09,1074418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54749 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:50:09,1956554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54768 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:50:09,1956676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54768 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:50:09,1971046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54768 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40926188, endtime: 40926188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:50:09,1972155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54768 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40926188, endtime: 40926188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:50:39,2645816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54801 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:50:39,3977287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54768 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:50:39,5319795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54801 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:50:39,5319856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54801 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:50:39,5332875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54801 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40929222, endtime: 40929222, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:50:39,5336851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54801 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40929222, endtime: 40929222, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:09,5925550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54828 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:09,6177256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54801 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:09,8346048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54828 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:09,8346161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54828 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:09,8348841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54828 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40932252, endtime: 40932252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:09,8350666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54828 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40932252, endtime: 40932252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:39,9353906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54846 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:40,0412470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54828 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:40,1509651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54846 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:40,1509776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54846 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:40,1514547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54846 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40935284, endtime: 40935284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:40,1515965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54846 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40935284, endtime: 40935284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,4372779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54846 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 61, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,4372917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54846 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 61, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,4396176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 9328</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,4545025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 13024</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,4553040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 9864</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5394165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5399737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936123, endtime: 40936123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5458005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936123, endtime: 40936123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5516965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936124, endtime: 40936124, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5546801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5550879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936124, endtime: 40936124, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5574216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936124, endtime: 40936124, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5603262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936125, endtime: 40936125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5632500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936125, endtime: 40936125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5662148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936125, endtime: 40936125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5691560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936126, endtime: 40936126, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5720438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936126, endtime: 40936126, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5769055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936126, endtime: 40936126, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5789059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936126, endtime: 40936126, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5829163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936127, endtime: 40936127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5849233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936127, endtime: 40936127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5887253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936127, endtime: 40936127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5905810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936128, endtime: 40936128, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5944850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936128, endtime: 40936128, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,5964399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936128, endtime: 40936128, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6004384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936129, endtime: 40936129, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6022002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936129, endtime: 40936129, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6060480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936129, endtime: 40936129, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6080123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936129, endtime: 40936129, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6120157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936130, endtime: 40936130, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6139665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936130, endtime: 40936130, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6177649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936130, endtime: 40936130, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6198304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936131, endtime: 40936131, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6236391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936131, endtime: 40936131, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6254776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936131, endtime: 40936131, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6295157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936132, endtime: 40936132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6314917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936132, endtime: 40936132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6352305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936132, endtime: 40936132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6372783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936132, endtime: 40936132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6412019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936133, endtime: 40936133, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6430812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936133, endtime: 40936133, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6473565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936133, endtime: 40936133, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6493817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936134, endtime: 40936134, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6531212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936134, endtime: 40936134, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6550525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936134, endtime: 40936134, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6589742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936134, endtime: 40936135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6609067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936135, endtime: 40936135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6647196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936135, endtime: 40936135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6667227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936135, endtime: 40936135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6707350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936136, endtime: 40936136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6726863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936136, endtime: 40936136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6766211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936136, endtime: 40936136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6785341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936136, endtime: 40936136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6842254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936137, endtime: 40936137, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6846565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936137, endtime: 40936137, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6902583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936138, endtime: 40936138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6904766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936138, endtime: 40936138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6961494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936138, endtime: 40936138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,6961721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936138, endtime: 40936138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7018611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936139, endtime: 40936139, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7758584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936139, endtime: 40936146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7758758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936139, endtime: 40936146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7758872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936140, endtime: 40936146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7758955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936141, endtime: 40936146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7759016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936141, endtime: 40936146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7759085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936142, endtime: 40936146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7759141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936142, endtime: 40936146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7759210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936143, endtime: 40936146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7759268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936143, endtime: 40936146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7759540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936144, endtime: 40936146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7759598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936145, endtime: 40936146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7759678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936145, endtime: 40936146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:48,7791462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936147, endtime: 40936147, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,1635953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936139, endtime: 40936185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,1636122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936140, endtime: 40936185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,1636194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936141, endtime: 40936185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,1636260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936141, endtime: 40936185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,1636313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936142, endtime: 40936185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,1636377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936142, endtime: 40936185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,1636426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936143, endtime: 40936185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,1636490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936143, endtime: 40936185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,1636546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936144, endtime: 40936185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,1637878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936145, endtime: 40936185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,1637942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936145, endtime: 40936185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,1638003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936147, endtime: 40936185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,4702453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936147, endtime: 40936216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,4702614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936148, endtime: 40936216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,4702683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936148, endtime: 40936216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,4702755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936149, endtime: 40936216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,4702808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936149, endtime: 40936216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,4702872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936150, endtime: 40936216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,4702927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936151, endtime: 40936216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,4702991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936151, endtime: 40936216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,4703046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936152, endtime: 40936216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,4703575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936152, endtime: 40936216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,4703639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936153, endtime: 40936216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:49,4703711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936153, endtime: 40936216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,3842737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936147, endtime: 40936407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,3842937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936185, endtime: 40936407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,3843014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936185, endtime: 40936407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,3843092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936186, endtime: 40936407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,3843153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936187, endtime: 40936407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,3843222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936188, endtime: 40936407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,3843280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936188, endtime: 40936407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,3843350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936189, endtime: 40936407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,3843408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936189, endtime: 40936407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,3843732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936190, endtime: 40936407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,3843793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936190, endtime: 40936407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,3843956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936191, endtime: 40936407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,3844017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936192, endtime: 40936407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,4597319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54846 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 58, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,4597427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54846 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 58, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,4598253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54848 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,4610111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 336</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,4647269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 5892</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,4653002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 8696</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5526842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5529588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5531721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936424, endtime: 40936424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5532541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936424, endtime: 40936424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5584550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936424, endtime: 40936424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5596026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936425, endtime: 40936425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5644660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936425, endtime: 40936425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5653132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936425, endtime: 40936425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5702875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936426, endtime: 40936426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5725541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936426, endtime: 40936426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5794029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936427, endtime: 40936427, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5796041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936427, endtime: 40936427, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5849679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936427, endtime: 40936427, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5849837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936427, endtime: 40936427, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5909102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936428, endtime: 40936428, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5909290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936428, endtime: 40936428, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5966461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936428, endtime: 40936428, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,5968428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936428, endtime: 40936428, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6041684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936429, endtime: 40936429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6043626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936429, endtime: 40936429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6104825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936430, endtime: 40936430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6105036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936430, endtime: 40936430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6162749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936430, endtime: 40936430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6162935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936430, endtime: 40936430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6220269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936431, endtime: 40936431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6222059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936431, endtime: 40936431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6274300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936431, endtime: 40936431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6274993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936431, endtime: 40936431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6333133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936432, endtime: 40936432, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6335372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936432, endtime: 40936432, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6392107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936433, endtime: 40936433, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6392315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936433, endtime: 40936433, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6451142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936433, endtime: 40936433, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6451347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936433, endtime: 40936433, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6509942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936434, endtime: 40936434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6511676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936434, endtime: 40936434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6578308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936434, endtime: 40936434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6578500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936434, endtime: 40936434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6637011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936435, endtime: 40936435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6637194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936435, endtime: 40936435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6696564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936436, endtime: 40936436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6696744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936436, endtime: 40936436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6753627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936436, endtime: 40936436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6755533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936436, endtime: 40936436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6813571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936437, endtime: 40936437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6813759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936437, endtime: 40936437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6870578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936437, endtime: 40936437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6870805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936437, endtime: 40936437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6929627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936438, endtime: 40936438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6931890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936438, endtime: 40936438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6987116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936438, endtime: 40936438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:51,6987847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936438, endtime: 40936438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0306882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936439, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0307064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936440, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0307136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936440, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0307209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936441, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0307267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936441, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0307333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936442, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0307389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936443, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0307455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936443, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0307510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936444, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0307857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936444, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0307915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936445, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0307981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936445, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0308034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936446, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0308142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936439, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0308209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936440, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0308267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936440, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0308333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936441, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0308389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936441, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0308452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936442, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0309032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936443, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0309106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936443, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0309159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936444, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0309223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936444, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0309275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936445, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0309342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936445, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:52,0309394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936446, endtime: 40936472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:53,8600801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936472, endtime: 40936655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:53,8601025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936472, endtime: 40936655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:53,8601131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936473, endtime: 40936655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:53,8601241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936473, endtime: 40936655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:53,8601333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936474, endtime: 40936655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:53,8601441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936475, endtime: 40936655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:53,8601527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936475, endtime: 40936655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:53,8601635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936476, endtime: 40936655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:53,8601724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936476, endtime: 40936655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:53,8602122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936477, endtime: 40936655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:53,8602211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936478, endtime: 40936655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:53,8602316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936478, endtime: 40936655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:53,8602405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936479, endtime: 40936655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,1935037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936154, endtime: 40936688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,1935215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936216, endtime: 40936688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,1935284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936216, endtime: 40936688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,1935356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936217, endtime: 40936688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,1935411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936217, endtime: 40936688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,1935475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936218, endtime: 40936688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,1935528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936219, endtime: 40936688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,1935592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936219, endtime: 40936688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,1935644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936220, endtime: 40936688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,1935932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936220, endtime: 40936688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,1935988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936221, endtime: 40936688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,1936051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936222, endtime: 40936688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,1937331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936222, endtime: 40936688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,4670969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,5549937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,5554478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936724, endtime: 40936724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,5611244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936725, endtime: 40936725, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,5669645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936725, endtime: 40936725, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,5728522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936726, endtime: 40936726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,5787405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936726, endtime: 40936726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,5845520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936727, endtime: 40936727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,5906021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936728, endtime: 40936728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,5962244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936728, endtime: 40936728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6030652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936729, endtime: 40936729, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6089169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936729, endtime: 40936730, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6148184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936730, endtime: 40936730, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6207092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936731, endtime: 40936731, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6264698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936731, endtime: 40936731, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6323575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936732, endtime: 40936732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6514278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6514536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6514851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6515093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6515189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6515419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6515719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6515802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6515885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6516062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6516231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6516486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6516542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6516675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6516769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6516927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6517071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6517146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6517220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6517348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6517420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6517605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6517755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6517891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6517971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6518040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:54,6521348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54853 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,4335063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936407, endtime: 40936812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,4335249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936408, endtime: 40936812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,4335326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936408, endtime: 40936812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,4335404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936409, endtime: 40936812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,4335462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936410, endtime: 40936812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,4335529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936410, endtime: 40936812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,4335584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936411, endtime: 40936812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,4335651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936411, endtime: 40936812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,4335706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936412, endtime: 40936812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,4335969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936412, endtime: 40936812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,4340133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936413, endtime: 40936812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,4340252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936415, endtime: 40936812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,4340316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936415, endtime: 40936812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,5069345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936472, endtime: 40936819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,5069533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936472, endtime: 40936819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,5069611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936473, endtime: 40936819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,5069769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936473, endtime: 40936819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,5069846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936474, endtime: 40936819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,5069918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936475, endtime: 40936819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,5069976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936475, endtime: 40936819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,5070129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936476, endtime: 40936819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,5070278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936476, endtime: 40936819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,5070799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936477, endtime: 40936819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,5072309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936478, endtime: 40936819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,5072440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936478, endtime: 40936819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:55,5072506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936479, endtime: 40936819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:56,7754652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936655, endtime: 40936946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:56,7754874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936655, endtime: 40936946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:56,7777077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936656, endtime: 40936946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:56,7777227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936656, endtime: 40936946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:56,7777302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936657, endtime: 40936946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:56,7777376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936658, endtime: 40936946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:56,7777437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936658, endtime: 40936946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:56,7777507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936659, endtime: 40936946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:56,7777565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936659, endtime: 40936946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:56,7777634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936660, endtime: 40936946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:56,7777690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936660, endtime: 40936946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:56,7782339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936661, endtime: 40936946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:56,7782422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936662, endtime: 40936946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,4595740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54848 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,6527289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,7311094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936812, endtime: 40937042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,7311274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936813, endtime: 40937042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,7311354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936813, endtime: 40937042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,7311432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936814, endtime: 40937042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,7311490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936815, endtime: 40937042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,7311562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936815, endtime: 40937042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,7311618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936816, endtime: 40937042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,7311687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936816, endtime: 40937042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,7311742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936817, endtime: 40937042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,7312402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936817, endtime: 40937042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,7312476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936818, endtime: 40937042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,7312546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936819, endtime: 40937042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:57,7317477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936819, endtime: 40937042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:59,2594727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936688, endtime: 40937195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:59,2594888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936689, endtime: 40937195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:59,2594968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936689, endtime: 40937195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:59,2595027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936690, endtime: 40937195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:59,2595093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936690, endtime: 40937195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:59,2595146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936691, endtime: 40937195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:59,2595209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936691, endtime: 40937195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:59,2595262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936692, endtime: 40937195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:59,2595326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936693, endtime: 40937195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:59,2596631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936694, endtime: 40937195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:59,2596766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936694, endtime: 40937195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:59,2596836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936695, endtime: 40937195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:51:59,2596910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936695, endtime: 40937195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:00,2973017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937042, endtime: 40937298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:00,2973191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937042, endtime: 40937298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:00,2973263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937043, endtime: 40937298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:00,2973338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937043, endtime: 40937298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:00,2973396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937044, endtime: 40937298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:00,2973463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937045, endtime: 40937298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:00,2973518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937045, endtime: 40937298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:00,2973585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937046, endtime: 40937298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:00,2973640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937046, endtime: 40937298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:00,2974189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937047, endtime: 40937298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:00,2974391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937048, endtime: 40937298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:00,2974466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937048, endtime: 40937298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:00,3873964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937049, endtime: 40937307, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,5566090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,6710517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,6719463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937436, endtime: 40937436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,6778966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937436, endtime: 40937436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,6838195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937437, endtime: 40937437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,6895158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937438, endtime: 40937438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,6955420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937438, endtime: 40937438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7013320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937439, endtime: 40937439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7082960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937439, endtime: 40937439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7140045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937440, endtime: 40937440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7199249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937441, endtime: 40937441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7258451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937441, endtime: 40937441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7315391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937442, endtime: 40937442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7385603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937442, endtime: 40937442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7442515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937443, endtime: 40937443, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7502351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937444, endtime: 40937444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7560580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937444, endtime: 40937444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7618136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937445, endtime: 40937445, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7678044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937445, endtime: 40937445, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7736092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937446, endtime: 40937446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7794737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937447, endtime: 40937447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7851400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937447, endtime: 40937447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7912621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937448, endtime: 40937448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,7969379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937448, endtime: 40937448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,8029608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937449, endtime: 40937449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,8086807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937449, endtime: 40937449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:01,8144720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937450, endtime: 40937450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:02,1241605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937451, endtime: 40937481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:02,1241874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937451, endtime: 40937481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:02,1241993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937452, endtime: 40937481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:02,1242118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937452, endtime: 40937481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:02,1242217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937453, endtime: 40937481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:02,1242331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937454, endtime: 40937481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:02,1242428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937454, endtime: 40937481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:02,1242541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937455, endtime: 40937481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:02,1242636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937455, endtime: 40937481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:02,1243361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937456, endtime: 40937481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:02,1243478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937457, endtime: 40937481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:02,1243591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937457, endtime: 40937481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:02,1243688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937458, endtime: 40937481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,2722844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937298, endtime: 40937596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,2723013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937299, endtime: 40937596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,2723101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937299, endtime: 40937596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,2723168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937300, endtime: 40937596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,2723243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937301, endtime: 40937596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,2723301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937301, endtime: 40937596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,2723370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937302, endtime: 40937596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,2723431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937303, endtime: 40937596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,2723500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937304, endtime: 40937596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,2724160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937304, endtime: 40937596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,2724243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937305, endtime: 40937596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,2724295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937306, endtime: 40937596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,2726116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937307, endtime: 40937596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6146201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936819, endtime: 40937630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6146353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936820, endtime: 40937630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6146433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936821, endtime: 40937630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6146494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936821, endtime: 40937630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6146561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936822, endtime: 40937630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6146611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936822, endtime: 40937630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6146674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936823, endtime: 40937630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6146727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936823, endtime: 40937630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6146791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936824, endtime: 40937630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6147073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936825, endtime: 40937630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6147140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936825, endtime: 40937630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6148259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936827, endtime: 40937630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6148331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936828, endtime: 40937630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,6519902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,7385802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,7392512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937642, endtime: 40937643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,7447796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937643, endtime: 40937643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,7500129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937644, endtime: 40937644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,7558264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937644, endtime: 40937644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,7615324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937645, endtime: 40937645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,7675290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937645, endtime: 40937645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,7732909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937646, endtime: 40937646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,7791794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937647, endtime: 40937647, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,7849791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937647, endtime: 40937647, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,7910463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937648, endtime: 40937648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,7968642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937648, endtime: 40937648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8036294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937649, endtime: 40937649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8094733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937650, endtime: 40937650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8153450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937650, endtime: 40937650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8210856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937651, endtime: 40937651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8269772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937651, endtime: 40937651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8328388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937652, endtime: 40937652, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8397771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937653, endtime: 40937653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8456779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937653, endtime: 40937653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8514509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937654, endtime: 40937654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8572705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937654, endtime: 40937654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8631316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937655, endtime: 40937655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8690628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937655, endtime: 40937656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8748203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937656, endtime: 40937656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,8807662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937657, endtime: 40937657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,9021671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937657, endtime: 40937659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,9021837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937658, endtime: 40937659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,9021912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937658, endtime: 40937659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,9040586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937659, endtime: 40937659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,9096460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937660, endtime: 40937660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,9147649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937660, endtime: 40937660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,9207072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937661, endtime: 40937661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,9268434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937661, endtime: 40937661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,9338507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937662, endtime: 40937662, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,9399656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937663, endtime: 40937663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,9451521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937663, endtime: 40937663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,9509276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937664, endtime: 40937664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:03,9567984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937664, endtime: 40937664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,6510402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936948, endtime: 40937734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,6510624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936948, endtime: 40937734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,6510732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936949, endtime: 40937734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,6510842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936949, endtime: 40937734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,6510931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936950, endtime: 40937734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,6511039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936950, endtime: 40937734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,6511125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936951, endtime: 40937734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,6511230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936952, endtime: 40937734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,6511316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936952, endtime: 40937734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,6511710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936953, endtime: 40937734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,6511798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936953, endtime: 40937734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,6511901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936954, endtime: 40937734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,6511989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40936955, endtime: 40937734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,8479780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937596, endtime: 40937753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,8479952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937596, endtime: 40937753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,8480024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937597, endtime: 40937753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,8480096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937598, endtime: 40937753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,8480151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937598, endtime: 40937753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,8480215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937599, endtime: 40937753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,8480268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937599, endtime: 40937753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,8480329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937600, endtime: 40937753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,8480381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937601, endtime: 40937753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,8481063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937601, endtime: 40937753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,8481780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937602, endtime: 40937753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,8481891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937602, endtime: 40937753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:04,8482769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937603, endtime: 40937753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,4130967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937195, endtime: 40937910, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,4131139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937195, endtime: 40937910, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,4131222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937196, endtime: 40937910, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,4131283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937196, endtime: 40937910, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,4131349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937197, endtime: 40937910, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,4131405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937197, endtime: 40937910, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,4131466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937198, endtime: 40937910, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,4131518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937199, endtime: 40937910, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,4131585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937199, endtime: 40937910, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,4131901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937200, endtime: 40937910, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,4131959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937200, endtime: 40937910, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,4132023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937201, endtime: 40937910, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,4133389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937201, endtime: 40937910, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,8695651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937630, endtime: 40937956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,8695815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937631, endtime: 40937956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,8695884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937631, endtime: 40937956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,8695953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937632, endtime: 40937956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,8696006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937632, endtime: 40937956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,8696069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937633, endtime: 40937956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,8696122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937634, endtime: 40937956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,8696186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937634, endtime: 40937956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,8696236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937635, endtime: 40937956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,8696518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937635, endtime: 40937956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,8697471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937636, endtime: 40937956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,8697596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937636, endtime: 40937956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,8697668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937637, endtime: 40937956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,9392134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937734, endtime: 40937963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,9392347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937734, endtime: 40937963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,9392453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937735, endtime: 40937963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,9392561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937736, endtime: 40937963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,9392646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937736, endtime: 40937963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,9392749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937737, endtime: 40937963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,9392835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937737, endtime: 40937963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,9392937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937738, endtime: 40937963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,9393021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937739, endtime: 40937963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,9393516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937739, endtime: 40937963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,9394841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937740, endtime: 40937963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,9395021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937740, endtime: 40937963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:06,9395129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937741, endtime: 40937963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,2416226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937753, endtime: 40937993, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,2416386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937754, endtime: 40937993, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,2416456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937755, endtime: 40937993, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,2416525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937755, endtime: 40937993, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,2416580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937756, endtime: 40937993, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,2416644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937756, endtime: 40937993, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,2416694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937757, endtime: 40937993, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,2416758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937758, endtime: 40937993, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,2416807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937758, endtime: 40937993, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,2417464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937759, endtime: 40937993, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,2417528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937759, endtime: 40937993, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,2417592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937760, endtime: 40937993, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,2418644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937760, endtime: 40937993, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,8039319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937481, endtime: 40938049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,8039474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937482, endtime: 40938049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,8039555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937482, endtime: 40938049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,8039613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937483, endtime: 40938049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,8039679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937483, endtime: 40938049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,8039732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937484, endtime: 40938049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,8039798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937485, endtime: 40938049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,8039851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937485, endtime: 40938049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,8039915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937486, endtime: 40938049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,8040200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937486, endtime: 40938049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,8041353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937487, endtime: 40938049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,8041563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937487, endtime: 40938049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:07,8041682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937488, endtime: 40938049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,1948910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937910, endtime: 40938188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,1949223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937911, endtime: 40938188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,1949353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937911, endtime: 40938188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,1949491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937912, endtime: 40938188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,1949608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937912, endtime: 40938188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,1949741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937913, endtime: 40938188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,1949852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937914, endtime: 40938188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,1949932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937914, endtime: 40938188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,1949998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937915, endtime: 40938188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,1950647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937915, endtime: 40938188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,1950771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937916, endtime: 40938188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,1950888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937916, endtime: 40938188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,1950993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937917, endtime: 40938188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,2248125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937956, endtime: 40938191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,2248288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937956, endtime: 40938191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,2248357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937957, endtime: 40938191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,2248429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937957, endtime: 40938191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,2248482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937958, endtime: 40938191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,2248549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937958, endtime: 40938191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,2248598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937959, endtime: 40938191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,2248662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937960, endtime: 40938191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,2248715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937960, endtime: 40938191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,2248997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937961, endtime: 40938191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,2249050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937961, endtime: 40938191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,2249114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937962, endtime: 40938191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,2249166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937963, endtime: 40938191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,7960001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937963, endtime: 40938248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,7960228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937963, endtime: 40938248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,7960342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937964, endtime: 40938248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,7960433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937964, endtime: 40938248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,7960494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937965, endtime: 40938248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,7960569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937965, endtime: 40938248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,7960630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937966, endtime: 40938248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,7960702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937967, endtime: 40938248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,7960757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937967, endtime: 40938248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,7961095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937968, endtime: 40938248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,7963151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937968, endtime: 40938248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,7963312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937969, endtime: 40938248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,7963392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937969, endtime: 40938248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,8737345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938049, endtime: 40938256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,8737511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938050, endtime: 40938256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,8737581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938050, endtime: 40938256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,8737653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938051, endtime: 40938256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,8737708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938051, endtime: 40938256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,8737772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938052, endtime: 40938256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,8737825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938052, endtime: 40938256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,8737888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938053, endtime: 40938256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,8737938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938054, endtime: 40938256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,8739024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938054, endtime: 40938256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,8739138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938055, endtime: 40938256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,8739218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938055, endtime: 40938256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:09,8739285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938056, endtime: 40938256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:11,3588145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937993, endtime: 40938404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:11,3588356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937993, endtime: 40938404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:11,3588458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937994, endtime: 40938404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:11,3588566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937995, endtime: 40938404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:11,3588652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937995, endtime: 40938404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:11,3588752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937996, endtime: 40938404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:11,3588835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937996, endtime: 40938404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:11,3589062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937997, endtime: 40938404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:11,3589151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937998, endtime: 40938404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:11,3589583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937998, endtime: 40938405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:11,3589669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937999, endtime: 40938405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:11,3589771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937999, endtime: 40938405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:11,3589857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938000, endtime: 40938405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:12,6876149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937665, endtime: 40938537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:12,6876349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937667, endtime: 40938537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:12,6876443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937667, endtime: 40938537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:12,6876518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937668, endtime: 40938537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:12,6876595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937668, endtime: 40938537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:12,6876659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937669, endtime: 40938537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:12,6876734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937670, endtime: 40938537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:12,6876795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937670, endtime: 40938537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:12,6876870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937671, endtime: 40938537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:12,6877169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937671, endtime: 40938537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:12,6877249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937672, endtime: 40938537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:12,6877313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937673, endtime: 40938537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:12,6877388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40937673, endtime: 40938537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:13,4194377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938188, endtime: 40938611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:13,4194568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938189, endtime: 40938611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:13,4194640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938189, endtime: 40938611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:13,4194715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938190, endtime: 40938611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:13,4194773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938191, endtime: 40938611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:13,4194842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938191, endtime: 40938611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:13,4194898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938192, endtime: 40938611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:13,4194967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938192, endtime: 40938611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:13,4195020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938193, endtime: 40938611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:13,4195554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938193, endtime: 40938611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:13,4195665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938194, endtime: 40938611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:13,4195740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938195, endtime: 40938611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:13,4195795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938195, endtime: 40938611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4224853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938405, endtime: 40938811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4225019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938405, endtime: 40938811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4225094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938406, endtime: 40938811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4225169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938407, endtime: 40938811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4225224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938408, endtime: 40938811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4225291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938408, endtime: 40938811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4225346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938409, endtime: 40938811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4225413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938409, endtime: 40938811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4225465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938410, endtime: 40938811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4225737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938411, endtime: 40938811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4225795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938411, endtime: 40938811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4225859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938412, endtime: 40938811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4225914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938412, endtime: 40938811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4367437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938611, endtime: 40938812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4367650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938611, endtime: 40938812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4367736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938612, endtime: 40938812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4367814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938612, endtime: 40938812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4367875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938613, endtime: 40938812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4367941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938613, endtime: 40938812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4368000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938614, endtime: 40938812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4368069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938615, endtime: 40938812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4368127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938615, endtime: 40938812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4368432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938616, endtime: 40938812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4368493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938616, endtime: 40938812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4368562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938617, endtime: 40938812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,4368617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938618, endtime: 40938812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:15,5084888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938812, endtime: 40938819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:16,9727519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938248, endtime: 40938966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:16,9727685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938249, endtime: 40938966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:16,9727768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938249, endtime: 40938966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:16,9727829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938250, endtime: 40938966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:16,9727893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938251, endtime: 40938966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:16,9727948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938251, endtime: 40938966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:16,9728012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938252, endtime: 40938966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:16,9728067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938252, endtime: 40938966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:16,9728131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938253, endtime: 40938966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:16,9732647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938254, endtime: 40938966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:16,9732738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938254, endtime: 40938966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:16,9732797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938255, endtime: 40938966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:16,9732863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938255, endtime: 40938966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,0595483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938191, endtime: 40938975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,0595754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938192, endtime: 40938975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,0595859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938192, endtime: 40938975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,0595923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938193, endtime: 40938975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,0596001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938193, endtime: 40938975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,0596059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938194, endtime: 40938975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,0596131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938195, endtime: 40938975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,0596192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938195, endtime: 40938975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,0596261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938196, endtime: 40938975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,0596574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938196, endtime: 40938975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,0596643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938197, endtime: 40938975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,0596696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938198, endtime: 40938975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,0596763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938198, endtime: 40938975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,1347712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938811, endtime: 40938982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,1347898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938811, endtime: 40938982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,1347972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938812, endtime: 40938982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,1348047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938813, endtime: 40938982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,1348105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938813, endtime: 40938982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,1348172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938814, endtime: 40938982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,1348224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938814, endtime: 40938982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,1348294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938815, endtime: 40938982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,1348349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938816, endtime: 40938982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,1348654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938816, endtime: 40938982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,1348712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938817, endtime: 40938982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,1348776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938817, endtime: 40938982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:17,1348831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938818, endtime: 40938982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,0751980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938813, endtime: 40939076, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,0752136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938813, endtime: 40939076, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,0752216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938814, endtime: 40939076, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,0752277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938815, endtime: 40939076, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,0752341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938815, endtime: 40939076, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,0752396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938816, endtime: 40939076, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,0752460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938816, endtime: 40939076, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,0752512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938817, endtime: 40939076, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,0753080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938817, endtime: 40939076, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,0753150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938818, endtime: 40939076, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,0754172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938819, endtime: 40939076, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,0754250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938819, endtime: 40939076, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,1483954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938256, endtime: 40939083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,1484137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938257, endtime: 40939083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,1484231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938257, endtime: 40939083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,1484295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938258, endtime: 40939083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,1484367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938258, endtime: 40939083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,1484425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938259, endtime: 40939083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,1484494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938260, endtime: 40939083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,1484553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938260, endtime: 40939083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,1484622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938261, endtime: 40939083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,1484921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938261, endtime: 40939083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,1484996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938262, endtime: 40939083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,1485051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938263, endtime: 40939083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,1485121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938263, endtime: 40939083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,5414163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938537, endtime: 40939123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,5414329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938538, endtime: 40939123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,5414399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938539, endtime: 40939123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,5414468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938539, endtime: 40939123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,5414521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938540, endtime: 40939123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,5414587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938540, endtime: 40939123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,5414640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938541, endtime: 40939123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,5414703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938541, endtime: 40939123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,5414756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938542, endtime: 40939123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,5415041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938543, endtime: 40939123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,5416094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938543, endtime: 40939123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,5416247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938544, endtime: 40939123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:18,5416341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938544, endtime: 40939123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,0803643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938975, endtime: 40939377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,0803809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938975, endtime: 40939377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,0803881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938976, endtime: 40939377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,0803951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938977, endtime: 40939377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,0804006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938977, endtime: 40939377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,0804070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938978, endtime: 40939377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,0804122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938978, endtime: 40939377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,0804186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938979, endtime: 40939377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,0804239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938979, endtime: 40939377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,0804541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938980, endtime: 40939377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,0804593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938981, endtime: 40939377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,0804657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938981, endtime: 40939377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,0805812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938982, endtime: 40939377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,5757837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54846 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,6054429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54863 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,9852355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54863 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,9852487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54863 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,9855327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54863 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40939467, endtime: 40939467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:21,9856945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54863 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40939467, endtime: 40939467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,5178801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938982, endtime: 40939520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,5178954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938983, endtime: 40939520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,5179037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938983, endtime: 40939520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,5179103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938984, endtime: 40939520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,5179170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938984, endtime: 40939520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,5179225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938985, endtime: 40939520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,5179289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938986, endtime: 40939520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,5179342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938986, endtime: 40939520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,5179405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938987, endtime: 40939520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,5179702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938988, endtime: 40939520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,5179768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938988, endtime: 40939520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,5179824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938989, endtime: 40939520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,5179887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938990, endtime: 40939520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6426928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938820, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6427105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939076, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6427191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939077, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6427255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939077, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6427324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939078, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6427379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939078, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6427446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939079, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6427498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939080, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6427568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939080, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6427623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939081, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6427922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939081, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6427981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939082, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6428047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939083, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:22,6437082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939533, endtime: 40939533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1157092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939377, endtime: 40939580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1157266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939377, endtime: 40939580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1157338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939378, endtime: 40939580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1157410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939378, endtime: 40939580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1157466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939379, endtime: 40939580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1157530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939380, endtime: 40939580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1157585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939380, endtime: 40939580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1157649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939381, endtime: 40939580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1157701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939381, endtime: 40939580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1158014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939382, endtime: 40939580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1158070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939382, endtime: 40939580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1158134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939383, endtime: 40939580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1158189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939384, endtime: 40939580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1733884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938966, endtime: 40939586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1734058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938966, endtime: 40939586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1734141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938967, endtime: 40939586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1734202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938968, endtime: 40939586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1734363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938968, endtime: 40939586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1734463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938969, endtime: 40939586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1734538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938969, endtime: 40939586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1734598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938970, endtime: 40939586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1734671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938971, endtime: 40939586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1734997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938971, endtime: 40939586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1735069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938972, endtime: 40939586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1735125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938972, endtime: 40939586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:23,1735194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40938973, endtime: 40939586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:24,7255749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939534, endtime: 40939741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:24,7255913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939534, endtime: 40939741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:24,7255985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939535, endtime: 40939741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:24,7256054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939535, endtime: 40939741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:24,7256112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939536, endtime: 40939741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:24,7256179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939536, endtime: 40939741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:24,7256229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939537, endtime: 40939741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:24,7256292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939538, endtime: 40939741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:24,7256345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939538, endtime: 40939741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:24,7257002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939539, endtime: 40939741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:24,7257068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939539, endtime: 40939741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:24,7258265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939540, endtime: 40939741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:24,7258351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939541, endtime: 40939741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,5056470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939123, endtime: 40939819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,5056620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939123, endtime: 40939819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,5056700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939124, endtime: 40939819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,5056761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939125, endtime: 40939819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,5056827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939125, endtime: 40939819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,5056880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939126, endtime: 40939819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,5056944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939126, endtime: 40939819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,5056996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939127, endtime: 40939819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,5057063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939127, endtime: 40939819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,5057326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939128, endtime: 40939819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,5058271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939128, endtime: 40939819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,5058337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939129, endtime: 40939819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,5058401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939130, endtime: 40939819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,6619906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939520, endtime: 40939835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,6620119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939521, endtime: 40939835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,6620202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939522, endtime: 40939835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,6620282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939522, endtime: 40939835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,6620343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939523, endtime: 40939835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,6620418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939523, endtime: 40939835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,6620476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939524, endtime: 40939835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,6620690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939525, endtime: 40939835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,6620812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939525, endtime: 40939835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,6621219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939526, endtime: 40939835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,6621285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939526, endtime: 40939835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,6621355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939527, endtime: 40939835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,6621413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939527, endtime: 40939835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,7324337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939083, endtime: 40939842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,7324517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939084, endtime: 40939842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,7324609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939085, endtime: 40939842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,7324675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939085, endtime: 40939842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,7324747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939086, endtime: 40939842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,7324805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939086, endtime: 40939842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,7324872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939088, endtime: 40939842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,7324930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939088, endtime: 40939842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,7324999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939089, endtime: 40939842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,7325293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939089, endtime: 40939842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,7325354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939090, endtime: 40939842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,7325421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939091, endtime: 40939842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,7325479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939091, endtime: 40939842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,9829071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939586, endtime: 40939867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,9829245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939587, endtime: 40939867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,9829320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939588, endtime: 40939867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,9829395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939588, endtime: 40939867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,9829453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939589, endtime: 40939867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,9829520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939589, endtime: 40939867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,9829575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939590, endtime: 40939867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,9829641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939591, endtime: 40939867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,9829697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939591, endtime: 40939867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,9830029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939592, endtime: 40939867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,9830088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939593, endtime: 40939867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,9830154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939593, endtime: 40939867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:25,9830209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939594, endtime: 40939867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,7411086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939580, endtime: 40939943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,7411255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939581, endtime: 40939943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,7411325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939581, endtime: 40939943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,7411394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939582, endtime: 40939943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,7411446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939583, endtime: 40939943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,7411510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939583, endtime: 40939943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,7411563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939584, endtime: 40939943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,7411624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939584, endtime: 40939943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,7411676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939585, endtime: 40939943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,7411978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939586, endtime: 40939943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,7412031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939587, endtime: 40939943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,7412967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939588, endtime: 40939943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,7413081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939588, endtime: 40939943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,8807235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939741, endtime: 40939957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,8807396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939742, endtime: 40939957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,8807463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939742, endtime: 40939957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,8807532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939743, endtime: 40939957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,8807587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939744, endtime: 40939957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,8807651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939744, endtime: 40939957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,8807704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939745, endtime: 40939957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,8807767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939745, endtime: 40939957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,8807820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939746, endtime: 40939957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,8808485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939747, endtime: 40939957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,8808551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939747, endtime: 40939957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,8808618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939748, endtime: 40939957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:26,8810355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939748, endtime: 40939957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:28,6936301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939867, endtime: 40940138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:28,6936467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939868, endtime: 40940138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:28,6936539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939868, endtime: 40940138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:28,6936614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939869, endtime: 40940138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:28,6936669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939869, endtime: 40940138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:28,6936736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939870, endtime: 40940138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:28,6936788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939870, endtime: 40940138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:28,6936852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939871, endtime: 40940138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:28,6936908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939872, endtime: 40940138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:28,6937201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939872, endtime: 40940138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:28,6937257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939873, endtime: 40940138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:28,6937323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939873, endtime: 40940138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:28,6937376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939874, endtime: 40940138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,2690231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939842, endtime: 40940196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,2690400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939842, endtime: 40940196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,2690470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939843, endtime: 40940196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,2690542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939844, endtime: 40940196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,2690594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939844, endtime: 40940196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,2690658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939845, endtime: 40940196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,2690711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939845, endtime: 40940196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,2690774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939846, endtime: 40940196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,2690827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939846, endtime: 40940196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,2691104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939847, endtime: 40940196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,2692257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939848, endtime: 40940196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,2692334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939848, endtime: 40940196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,2692387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939849, endtime: 40940196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,3274678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939819, endtime: 40940201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,3274839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939820, endtime: 40940201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,3274911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939820, endtime: 40940201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,3274980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939821, endtime: 40940201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,3275033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939821, endtime: 40940201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,3275097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939822, endtime: 40940201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,3275149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939823, endtime: 40940201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,3275213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939823, endtime: 40940201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,3275263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939824, endtime: 40940201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,3275792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939824, endtime: 40940201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,3275892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939825, endtime: 40940201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,3275958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939825, endtime: 40940201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,3276011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939826, endtime: 40940201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,6457667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939957, endtime: 40940233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,6457867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939957, endtime: 40940233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,6457939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939958, endtime: 40940233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,6458013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939958, endtime: 40940233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,6458072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939959, endtime: 40940233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,6458138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939960, endtime: 40940233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,6458191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939960, endtime: 40940233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,6458257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939961, endtime: 40940233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,6458313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939961, endtime: 40940233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,6458623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939962, endtime: 40940233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,6458681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939963, endtime: 40940233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,6458745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939963, endtime: 40940233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,6458798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939964, endtime: 40940233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,7826615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939943, endtime: 40940247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,7826873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939943, endtime: 40940247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,7826981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939944, endtime: 40940247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,7827091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939945, endtime: 40940247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,7827183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939945, endtime: 40940247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,7827294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939946, endtime: 40940247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,7827388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939946, endtime: 40940247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,7827501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939947, endtime: 40940247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,7827596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939948, endtime: 40940247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,7828153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939948, endtime: 40940247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,7828250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939949, endtime: 40940247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,7828352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939949, endtime: 40940247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:29,7828435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939950, endtime: 40940247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:30,1204704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939835, endtime: 40940281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:30,1204876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939835, endtime: 40940281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:30,1204945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939836, endtime: 40940281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:30,1205014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939837, endtime: 40940281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:30,1205070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939837, endtime: 40940281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:30,1205136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939838, endtime: 40940281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:30,1205189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939838, endtime: 40940281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:30,1205255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939839, endtime: 40940281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:30,1205308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939840, endtime: 40940281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:30,1205624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939840, endtime: 40940281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:30,1205679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939841, endtime: 40940281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:30,1205743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939841, endtime: 40940281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:30,1205795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40939842, endtime: 40940281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:31,8808039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940247, endtime: 40940457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:31,8808205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940248, endtime: 40940457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:31,8808277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940248, endtime: 40940457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:31,8808349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940249, endtime: 40940457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:31,8808405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940249, endtime: 40940457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:31,8808468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940250, endtime: 40940457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:31,8808521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940250, endtime: 40940457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:31,8808585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940251, endtime: 40940457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:31,8808637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940252, endtime: 40940457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:31,8808928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940252, endtime: 40940457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:31,8808984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940253, endtime: 40940457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:31,8809045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940253, endtime: 40940457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:31,8809100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940254, endtime: 40940457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,3700203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940138, endtime: 40940506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,3700369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940139, endtime: 40940506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,3700439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940139, endtime: 40940506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,3700508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940140, endtime: 40940506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,3700563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940140, endtime: 40940506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,3700627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940141, endtime: 40940506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,3700680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940141, endtime: 40940506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,3700746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940142, endtime: 40940506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,3700802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940143, endtime: 40940506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,3702192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940143, endtime: 40940506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,3702262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940144, endtime: 40940506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,3702328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940144, endtime: 40940506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,3702381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940145, endtime: 40940506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,6075405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940233, endtime: 40940529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,6075557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940234, endtime: 40940529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,6075629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940234, endtime: 40940529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,6075698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940235, endtime: 40940529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,6075754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940236, endtime: 40940529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,6075820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940236, endtime: 40940529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,6075876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940237, endtime: 40940529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,6075939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940237, endtime: 40940529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,6075992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940238, endtime: 40940529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,6076297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940239, endtime: 40940529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,6076352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940239, endtime: 40940529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,6076416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940240, endtime: 40940529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:32,6077452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940240, endtime: 40940529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,0174698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940281, endtime: 40940570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,0174856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940281, endtime: 40940570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,0174928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940282, endtime: 40940570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,0174997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940282, endtime: 40940570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,0175058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940283, endtime: 40940570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,0175122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940284, endtime: 40940570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,0175177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940284, endtime: 40940570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,0175241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940285, endtime: 40940570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,0175294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940285, endtime: 40940570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,0175599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940286, endtime: 40940570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,0175651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940287, endtime: 40940570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,0175715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940287, endtime: 40940570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,0175770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940288, endtime: 40940570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,1586249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940196, endtime: 40940584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,1586412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940196, endtime: 40940584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,1586484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940197, endtime: 40940584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,1586556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940197, endtime: 40940584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,1586612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940198, endtime: 40940584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,1586675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940199, endtime: 40940584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,1586731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940199, endtime: 40940584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,1586795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940200, endtime: 40940584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,1586847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940200, endtime: 40940584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,1587623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940201, endtime: 40940584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,1587692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940201, endtime: 40940584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,1589097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940202, endtime: 40940585, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,1589186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940203, endtime: 40940585, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,5007329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940201, endtime: 40940619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,5007495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940202, endtime: 40940619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,5007564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940203, endtime: 40940619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,5007636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940203, endtime: 40940619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,5007692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940204, endtime: 40940619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,5007758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940205, endtime: 40940619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,5007811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940205, endtime: 40940619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,5007874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940206, endtime: 40940619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,5007927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940206, endtime: 40940619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,5008719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940207, endtime: 40940619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,5008789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940207, endtime: 40940619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,5008855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940208, endtime: 40940619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:33,5009908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940209, endtime: 40940619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:34,9576407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940457, endtime: 40940764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:34,9576576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940457, endtime: 40940764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:34,9576642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940458, endtime: 40940764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:34,9576714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940458, endtime: 40940764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:34,9576770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940459, endtime: 40940764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:34,9576833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940460, endtime: 40940764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:34,9576886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940460, endtime: 40940764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:34,9576952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940461, endtime: 40940764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:34,9577002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940461, endtime: 40940764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:34,9577288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940462, endtime: 40940764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:34,9577343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940463, endtime: 40940764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:34,9578324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940464, endtime: 40940764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:34,9578438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940464, endtime: 40940764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0274278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0274527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0274821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0275048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0275148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0275239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0275416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0275488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0275563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0275713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0275779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0276015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0276070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0276198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0276272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0276425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0276563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0276635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0276713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0276843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0276912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0276982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0277104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0277159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0277223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0277295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,0278159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54849 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1210273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1214434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940781, endtime: 40940781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1271998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940781, endtime: 40940781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1331222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940782, endtime: 40940782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1388924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940782, endtime: 40940782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1447186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940783, endtime: 40940783, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1505939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940784, endtime: 40940784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1564916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940784, endtime: 40940784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1624967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940785, endtime: 40940785, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1681567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940785, endtime: 40940785, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1740076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940786, endtime: 40940786, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1835957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940787, endtime: 40940787, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1890650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940787, endtime: 40940788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,1947591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940788, endtime: 40940788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2003617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940789, endtime: 40940789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2059087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940789, endtime: 40940789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2119914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940790, endtime: 40940790, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2179775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940790, endtime: 40940790, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2237657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940791, endtime: 40940791, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2296814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940792, endtime: 40940792, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2363856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940792, endtime: 40940792, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2422958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940793, endtime: 40940793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2482874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940793, endtime: 40940793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2540953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940794, endtime: 40940794, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2600823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940795, endtime: 40940795, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2664304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940795, endtime: 40940795, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2716313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940796, endtime: 40940796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,2774096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940796, endtime: 40940796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,9447398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940797, endtime: 40940863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,9447567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940798, endtime: 40940863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,9447637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940798, endtime: 40940863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,9447711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940799, endtime: 40940863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,9447767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940799, endtime: 40940863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,9447833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940800, endtime: 40940863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,9447886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940800, endtime: 40940863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,9447952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940801, endtime: 40940863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,9448005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940802, endtime: 40940863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,9448332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940802, endtime: 40940863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:35,9449471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940803, endtime: 40940863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,0180505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940529, endtime: 40940870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,0180680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940530, endtime: 40940870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,0180752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940531, endtime: 40940870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,0180821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940531, endtime: 40940870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,0180876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940532, endtime: 40940870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,0180943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940532, endtime: 40940870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,0180996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940533, endtime: 40940870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,0181059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940533, endtime: 40940870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,0181112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940534, endtime: 40940870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,0181420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940535, endtime: 40940870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,0181641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940535, endtime: 40940870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,0182711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940536, endtime: 40940870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,0182835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940536, endtime: 40940870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,1000389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940619, endtime: 40940879, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,1000591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940619, endtime: 40940879, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,1000674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940620, endtime: 40940879, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,1000755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940620, endtime: 40940879, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,1000818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940621, endtime: 40940879, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,1000888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940622, endtime: 40940879, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,1000949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940622, endtime: 40940879, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,1001018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940623, endtime: 40940879, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,1001076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940623, endtime: 40940879, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,1001746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940624, endtime: 40940879, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,1001824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940625, endtime: 40940879, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,1001896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940625, endtime: 40940879, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,8203192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940584, endtime: 40940951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,8203356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940585, endtime: 40940951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,8203425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940586, endtime: 40940951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,8203497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940587, endtime: 40940951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,8203552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940588, endtime: 40940951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,8203616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940588, endtime: 40940951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,8203669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940589, endtime: 40940951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,8203732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940589, endtime: 40940951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,8203785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940590, endtime: 40940951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,8204525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940591, endtime: 40940951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,8204591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940591, endtime: 40940951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,8205240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940592, endtime: 40940951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:36,8205337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940592, endtime: 40940951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8872560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8872792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8873081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8873305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8873399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8873491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8873662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8873734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8873809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8873945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8874011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8874233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8874286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8874410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8874482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8874632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8874768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8874840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8874915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8875042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8875111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8875181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8875300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8875352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8875416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8875485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,8876635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54847 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,9225479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940506, endtime: 40941061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,9225629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940506, endtime: 40941061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,9225709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940507, endtime: 40941061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,9225767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940508, endtime: 40941061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,9225831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940508, endtime: 40941061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,9225884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940509, endtime: 40941061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,9225947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940509, endtime: 40941061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,9225997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940510, endtime: 40941061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,9226061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940510, endtime: 40941061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,9226731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940511, endtime: 40941061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,9226809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940511, endtime: 40941061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,9226862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940512, endtime: 40941061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:37,9228915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940513, endtime: 40941061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,0885001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940626, endtime: 40941077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,0885189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940879, endtime: 40941077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,0885261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940879, endtime: 40941077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,0885333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940880, endtime: 40941077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,0885391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940880, endtime: 40941077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,0885458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940881, endtime: 40941077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,0885513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940882, endtime: 40941077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,0885577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940882, endtime: 40941077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,0885632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940883, endtime: 40941077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,0885923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940883, endtime: 40941077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,0885981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940884, endtime: 40941077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,0886045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940884, endtime: 40941077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,0886100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940885, endtime: 40941077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,9768711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940951, endtime: 40941166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,9768872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940951, endtime: 40941166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,9768950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940952, endtime: 40941166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,9769022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940952, endtime: 40941166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,9769074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940953, endtime: 40941166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,9769141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940953, endtime: 40941166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,9769196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940954, endtime: 40941166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,9769373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940955, endtime: 40941166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,9769432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940956, endtime: 40941166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,9769756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940956, endtime: 40941166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,9769811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940957, endtime: 40941166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,9770947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940958, endtime: 40941166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:38,9771014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940959, endtime: 40941166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,6113818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940764, endtime: 40941230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,6114029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940765, endtime: 40941230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,6114109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940766, endtime: 40941230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,6114192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940766, endtime: 40941230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,6114253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940767, endtime: 40941230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,6114325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940767, endtime: 40941230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,6114384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940768, endtime: 40941230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,6114453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940769, endtime: 40941230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,6114514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940769, endtime: 40941230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,6114827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940770, endtime: 40941230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,6114891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940770, endtime: 40941230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,6114960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940771, endtime: 40941230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,6115018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940772, endtime: 40941230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,7051332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940803, endtime: 40941239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,7051476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940804, endtime: 40941239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,7051562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940863, endtime: 40941239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,7051628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940864, endtime: 40941239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,7051700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940864, endtime: 40941239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,7051758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940865, endtime: 40941239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,7051828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940865, endtime: 40941239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,7051886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940866, endtime: 40941239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,7051955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940867, endtime: 40941239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,7052227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940868, endtime: 40941239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,7052301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940868, endtime: 40941239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,7052357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940869, endtime: 40941239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:39,7052429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40940869, endtime: 40941239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:40,8871665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:41,8222614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941077, endtime: 40941451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:41,8222811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941078, endtime: 40941451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:41,8222883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941079, endtime: 40941451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:41,8222955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941079, endtime: 40941451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:41,8223010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941080, endtime: 40941451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:41,8223077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941080, endtime: 40941451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:41,8223132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941081, endtime: 40941451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:41,8223193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941082, endtime: 40941451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:41,8223246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941082, endtime: 40941451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:41,8223578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941083, endtime: 40941451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:41,8223633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941083, endtime: 40941451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:41,8223697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941084, endtime: 40941451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:41,8223750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941085, endtime: 40941451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,0902239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941166, endtime: 40941478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,0902408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941167, endtime: 40941478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,0902480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941167, endtime: 40941478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,0902552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941168, endtime: 40941478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,0902607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941169, endtime: 40941478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,0902668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941169, endtime: 40941478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,0902724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941170, endtime: 40941478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,0902788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941170, endtime: 40941478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,0902840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941171, endtime: 40941478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,0903137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941172, endtime: 40941478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,0903189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941172, endtime: 40941478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,0903253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941173, endtime: 40941478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,0903306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941174, endtime: 40941478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,4472954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941061, endtime: 40941513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,4473112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941061, endtime: 40941513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,4473184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941062, endtime: 40941513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,4473253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941062, endtime: 40941513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,4473309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941063, endtime: 40941513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,4473372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941064, endtime: 40941513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,4473425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941064, endtime: 40941513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,4473486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941065, endtime: 40941513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,4473539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941066, endtime: 40941513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,4474198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941066, endtime: 40941513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,4474264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941067, endtime: 40941513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,4474328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941067, endtime: 40941513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:42,4476328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941068, endtime: 40941513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,0299900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941230, endtime: 40941672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,0300080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941230, endtime: 40941672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,0300155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941231, endtime: 40941672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,0300227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941232, endtime: 40941672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,0300282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941232, endtime: 40941672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,0300349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941233, endtime: 40941672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,0300401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941233, endtime: 40941672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,0300465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941234, endtime: 40941672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,0300520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941235, endtime: 40941672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,0303236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941235, endtime: 40941672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,0303357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941236, endtime: 40941672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,0303438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941236, endtime: 40941672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,0303501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941237, endtime: 40941672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,7564597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941451, endtime: 40941744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,7564772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941451, endtime: 40941744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,7564841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941452, endtime: 40941744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,7564913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941453, endtime: 40941744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,7564966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941453, endtime: 40941744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,7565030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941454, endtime: 40941744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,7565082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941454, endtime: 40941744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,7565146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941455, endtime: 40941744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,7565199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941455, endtime: 40941744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,7565487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941456, endtime: 40941744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,7565542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941457, endtime: 40941744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,7565606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941457, endtime: 40941744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,7565656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941458, endtime: 40941744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,9965410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941239, endtime: 40941768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,9965585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941240, endtime: 40941768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,9965659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941240, endtime: 40941768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,9965729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941241, endtime: 40941768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,9965784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941241, endtime: 40941768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,9965848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941242, endtime: 40941768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,9965903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941243, endtime: 40941768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,9965970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941243, endtime: 40941768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,9966022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941244, endtime: 40941768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,9966324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941244, endtime: 40941768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,9966382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941245, endtime: 40941768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,9966446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941245, endtime: 40941768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:44,9966499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941246, endtime: 40941768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:45,4008212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941478, endtime: 40941809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:45,4008386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941478, endtime: 40941809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:45,4008458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941479, endtime: 40941809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:45,4008533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941479, endtime: 40941809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:45,4008589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941480, endtime: 40941809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:45,4008655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941481, endtime: 40941809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:45,4008711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941481, endtime: 40941809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:45,4008777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941482, endtime: 40941809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:45,4008832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941482, endtime: 40941809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:45,4009112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941483, endtime: 40941809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:45,4009170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941483, endtime: 40941809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:45,4009237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941484, endtime: 40941809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:45,4009290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941485, endtime: 40941809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,8880605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9117959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941672, endtime: 40941960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9118120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941672, endtime: 40941960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9118192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941673, endtime: 40941960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9118264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941673, endtime: 40941960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9118317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941674, endtime: 40941960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9118380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941675, endtime: 40941960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9118433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941675, endtime: 40941960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9118494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941676, endtime: 40941960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9118547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941676, endtime: 40941960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9118851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941677, endtime: 40941960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9118904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941678, endtime: 40941960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9118968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941678, endtime: 40941960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9119020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941679, endtime: 40941960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9786906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9794176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941966, endtime: 40941967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9850825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941967, endtime: 40941967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9908943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941968, endtime: 40941968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:46,9965513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941968, endtime: 40941968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0025974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941969, endtime: 40941969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0084508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941969, endtime: 40941969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0152678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941970, endtime: 40941970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0211272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941971, endtime: 40941971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0270332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941971, endtime: 40941971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0325932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941972, endtime: 40941972, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0386737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941972, endtime: 40941972, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0445049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941973, endtime: 40941973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0503807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941974, endtime: 40941974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0562075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941974, endtime: 40941974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0620190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941975, endtime: 40941975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0680123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941975, endtime: 40941975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0743832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941976, endtime: 40941976, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0797257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941977, endtime: 40941977, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0854970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941977, endtime: 40941977, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0913571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941978, endtime: 40941978, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,0971561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941978, endtime: 40941978, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1029940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941979, endtime: 40941979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1089767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941979, endtime: 40941980, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1147522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941980, endtime: 40941980, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1210927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941981, endtime: 40941981, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1878690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941981, endtime: 40941987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1878837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941982, endtime: 40941987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1878909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941982, endtime: 40941987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1878981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941983, endtime: 40941987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1879036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941984, endtime: 40941987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1879100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941984, endtime: 40941987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1879155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941985, endtime: 40941987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1879219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941985, endtime: 40941987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1879274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941986, endtime: 40941987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1913050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941988, endtime: 40941988, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,1973482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941988, endtime: 40941988, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,2037044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941989, endtime: 40941989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,2097057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941990, endtime: 40941990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,6474360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941513, endtime: 40942033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,6474529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941514, endtime: 40942033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,6474601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941514, endtime: 40942033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,6474670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941515, endtime: 40942033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,6474723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941516, endtime: 40942033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,6474792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941516, endtime: 40942033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,6474845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941517, endtime: 40942033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,6474908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941517, endtime: 40942033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,6474961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941518, endtime: 40942033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,6475260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941519, endtime: 40942033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,6475449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941519, endtime: 40942033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,6475526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941520, endtime: 40942033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,6476579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941520, endtime: 40942033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,9167746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941744, endtime: 40942060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,9167924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941745, endtime: 40942060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,9167998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941746, endtime: 40942060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,9168070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941746, endtime: 40942060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,9168126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941747, endtime: 40942060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,9168192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941748, endtime: 40942060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,9168245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941748, endtime: 40942060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,9168311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941749, endtime: 40942060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,9168367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941749, endtime: 40942060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,9168644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941750, endtime: 40942060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,9168702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941751, endtime: 40942060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,9168766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941751, endtime: 40942060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:47,9168821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941752, endtime: 40942060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:48,7722328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941960, endtime: 40942146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:48,7722506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941960, endtime: 40942146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:48,7722580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941961, endtime: 40942146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:48,7722655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941962, endtime: 40942146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:48,7722711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941962, endtime: 40942146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:48,7722777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941963, endtime: 40942146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:48,7722830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941963, endtime: 40942146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:48,7722896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941964, endtime: 40942146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:48,7722949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941964, endtime: 40942146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:48,7723248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941965, endtime: 40942146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:48,7723303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941966, endtime: 40942146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:48,7723370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941966, endtime: 40942146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:48,7723423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941967, endtime: 40942146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:49,1785624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941768, endtime: 40942186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:49,1785793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941769, endtime: 40942186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:49,1785865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941770, endtime: 40942186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:49,1785937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941770, endtime: 40942186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:49,1785990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941771, endtime: 40942186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:49,1786053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941771, endtime: 40942186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:49,1786106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941772, endtime: 40942186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:49,1786170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941773, endtime: 40942186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:49,1786222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941773, endtime: 40942186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:49,1786524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941774, endtime: 40942186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:49,1786580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941774, endtime: 40942186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:49,1786643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941775, endtime: 40942186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:49,1786696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941776, endtime: 40942186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,5003840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942186, endtime: 40942419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,5004007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942187, endtime: 40942419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,5004076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942188, endtime: 40942419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,5004148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942188, endtime: 40942419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,5004203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942190, endtime: 40942419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,5004267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942190, endtime: 40942419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,5004320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942191, endtime: 40942419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,5004383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942191, endtime: 40942419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,5004436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942192, endtime: 40942419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,5004744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942193, endtime: 40942419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,5004799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942193, endtime: 40942419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,5004863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942194, endtime: 40942419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,5006035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942194, endtime: 40942419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,6984747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942033, endtime: 40942438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,6984924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942034, endtime: 40942438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,6984996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942035, endtime: 40942438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,6985071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942035, endtime: 40942438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,6985132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942036, endtime: 40942438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,6985198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942036, endtime: 40942438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,6985254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942037, endtime: 40942438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,6985320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942037, endtime: 40942438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,6985376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942038, endtime: 40942438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,6985700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942039, endtime: 40942438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,6985758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942039, endtime: 40942438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,6985825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942040, endtime: 40942438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,6985880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942040, endtime: 40942438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,7731468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942146, endtime: 40942446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,7731635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942146, endtime: 40942446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,7731704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942147, endtime: 40942446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,7731773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942148, endtime: 40942446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,7731828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942148, endtime: 40942446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,7731892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942149, endtime: 40942446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,7731945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942149, endtime: 40942446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,7732009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942150, endtime: 40942446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,7732058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942151, endtime: 40942446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,7732358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942151, endtime: 40942446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,7732410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942152, endtime: 40942446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,7732474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942152, endtime: 40942446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:51,7732527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942153, endtime: 40942446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:52,0443617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54873 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:52,3094340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54863 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:52,4079609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54873 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:52,4079759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54873 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:52,4082610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54873 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40942509, endtime: 40942509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:52,4084388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54873 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40942509, endtime: 40942509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:53,6810891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941809, endtime: 40942637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:53,6811052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941809, endtime: 40942637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:53,6811130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941810, endtime: 40942637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:53,6811188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941810, endtime: 40942637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:53,6811254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941811, endtime: 40942637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:53,6811310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941812, endtime: 40942637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:53,6811373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941812, endtime: 40942637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:53,6811426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941813, endtime: 40942637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:53,6811490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941813, endtime: 40942637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:53,6811897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941814, endtime: 40942637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:53,6813163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941815, endtime: 40942637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:53,6813233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941815, endtime: 40942637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:53,6813296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941816, endtime: 40942637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:54,8032287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942419, endtime: 40942749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:54,8032498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942419, endtime: 40942749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:54,8032587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942420, endtime: 40942749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:54,8032673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942420, endtime: 40942749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:54,8032736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942421, endtime: 40942749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:54,8032817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942422, endtime: 40942749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:54,8032880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942422, endtime: 40942749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:54,8032958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942423, endtime: 40942749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:54,8033022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942423, endtime: 40942749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:54,8033371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942424, endtime: 40942749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:54,8033437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942425, endtime: 40942749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:54,8033509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942425, endtime: 40942749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:54,8033573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942426, endtime: 40942749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:55,5750917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942637, endtime: 40942826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:55,5751133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942637, endtime: 40942826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:55,5751207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942638, endtime: 40942826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:55,5751282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942638, endtime: 40942826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:55,5751338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942639, endtime: 40942826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:55,5751401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942640, endtime: 40942826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:55,5751460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942640, endtime: 40942826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:55,5751670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942641, endtime: 40942826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:55,5751762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942642, endtime: 40942826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:55,5752227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942642, endtime: 40942826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:55,5752288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942643, endtime: 40942826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:55,5752357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942643, endtime: 40942826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:55,5752413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942644, endtime: 40942826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:56,1273433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942446, endtime: 40942881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:56,1273594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942446, endtime: 40942881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:56,1273666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942447, endtime: 40942881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:56,1273732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942448, endtime: 40942881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:56,1273788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942448, endtime: 40942881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:56,1273852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942449, endtime: 40942881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:56,1273901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942449, endtime: 40942881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:56,1273962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942450, endtime: 40942881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:56,1274015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942450, endtime: 40942881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:56,1274311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942451, endtime: 40942881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:56,1274367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942452, endtime: 40942881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:56,1274428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942452, endtime: 40942881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:56,1274480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942453, endtime: 40942881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,1571493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941990, endtime: 40942984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,1571690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941991, endtime: 40942984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,1571786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941991, endtime: 40942984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,1571861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941992, endtime: 40942984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,1571939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941992, endtime: 40942984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,1572003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941993, endtime: 40942984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,1572077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941994, endtime: 40942984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,1572141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941994, endtime: 40942984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,1572216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941995, endtime: 40942984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,1572512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941995, endtime: 40942984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,1572593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941996, endtime: 40942984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,1572654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941997, endtime: 40942984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,1572728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40941997, endtime: 40942984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,9332611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942749, endtime: 40943062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,9332805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942750, endtime: 40943062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,9332883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942750, endtime: 40943062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,9332960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942751, endtime: 40943062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,9333024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942752, endtime: 40943062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,9333099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942752, endtime: 40943062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,9333157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942753, endtime: 40943062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,9333229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942753, endtime: 40943062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,9333287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942754, endtime: 40943062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,9333573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942755, endtime: 40943062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,9333634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942755, endtime: 40943062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,9333700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942756, endtime: 40943062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:57,9333758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942756, endtime: 40943062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,0934693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,0939401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943078, endtime: 40943078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1001178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943079, endtime: 40943079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1056565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943079, endtime: 40943079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1116265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943080, endtime: 40943080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1172020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943080, endtime: 40943080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1230332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943081, endtime: 40943081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1291181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943081, endtime: 40943082, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1348859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943082, endtime: 40943082, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1406886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943083, endtime: 40943083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1465599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943083, endtime: 40943083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1523778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943084, endtime: 40943084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1581641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943084, endtime: 40943084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1640929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943085, endtime: 40943085, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1698914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943086, endtime: 40943086, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1764853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943086, endtime: 40943086, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1838483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943087, endtime: 40943087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1894064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943088, endtime: 40943088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,1952667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943088, endtime: 40943088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,2011948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943089, endtime: 40943089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,2066595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943089, endtime: 40943089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,2119086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943090, endtime: 40943090, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,2178029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943090, endtime: 40943090, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,2236125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943091, endtime: 40943091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,2295088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943092, endtime: 40943092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,2354777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943092, endtime: 40943092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,2413339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943093, endtime: 40943093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,2470700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943093, endtime: 40943093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,6752856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942826, endtime: 40943136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,6753028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942827, endtime: 40943136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,6753100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942827, endtime: 40943136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,6753170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942828, endtime: 40943136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,6753222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942828, endtime: 40943136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,6753286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942829, endtime: 40943136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,6753339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942830, endtime: 40943136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,6753402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942830, endtime: 40943136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,6753455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942831, endtime: 40943136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,6753751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942832, endtime: 40943136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,6753807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942832, endtime: 40943136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,6754799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942833, endtime: 40943136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:58,6754909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942833, endtime: 40943136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:59,2529874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943094, endtime: 40943194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:59,2530054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943094, endtime: 40943194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:59,2530129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943095, endtime: 40943194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:59,2530204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943096, endtime: 40943194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:59,2530259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943096, endtime: 40943194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:59,2530326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943097, endtime: 40943194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:59,2530381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943097, endtime: 40943194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:59,2530448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943098, endtime: 40943194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:59,2530500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943099, endtime: 40943194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:59,2530799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943099, endtime: 40943194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:52:59,2530855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943100, endtime: 40943194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,0984655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942881, endtime: 40943278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,0984829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942882, endtime: 40943278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,0984904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942883, endtime: 40943278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,0984976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942883, endtime: 40943278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,0985034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942884, endtime: 40943278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,0985206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942884, endtime: 40943278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,0985325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942885, endtime: 40943278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,0985397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942885, endtime: 40943278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,0985456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942886, endtime: 40943278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,0985774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942887, endtime: 40943278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,0985830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942887, endtime: 40943278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,0985893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942888, endtime: 40943278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,0985949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942888, endtime: 40943278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,4679341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942060, endtime: 40943315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,4679532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942061, endtime: 40943315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,4679629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942061, endtime: 40943315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,4679699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942062, endtime: 40943315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,4679774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942063, endtime: 40943315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,4679832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942063, endtime: 40943315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,4679904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942064, endtime: 40943315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,4679965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942064, endtime: 40943315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,4680034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942065, endtime: 40943315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,4680289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942066, endtime: 40943315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,4680366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942067, endtime: 40943315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,4680425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942067, endtime: 40943315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,4680497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942068, endtime: 40943315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,6897446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943100, endtime: 40943338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,6897588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943101, endtime: 40943338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,6897671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943194, endtime: 40943338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,6897732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943194, endtime: 40943338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,6897796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943195, endtime: 40943338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,6897848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943196, endtime: 40943338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,6897912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943196, endtime: 40943338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,6897962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943197, endtime: 40943338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,6898028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943197, endtime: 40943338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,6899303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943198, endtime: 40943338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,6899378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943199, endtime: 40943338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,6899430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943199, endtime: 40943338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,6899494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943200, endtime: 40943338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,8559725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942984, endtime: 40943354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,8559963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942985, endtime: 40943354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,8560088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942986, endtime: 40943354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,8560182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942986, endtime: 40943354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,8560245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942987, endtime: 40943354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,8560320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942988, endtime: 40943354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,8560381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942988, endtime: 40943354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,8560453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942989, endtime: 40943354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,8560511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942989, endtime: 40943354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,8560824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942990, endtime: 40943354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,8560883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942990, endtime: 40943354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,8560946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942991, endtime: 40943354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:00,8561002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942992, endtime: 40943354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,0464335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943062, endtime: 40943473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,0464499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943063, endtime: 40943473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,0464568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943063, endtime: 40943473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,0464637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943064, endtime: 40943473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,0464693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943064, endtime: 40943473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,0464759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943065, endtime: 40943473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,0464812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943066, endtime: 40943473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,0464876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943066, endtime: 40943473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,0464928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943067, endtime: 40943473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,0465225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943067, endtime: 40943473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,0465280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943068, endtime: 40943473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,0465344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943068, endtime: 40943473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,0465396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943069, endtime: 40943473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,5153681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943136, endtime: 40943520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,5153988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943137, endtime: 40943520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,5154132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943137, endtime: 40943520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,5154262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943138, endtime: 40943520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,5154354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943139, endtime: 40943520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,5154434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943139, endtime: 40943520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,5154495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943140, endtime: 40943520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,5154573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943140, endtime: 40943520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,5154634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943141, endtime: 40943520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,5154969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943141, endtime: 40943520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,5155035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943142, endtime: 40943520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,5155105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943143, endtime: 40943520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:02,5155163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943143, endtime: 40943520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:03,3827363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943278, endtime: 40943607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:03,3827533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943279, endtime: 40943607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:03,3827602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943280, endtime: 40943607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:03,3827671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943280, endtime: 40943607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:03,3827724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943281, endtime: 40943607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:03,3827787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943281, endtime: 40943607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:03,3827840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943282, endtime: 40943607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:03,3827901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943283, endtime: 40943607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:03,3827954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943283, endtime: 40943607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:03,3828355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943284, endtime: 40943607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:03,3828422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943284, endtime: 40943607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:03,3828491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943285, endtime: 40943607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:03,3829491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943285, endtime: 40943607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1512084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943473, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1512244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943474, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1512319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943474, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1512394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943475, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1512449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943475, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1512516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943476, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1512571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943477, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1512635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943477, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1512690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943478, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1513020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943478, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1513076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943479, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1513139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943479, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1513195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943480, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1513328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942438, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1513389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942439, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1513461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942440, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1513516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942440, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1513588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942441, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1514056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942442, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1514139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942442, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1514195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942443, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1514261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942443, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1514317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942444, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1514383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942444, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1514439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942445, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,1514505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40942446, endtime: 40943684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5904688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5904921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5905201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5905431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5905528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5905619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5905794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5905866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5905940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5906079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5906145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5906359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5906414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5906536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5906619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5906772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5906907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5906979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5907054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5907182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5907251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5907320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5907439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5907492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5907550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5907611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,5908971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54857 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,6759245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,6789206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943736, endtime: 40943737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,6836134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943737, endtime: 40943737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,6887414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943737, endtime: 40943737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,6945668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943738, endtime: 40943738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7004002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943739, endtime: 40943739, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7062012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943739, endtime: 40943739, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7120488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943740, endtime: 40943740, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7179927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943740, endtime: 40943740, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7238328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943741, endtime: 40943741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7305716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943742, endtime: 40943742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7366721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943742, endtime: 40943742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7429164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943743, endtime: 40943743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7483606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943743, endtime: 40943743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7540399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943744, endtime: 40943744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7599066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943745, endtime: 40943745, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7658824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943745, endtime: 40943745, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7716372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943746, endtime: 40943746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7760695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7807614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943747, endtime: 40943747, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7865248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943747, endtime: 40943747, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7923274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943748, endtime: 40943748, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,7981503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943748, endtime: 40943748, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,8037183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943749, endtime: 40943749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,8097651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943750, endtime: 40943750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,8156032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943750, endtime: 40943750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,8214360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943751, endtime: 40943751, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,8623855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,8626905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943755, endtime: 40943755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,8682732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943755, endtime: 40943755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,8741277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943756, endtime: 40943756, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,8800018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943757, endtime: 40943757, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,8858710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943757, endtime: 40943757, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,8917714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943758, endtime: 40943758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,8976464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943758, endtime: 40943758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9035050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943759, endtime: 40943759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9098200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943760, endtime: 40943760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9161097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943760, endtime: 40943760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9219209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943761, endtime: 40943761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9278355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943761, endtime: 40943761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9338244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943762, endtime: 40943762, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9392397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943763, endtime: 40943763, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9451787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943763, endtime: 40943763, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9509309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943764, endtime: 40943764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9568610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943764, endtime: 40943764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9627294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943765, endtime: 40943765, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9682167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943765, endtime: 40943765, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9736016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943766, endtime: 40943766, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9793691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943767, endtime: 40943767, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9852166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943767, endtime: 40943767, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9910567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943768, endtime: 40943768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:04,9968197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943768, endtime: 40943768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,0027484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943769, endtime: 40943769, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,1553141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943751, endtime: 40943784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,1553340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943752, endtime: 40943784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,1553445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943752, endtime: 40943784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,1553562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943753, endtime: 40943784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,1553653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943754, endtime: 40943784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,1553761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943754, endtime: 40943784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,1553853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943755, endtime: 40943784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,1553961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943755, endtime: 40943784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,1554052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943756, endtime: 40943784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,1554457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943757, endtime: 40943784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,1554548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943757, endtime: 40943784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,1554653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943758, endtime: 40943784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,1554742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943758, endtime: 40943784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,3354157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943769, endtime: 40943802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,3354357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943770, endtime: 40943802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,3354437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943771, endtime: 40943802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,3354515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943771, endtime: 40943802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,3354576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943772, endtime: 40943802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,3354645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943772, endtime: 40943802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,3354703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943773, endtime: 40943802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,3354770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943774, endtime: 40943802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,3354828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943774, endtime: 40943802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,3355141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943775, endtime: 40943802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,3355202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943775, endtime: 40943802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,3355271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943776, endtime: 40943802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,3355326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943777, endtime: 40943802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,4947141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943338, endtime: 40943818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,4947332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943338, endtime: 40943818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,4947410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943339, endtime: 40943818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,4947487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943339, endtime: 40943818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,4947548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943340, endtime: 40943818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,4947615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943340, endtime: 40943818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,4947673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943341, endtime: 40943818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,4947742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943342, endtime: 40943818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,4947798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943342, endtime: 40943818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,4948097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943343, endtime: 40943818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,4948158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943343, endtime: 40943818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,4948227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943344, endtime: 40943818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,4948285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943344, endtime: 40943818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,7581977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943354, endtime: 40943844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,7582307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943355, endtime: 40943844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,7582423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943355, endtime: 40943844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,7582504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943356, endtime: 40943844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,7582565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943357, endtime: 40943844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,7582631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943357, endtime: 40943844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,7582686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943358, endtime: 40943844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,7582756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943358, endtime: 40943844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,7582808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943359, endtime: 40943844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,7583102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943360, endtime: 40943844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,7584160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943360, endtime: 40943844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,7584291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943361, endtime: 40943844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:05,7584360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943361, endtime: 40943844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,2706813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943607, endtime: 40943896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,2707068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943608, endtime: 40943896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,2707184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943608, endtime: 40943896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,2707406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943609, endtime: 40943896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,2707536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943609, endtime: 40943896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,2707653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943610, endtime: 40943896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,2707752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943611, endtime: 40943896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,2707871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943611, endtime: 40943896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,2707968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943612, endtime: 40943896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,2708414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943612, endtime: 40943896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,2708511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943613, endtime: 40943896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,2708625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943614, endtime: 40943896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,2708719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943614, endtime: 40943896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,8883243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943684, endtime: 40943957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,8883409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943684, endtime: 40943957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,8883476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943685, endtime: 40943957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,8883548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943686, endtime: 40943957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,8883603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943686, endtime: 40943957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,8883667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943687, endtime: 40943957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,8883719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943687, endtime: 40943957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,8883783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943688, endtime: 40943957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,8883836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943689, endtime: 40943957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,8884135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943689, endtime: 40943957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,8885157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943690, endtime: 40943957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,8885246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943690, endtime: 40943957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:06,8885301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943691, endtime: 40943957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:08,1112646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943844, endtime: 40944080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:08,1112846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943845, endtime: 40944080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:08,1112926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943846, endtime: 40944080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:08,1113004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943846, endtime: 40944080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:08,1113068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943847, endtime: 40944080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:08,1113137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943847, endtime: 40944080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:08,1113195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943848, endtime: 40944080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:08,1113264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943849, endtime: 40944080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:08,1113320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943849, endtime: 40944080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:08,1113624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943850, endtime: 40944080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:08,1113688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943850, endtime: 40944080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:08,1113935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943851, endtime: 40944080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:08,1114040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943851, endtime: 40944080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:09,3012855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943818, endtime: 40944199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:09,3013024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943819, endtime: 40944199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:09,3013093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943819, endtime: 40944199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:09,3013162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943820, endtime: 40944199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:09,3013218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943820, endtime: 40944199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:09,3013281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943821, endtime: 40944199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:09,3013331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943822, endtime: 40944199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:09,3013398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943822, endtime: 40944199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:09,3013450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943823, endtime: 40944199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:09,3014567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943823, endtime: 40944199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:09,3014661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943824, endtime: 40944199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:09,3014730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943825, endtime: 40944199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:09,3014791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943825, endtime: 40944199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,1463690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943896, endtime: 40944283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,1463873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943896, endtime: 40944283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,1463945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943897, endtime: 40944283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,1464017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943898, endtime: 40944283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,1464073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943898, endtime: 40944283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,1464136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943899, endtime: 40944283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,1464192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943899, endtime: 40944283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,1464261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943900, endtime: 40944283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,1464316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943900, endtime: 40944283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,1464643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943901, endtime: 40944283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,1464699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943902, endtime: 40944283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,1464765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943902, endtime: 40944283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,1464818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943903, endtime: 40944283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:10,4758208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54854 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,6147118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944199, endtime: 40944430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,6147314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944199, endtime: 40944430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,6147514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944200, endtime: 40944430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,6147658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944201, endtime: 40944430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,6147758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944201, endtime: 40944430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,6147871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944202, endtime: 40944430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,6147968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944202, endtime: 40944430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,6148046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944203, endtime: 40944430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,6148107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944203, endtime: 40944430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,6148445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944204, endtime: 40944430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,6148503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944205, endtime: 40944430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,6148572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944205, endtime: 40944430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,6148630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944206, endtime: 40944430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8194069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944080, endtime: 40944451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8194271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944080, endtime: 40944451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8194374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944081, endtime: 40944451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8194482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944082, endtime: 40944451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8194567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944082, endtime: 40944451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8194670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944083, endtime: 40944451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8194753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944083, endtime: 40944451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8194853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944084, endtime: 40944451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8194936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944085, endtime: 40944451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8196801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944085, endtime: 40944451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8196903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944086, endtime: 40944451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8197006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944086, endtime: 40944451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8197089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944087, endtime: 40944451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8343034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943802, endtime: 40944452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8343239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943803, endtime: 40944452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8343366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943803, endtime: 40944452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8343460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943804, endtime: 40944452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8343568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943804, endtime: 40944452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8343657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943805, endtime: 40944452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8343762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943806, endtime: 40944452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8343848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943806, endtime: 40944452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8343956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943807, endtime: 40944452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8344322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943807, endtime: 40944452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8344430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943808, endtime: 40944452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8344521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943809, endtime: 40944452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:11,8346239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943809, endtime: 40944452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,1357378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54852 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,4371770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943957, endtime: 40944512, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,4396193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943958, endtime: 40944513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,4396295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943959, endtime: 40944513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,4398761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943959, endtime: 40944513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,4399479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943960, endtime: 40944513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,4399545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943960, endtime: 40944513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,4399609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943961, endtime: 40944513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,4399659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943962, endtime: 40944513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,4399723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943962, endtime: 40944513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,4401141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943963, endtime: 40944513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,4401221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943963, endtime: 40944513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,4401274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943964, endtime: 40944513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,4401335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943965, endtime: 40944513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,6623352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943784, endtime: 40944535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,6623502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943785, endtime: 40944535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,6623582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943785, endtime: 40944535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,6623640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943786, endtime: 40944535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,6623707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943787, endtime: 40944535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,6623759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943787, endtime: 40944535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,6623820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943788, endtime: 40944535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,6623873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943788, endtime: 40944535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,6623937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943789, endtime: 40944535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,6624200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943790, endtime: 40944535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,6624266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943790, endtime: 40944535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,6625364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943791, endtime: 40944535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:12,6625497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40943791, endtime: 40944535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,0950463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944283, endtime: 40944578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,0950627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944284, endtime: 40944578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,0950696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944284, endtime: 40944578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,0950765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944285, endtime: 40944578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,0950821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944286, endtime: 40944578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,0950885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944286, endtime: 40944578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,0950934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944287, endtime: 40944578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,0950998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944288, endtime: 40944578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,0951051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944288, endtime: 40944578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,0951350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944289, endtime: 40944578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,0951405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944289, endtime: 40944578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,0951466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944290, endtime: 40944578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,0952544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944291, endtime: 40944578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,7251372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944512, endtime: 40944641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,7251538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944513, endtime: 40944641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,7251604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944514, endtime: 40944641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,7251676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944514, endtime: 40944641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,7251729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944515, endtime: 40944641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,7251793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944515, endtime: 40944641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,7251845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944516, endtime: 40944641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,7251909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944516, endtime: 40944641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,7251962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944517, endtime: 40944641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,7252513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944518, endtime: 40944641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,7252577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944518, endtime: 40944641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,7253818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944519, endtime: 40944641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,8210221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944451, endtime: 40944651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,8210471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944451, endtime: 40944651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,8210592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944452, endtime: 40944651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,8210714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944452, endtime: 40944651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,8210817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944453, endtime: 40944651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,8210933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944453, endtime: 40944651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,8211030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944454, endtime: 40944651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,8211147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944455, endtime: 40944651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,8211243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944455, endtime: 40944651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,8211665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944456, endtime: 40944651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,8211764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944456, endtime: 40944651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,8211875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944457, endtime: 40944651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,8211953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944457, endtime: 40944651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,9028420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944430, endtime: 40944659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,9028581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944431, endtime: 40944659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,9028653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944431, endtime: 40944659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,9028725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944432, endtime: 40944659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,9028780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944432, endtime: 40944659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,9028841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944433, endtime: 40944659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,9028894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944434, endtime: 40944659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,9028958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944434, endtime: 40944659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,9029010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944435, endtime: 40944659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,9029456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944435, endtime: 40944659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,9029520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944436, endtime: 40944659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,9029584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944437, endtime: 40944659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:13,9029637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944437, endtime: 40944659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,5455508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944578, endtime: 40944823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,5455666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944579, endtime: 40944823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,5455735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944579, endtime: 40944823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,5455805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944580, endtime: 40944823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,5455857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944580, endtime: 40944823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,5455921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944581, endtime: 40944823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,5455977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944582, endtime: 40944823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,5456040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944582, endtime: 40944823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,5456093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944583, endtime: 40944823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,5456381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944583, endtime: 40944823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,5456436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944584, endtime: 40944823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,5457320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944585, endtime: 40944823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,5457439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944585, endtime: 40944823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,6188945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944535, endtime: 40944830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,6189158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944535, endtime: 40944830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,6189241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944536, endtime: 40944830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,6189322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944537, endtime: 40944830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,6189383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944537, endtime: 40944830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,6189452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944538, endtime: 40944830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,6189510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944538, endtime: 40944830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,6189582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944539, endtime: 40944830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,6189640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944540, endtime: 40944830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,6190073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944540, endtime: 40944831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,6190150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944541, endtime: 40944831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,6190219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944541, endtime: 40944831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:15,6190278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944542, endtime: 40944831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,4078947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944651, endtime: 40944909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,4079105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944651, endtime: 40944909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,4079174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944652, endtime: 40944909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,4079246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944652, endtime: 40944909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,4079302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944653, endtime: 40944909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,4079365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944654, endtime: 40944909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,4079415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944654, endtime: 40944909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,4079479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944655, endtime: 40944909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,4079532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944655, endtime: 40944909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,4079828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944656, endtime: 40944909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,4079881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944656, endtime: 40944909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,4079944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944657, endtime: 40944909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,4079997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944658, endtime: 40944909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,6373301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944659, endtime: 40944932, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,6373461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944659, endtime: 40944932, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,6373534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944660, endtime: 40944932, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,6373606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944661, endtime: 40944932, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,6373661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944661, endtime: 40944932, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,6373725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944662, endtime: 40944932, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,6373777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944663, endtime: 40944932, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,6373841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944663, endtime: 40944932, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,6373894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944664, endtime: 40944932, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,6374567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944664, endtime: 40944932, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,6375611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944665, endtime: 40944932, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,6375706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944665, endtime: 40944932, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,6376307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944666, endtime: 40944932, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,7758620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944452, endtime: 40944946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,7758772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944453, endtime: 40944946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,7758841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944453, endtime: 40944946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,7758913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944454, endtime: 40944946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,7758969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944454, endtime: 40944946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,7759035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944455, endtime: 40944946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,7759088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944455, endtime: 40944946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,7759152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944456, endtime: 40944946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,7759204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944457, endtime: 40944946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,7759484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944457, endtime: 40944946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,7759540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944458, endtime: 40944946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,7759603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944458, endtime: 40944946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:16,7759656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944459, endtime: 40944946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:18,0632284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944831, endtime: 40945075, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:18,0632447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944831, endtime: 40945075, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:18,0632514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944832, endtime: 40945075, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:18,0632580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944832, endtime: 40945075, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:18,0632636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944833, endtime: 40945075, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:18,0632699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944833, endtime: 40945075, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:18,0632752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944834, endtime: 40945075, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:18,0632813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944835, endtime: 40945075, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:18,0632863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944835, endtime: 40945075, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:18,0633170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944836, endtime: 40945075, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:18,0633226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944836, endtime: 40945075, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:18,0634340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944837, endtime: 40945075, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:18,0634462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944838, endtime: 40945075, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,4347096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944823, endtime: 40945212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,4347270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944824, endtime: 40945212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,4347345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944824, endtime: 40945212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,4347420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944825, endtime: 40945212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,4347475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944825, endtime: 40945212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,4347542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944826, endtime: 40945212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,4347597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944827, endtime: 40945212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,4347661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944827, endtime: 40945212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,4347716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944828, endtime: 40945212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,4347993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944828, endtime: 40945212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,4348049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944829, endtime: 40945212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,4348113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944829, endtime: 40945212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,4348168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944830, endtime: 40945212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,6838090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944519, endtime: 40945237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,6838281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944641, endtime: 40945237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,6838359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944642, endtime: 40945237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,6838431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944642, endtime: 40945237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,6838486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944643, endtime: 40945237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,6838553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944643, endtime: 40945237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,6838608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944644, endtime: 40945237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,6838672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944645, endtime: 40945237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,6838724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944645, endtime: 40945237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,6839004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944646, endtime: 40945237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,6839062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944646, endtime: 40945237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,6839126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944647, endtime: 40945237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,6839182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944647, endtime: 40945237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,7257971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944932, endtime: 40945241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,7258137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944933, endtime: 40945241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,7258204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944934, endtime: 40945241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,7258279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944934, endtime: 40945241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,7258331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944935, endtime: 40945241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,7258398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944935, endtime: 40945241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,7258453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944936, endtime: 40945241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,7258517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944936, endtime: 40945241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,7258567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944937, endtime: 40945241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,7259212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944938, endtime: 40945241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,7259279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944938, endtime: 40945241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,7259473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944939, endtime: 40945241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:19,7260204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944939, endtime: 40945241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,1415643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944909, endtime: 40945283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,1415857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944910, endtime: 40945283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,1415937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944911, endtime: 40945283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,1416020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944911, endtime: 40945283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,1416081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944912, endtime: 40945283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,1416150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944912, endtime: 40945283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,1416208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944913, endtime: 40945283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,1416280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944914, endtime: 40945283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,1416339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944914, endtime: 40945283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,1417004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944915, endtime: 40945283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,1417081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944915, endtime: 40945283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,1417150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944916, endtime: 40945283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,1417646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944917, endtime: 40945283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,5026980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944946, endtime: 40945319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,5027160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944947, endtime: 40945319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,5027227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944947, endtime: 40945319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,5027299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944948, endtime: 40945319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,5027354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944949, endtime: 40945319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,5027418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944949, endtime: 40945319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,5027471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944950, endtime: 40945319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,5027537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944950, endtime: 40945319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,5027590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944951, endtime: 40945319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,5027894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944952, endtime: 40945319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,5027950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944952, endtime: 40945319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,5028016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944953, endtime: 40945319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:20,5028069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40944953, endtime: 40945319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4707482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54883 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4741158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945075, endtime: 40945516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4741310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945076, endtime: 40945516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4741380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945076, endtime: 40945516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4741449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945077, endtime: 40945516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4741502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945077, endtime: 40945516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4741565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945078, endtime: 40945516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4741615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945078, endtime: 40945516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4741679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945079, endtime: 40945516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4741732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945080, endtime: 40945516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4742011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945080, endtime: 40945516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4742064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945081, endtime: 40945516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4742128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945081, endtime: 40945516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,4743197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945082, endtime: 40945516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,5756751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54873 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,7410784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54883 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,7410926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54883 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,7416525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54883 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40945543, endtime: 40945543, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:22,7417600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54883 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40945543, endtime: 40945543, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,0861897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945241, endtime: 40945577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,0862066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945242, endtime: 40945577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,0862135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945242, endtime: 40945577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,0862204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945243, endtime: 40945577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,0862260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945244, endtime: 40945577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,0862324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945244, endtime: 40945577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,0862376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945245, endtime: 40945577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,0862440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945246, endtime: 40945577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,0862493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945246, endtime: 40945577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,0862797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945247, endtime: 40945577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,0864019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945247, endtime: 40945577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,0864099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945248, endtime: 40945577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,0864149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945248, endtime: 40945577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,4965260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945237, endtime: 40945618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,4965468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945238, endtime: 40945618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,4965543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945238, endtime: 40945618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,4965618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945239, endtime: 40945618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,4965679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945239, endtime: 40945618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,4965748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945240, endtime: 40945618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,4965803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945241, endtime: 40945618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,4965870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945241, endtime: 40945618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,4965925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945242, endtime: 40945618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,4966881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945242, endtime: 40945618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,4966970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945243, endtime: 40945618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,4967039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945243, endtime: 40945618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:23,4967097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945244, endtime: 40945618, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:24,2427995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945212, endtime: 40945693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:24,2428197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945213, endtime: 40945693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:24,2428278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945213, endtime: 40945693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:24,2428355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945214, endtime: 40945693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:24,2428416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945215, endtime: 40945693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:24,2428488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945215, endtime: 40945693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:24,2428546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945216, endtime: 40945693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:24,2428613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945217, endtime: 40945693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:24,2428668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945217, endtime: 40945693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:24,2428970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945218, endtime: 40945693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:24,2429028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945218, endtime: 40945693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:24,2429098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945219, endtime: 40945693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:24,2429153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945220, endtime: 40945693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,3748109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945319, endtime: 40945806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,3748308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945319, endtime: 40945806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,3748389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945320, endtime: 40945806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,3748469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945321, endtime: 40945806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,3748533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945321, endtime: 40945806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,3748605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945322, endtime: 40945806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,3748666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945322, endtime: 40945806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,3748741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945323, endtime: 40945806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,3748799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945323, endtime: 40945806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,3749109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945324, endtime: 40945806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,3749170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945325, endtime: 40945806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,3749239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945325, endtime: 40945806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,3749297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945326, endtime: 40945806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,6540720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945577, endtime: 40945834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,6540886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945578, endtime: 40945834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,6540956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945578, endtime: 40945834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,6541028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945579, endtime: 40945834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,6541083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945579, endtime: 40945834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,6541150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945580, endtime: 40945834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,6541200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945581, endtime: 40945834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,6541263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945581, endtime: 40945834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,6541316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945582, endtime: 40945834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,6541604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945582, endtime: 40945834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,6541659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945583, endtime: 40945834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,6542504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945583, endtime: 40945834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:25,6542621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945584, endtime: 40945834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,1772644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945283, endtime: 40945886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,1772796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945283, endtime: 40945886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,1772877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945284, endtime: 40945886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,1772935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945285, endtime: 40945886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,1773001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945285, endtime: 40945886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,1773054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945286, endtime: 40945886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,1773115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945286, endtime: 40945886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,1773167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945287, endtime: 40945886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,1773231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945288, endtime: 40945886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,1774007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945288, endtime: 40945886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,1774129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945289, endtime: 40945886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,1774206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945289, endtime: 40945886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,3284206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945516, endtime: 40945901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,3284378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945517, endtime: 40945901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,3284447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945517, endtime: 40945901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,3284517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945518, endtime: 40945901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,3284572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945518, endtime: 40945901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,3284638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945519, endtime: 40945901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,3284691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945520, endtime: 40945901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,3284755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945520, endtime: 40945901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,3284807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945521, endtime: 40945901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,3285093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945521, endtime: 40945901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,3285145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945522, endtime: 40945901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,3285209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945522, endtime: 40945901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,3286193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945523, endtime: 40945901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,4272019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945618, endtime: 40945911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,4272224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945619, endtime: 40945911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,4272446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945619, endtime: 40945911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,4272568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945620, endtime: 40945911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,4272656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945621, endtime: 40945911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,4272767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945621, endtime: 40945911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,4272856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945622, endtime: 40945911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,4272967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945622, endtime: 40945911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,4273025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945623, endtime: 40945911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,4273346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945623, endtime: 40945911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,4273402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945624, endtime: 40945911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,4273465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945625, endtime: 40945911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:26,4273518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945625, endtime: 40945911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:28,5273178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945901, endtime: 40946121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:28,5273355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945902, endtime: 40946121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:28,5273427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945903, endtime: 40946121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:28,5273502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945903, endtime: 40946121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:28,5273557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945904, endtime: 40946121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:28,5273621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945904, endtime: 40946121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:28,5273676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945905, endtime: 40946121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:28,5273740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945906, endtime: 40946121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:28,5273793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945907, endtime: 40946121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:28,5274092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945907, endtime: 40946121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:28,5274147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945908, endtime: 40946121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:28,5274211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945908, endtime: 40946121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:28,5274264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945909, endtime: 40946121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3227382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945834, endtime: 40946301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3227551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945835, endtime: 40946301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3227626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945835, endtime: 40946301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3227698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945836, endtime: 40946301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3227753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945836, endtime: 40946301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3227820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945837, endtime: 40946301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3227872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945838, endtime: 40946301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3227939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945838, endtime: 40946301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3227992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945839, endtime: 40946301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3228687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945839, endtime: 40946301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3228759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945840, endtime: 40946301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3228825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945841, endtime: 40946301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3229878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945841, endtime: 40946301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3686273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945693, endtime: 40946305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3686442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945694, endtime: 40946305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3686528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945694, endtime: 40946305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3686586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945695, endtime: 40946305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3686652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945695, endtime: 40946305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3686705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945696, endtime: 40946305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3686771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945696, endtime: 40946305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3686824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945697, endtime: 40946305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3686888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945698, endtime: 40946305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3687157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945698, endtime: 40946305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3687226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945699, endtime: 40946305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3687278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945699, endtime: 40946305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,3687486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945700, endtime: 40946305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9000194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946121, endtime: 40946359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9000399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946122, endtime: 40946359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9000479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946123, endtime: 40946359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9000560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946123, endtime: 40946359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9000618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946124, endtime: 40946359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9000687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946124, endtime: 40946359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9000742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946125, endtime: 40946359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9000812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946126, endtime: 40946359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9000867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946126, endtime: 40946359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9001169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946127, endtime: 40946359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9001230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946127, endtime: 40946359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9001297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946128, endtime: 40946359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9001355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946129, endtime: 40946359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9843417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945806, endtime: 40946367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9843572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945807, endtime: 40946367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9843655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945807, endtime: 40946367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9843713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945808, endtime: 40946367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9843780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945808, endtime: 40946367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9843835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945809, endtime: 40946367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9843899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945809, endtime: 40946367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9843954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945810, endtime: 40946367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9844018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945811, endtime: 40946367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9844317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945811, endtime: 40946367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9844386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945812, endtime: 40946367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9844439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945813, endtime: 40946367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:30,9844503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945813, endtime: 40946367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:31,5685714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54868 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6045374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946359, endtime: 40946529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6045546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946359, endtime: 40946529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6045618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946360, endtime: 40946529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6045693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946360, endtime: 40946529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6045748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946361, endtime: 40946529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6045821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946362, endtime: 40946529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6045873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946362, endtime: 40946529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6045940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946363, endtime: 40946529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6045992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946363, endtime: 40946529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6046303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946364, endtime: 40946529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6046361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946364, endtime: 40946529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6046425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946365, endtime: 40946529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6046480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946366, endtime: 40946529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6758749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945290, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6758927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945886, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6759013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945887, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6759074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945887, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6759143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945888, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6759198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945889, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6759265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945889, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6759320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945890, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6759384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945890, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6759437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945891, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6759844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945892, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6759910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945892, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6759977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40945893, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:32,6763570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946536, endtime: 40946536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,0833036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946529, endtime: 40946677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,0833208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946530, endtime: 40946677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,0833283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946530, endtime: 40946677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,0833355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946531, endtime: 40946677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,0833410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946531, endtime: 40946677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,0833476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946532, endtime: 40946677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,0833529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946533, endtime: 40946677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,0833596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946533, endtime: 40946677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,0833648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946534, endtime: 40946677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,0834075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946534, endtime: 40946677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,0834141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946535, endtime: 40946677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,0834211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946535, endtime: 40946677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,0834266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946536, endtime: 40946677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,5693067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,6492111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946367, endtime: 40946734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,6492277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946368, endtime: 40946734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,6492349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946368, endtime: 40946734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,6492421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946369, endtime: 40946734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,6492474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946369, endtime: 40946734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,6492537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946370, endtime: 40946734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,6492590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946371, endtime: 40946734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,6492654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946371, endtime: 40946734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,6492706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946372, endtime: 40946734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,6493144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946372, endtime: 40946734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,6493208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946373, endtime: 40946734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,6494194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946373, endtime: 40946734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:34,6494313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946374, endtime: 40946734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:35,4474655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946537, endtime: 40946813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:35,4474838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946537, endtime: 40946813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:35,4474918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946538, endtime: 40946813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:35,4475392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946539, endtime: 40946813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:35,4476268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946539, endtime: 40946813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:35,4476353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946540, endtime: 40946813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:35,4476423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946540, endtime: 40946813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:35,4476506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946541, endtime: 40946813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:35,4476575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946541, endtime: 40946813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:35,4477320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946542, endtime: 40946813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:35,4477395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946543, endtime: 40946813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:35,4477464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946543, endtime: 40946813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,4327549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946306, endtime: 40946912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,4327752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946307, endtime: 40946912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,4327843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946307, endtime: 40946912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,4327910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946308, endtime: 40946912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,4327982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946308, endtime: 40946912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,4328040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946309, endtime: 40946912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,4328109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946310, endtime: 40946912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,4328164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946310, endtime: 40946912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,4328234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946311, endtime: 40946912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,4328516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946311, endtime: 40946912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,4328691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946312, endtime: 40946912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,4328766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946312, endtime: 40946912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,4328838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946313, endtime: 40946912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,6474775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946301, endtime: 40946933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,6474978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946302, endtime: 40946933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,6475072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946302, endtime: 40946933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,6475141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946303, endtime: 40946933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,6475219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946303, endtime: 40946933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,6475280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946304, endtime: 40946933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,6475670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946305, endtime: 40946933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,6476335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946306, endtime: 40946933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,6476421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946307, endtime: 40946933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,6477402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946307, endtime: 40946933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,6477493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946308, endtime: 40946933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:36,6477554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946308, endtime: 40946933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:37,8040627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946677, endtime: 40947049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:37,8040790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946678, endtime: 40947049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:37,8040862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946678, endtime: 40947049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:37,8040932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946679, endtime: 40947049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:37,8040984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946679, endtime: 40947049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:37,8041051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946680, endtime: 40947049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:37,8041103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946681, endtime: 40947049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:37,8041170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946681, endtime: 40947049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:37,8041223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946682, endtime: 40947049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:37,8041538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946682, endtime: 40947049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:37,8041594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946683, endtime: 40947049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:37,8041655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946684, endtime: 40947049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:37,8042901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946684, endtime: 40947049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,1209062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947049, endtime: 40947281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,1209259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947050, endtime: 40947281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,1209367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947050, endtime: 40947281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,1209475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947051, endtime: 40947281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,1209563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947051, endtime: 40947281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,1209669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947052, endtime: 40947281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,1209757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947053, endtime: 40947281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,1209857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947053, endtime: 40947281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,1209943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947054, endtime: 40947281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,1210320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947054, endtime: 40947281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,1210375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947055, endtime: 40947281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,1210439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947056, endtime: 40947281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,1210492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947056, endtime: 40947281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4319764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946309, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4319947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946933, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4320038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946934, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4320108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946935, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4320180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946935, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4320238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946936, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4320310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946936, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4320365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946937, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4320435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946938, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4320493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946938, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4320784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946939, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4320845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946939, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4320914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946940, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,4332287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947312, endtime: 40947312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,5700121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,6583595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,6591671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947334, endtime: 40947335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,6649138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947335, endtime: 40947335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,6706846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947336, endtime: 40947336, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,6766729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947336, endtime: 40947336, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,6832604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947337, endtime: 40947337, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,6892501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947338, endtime: 40947338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,6951996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947338, endtime: 40947338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7006562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947339, endtime: 40947339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7059763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947339, endtime: 40947339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7116878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947340, endtime: 40947340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7176090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947340, endtime: 40947340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7233937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947341, endtime: 40947341, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7292476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947342, endtime: 40947342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7352741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947342, endtime: 40947342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7410718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947343, endtime: 40947343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7471196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947343, endtime: 40947343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7527480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947344, endtime: 40947344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7585781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947344, endtime: 40947344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7648279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947345, endtime: 40947345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7703455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947346, endtime: 40947346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7894289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947348, endtime: 40947348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,7971972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947348, endtime: 40947348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,8097246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947350, endtime: 40947350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,8172115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947350, endtime: 40947350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:40,8230219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947351, endtime: 40947351, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:41,3803675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946734, endtime: 40947407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:41,3803844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946734, endtime: 40947407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:41,3803927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946735, endtime: 40947407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:41,3803988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946736, endtime: 40947407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:41,3804060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946736, endtime: 40947407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:41,3804118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946737, endtime: 40947407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:41,3804185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946737, endtime: 40947407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:41,3804240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946738, endtime: 40947407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:41,3804307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946739, endtime: 40947407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:41,3804601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946739, endtime: 40947407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:41,3804673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946740, endtime: 40947407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:41,3804725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946740, endtime: 40947407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:41,3804922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946741, endtime: 40947407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,0110050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946544, endtime: 40947470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,0110260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946814, endtime: 40947470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,0110341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946814, endtime: 40947470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,0110421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946815, endtime: 40947470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,0110482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946815, endtime: 40947470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,0110549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946816, endtime: 40947470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,0110607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946816, endtime: 40947470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,0110676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946817, endtime: 40947470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,0110731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946818, endtime: 40947470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,0111020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946818, endtime: 40947470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,0111081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946819, endtime: 40947470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,0111147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946819, endtime: 40947470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,0111205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946820, endtime: 40947470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1468655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946912, endtime: 40947483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1468838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946913, endtime: 40947483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1468913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946913, endtime: 40947483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1468985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946914, endtime: 40947483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1469043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946914, endtime: 40947483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1469110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946915, endtime: 40947483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1469165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946916, endtime: 40947483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1469231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946916, endtime: 40947483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1469287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946917, endtime: 40947483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1469583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946917, endtime: 40947483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1469644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946918, endtime: 40947483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1469711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946918, endtime: 40947483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1469763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40946919, endtime: 40947483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1760683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947281, endtime: 40947486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1760850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947281, endtime: 40947486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1760922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947282, endtime: 40947486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1760994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947282, endtime: 40947486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1761046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947283, endtime: 40947486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1761110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947284, endtime: 40947486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1761163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947284, endtime: 40947486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1761224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947285, endtime: 40947486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1761276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947285, endtime: 40947486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1761562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947286, endtime: 40947486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1761617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947287, endtime: 40947486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1761681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947287, endtime: 40947486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,1761733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947288, endtime: 40947486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,5523506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947313, endtime: 40947524, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,5523659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947313, endtime: 40947524, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,5523731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947314, endtime: 40947524, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,5523803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947314, endtime: 40947524, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,5523861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947315, endtime: 40947524, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,5523927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947316, endtime: 40947524, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,5523983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947316, endtime: 40947524, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,5524046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947317, endtime: 40947524, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,5545213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947317, endtime: 40947524, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,5545413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947318, endtime: 40947524, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,5545521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947318, endtime: 40947524, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:42,5545626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947319, endtime: 40947524, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:43,8448492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947407, endtime: 40947653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:43,8448647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947407, endtime: 40947653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:43,8448717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947408, endtime: 40947653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:43,8448789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947408, endtime: 40947653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:43,8448844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947409, endtime: 40947653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:43,8448908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947410, endtime: 40947653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:43,8448960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947410, endtime: 40947653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:43,8449024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947411, endtime: 40947653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:43,8449074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947412, endtime: 40947653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:43,8449370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947412, endtime: 40947653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:43,8449426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947413, endtime: 40947653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:43,8449490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947413, endtime: 40947653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:43,8450659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947414, endtime: 40947653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2133939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947486, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2134155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947487, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2134238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947488, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2134318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947488, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2134385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947489, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2134457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947489, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2134521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947490, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2134595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947490, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2134656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947491, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2135011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947492, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2135075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947492, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2135147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947493, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2135208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947493, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2135310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947470, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2135385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947470, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2135449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947471, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2135521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947472, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2135582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947472, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2135657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947473, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2136191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947473, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2136283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947474, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2136341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947474, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2136410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947475, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2136466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947476, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2136535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947476, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2136593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947477, endtime: 40947690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:44,2992635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947690, endtime: 40947699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:45,6168263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947483, endtime: 40947830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:45,6168434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947484, endtime: 40947830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:45,6168506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947484, endtime: 40947830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:45,6168581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947485, endtime: 40947830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:45,6168637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947486, endtime: 40947830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:45,6168700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947486, endtime: 40947830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:45,6168753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947487, endtime: 40947830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:45,6168820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947488, endtime: 40947830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:45,6168872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947488, endtime: 40947830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:45,6169146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947489, endtime: 40947830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:45,6169207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947489, endtime: 40947830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:45,6169271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947490, endtime: 40947830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:45,6169327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947490, endtime: 40947830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,1710991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947690, endtime: 40947886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,1711157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947691, endtime: 40947886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,1711232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947691, endtime: 40947886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,1711312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947692, endtime: 40947886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,1711370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947692, endtime: 40947886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,1711434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947693, endtime: 40947886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,1711486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947694, endtime: 40947886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,1711553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947694, endtime: 40947886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,1711606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947695, endtime: 40947886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,1711910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947695, endtime: 40947886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,1711969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947696, endtime: 40947886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,1712032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947696, endtime: 40947886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,1712088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947697, endtime: 40947886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,2433151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947886, endtime: 40947893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4339554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947653, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4339748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947654, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4339831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947654, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4339912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947655, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4339973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947656, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4340047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947656, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4340108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947658, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4340180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947658, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4340239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947659, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4340759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947659, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4340837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947660, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4340909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947661, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4340970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947663, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4341114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947691, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4341178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947691, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4341250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947692, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4341311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947692, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4341386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947693, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4342181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947694, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4342269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947694, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4342328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947695, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4342400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947695, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4362295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947696, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4362422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947696, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:46,4362497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947697, endtime: 40947912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:47,4592797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947831, endtime: 40948015, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:47,4592975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947831, endtime: 40948015, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:47,4593049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947832, endtime: 40948015, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:47,4593121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947833, endtime: 40948015, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:47,4593180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947833, endtime: 40948015, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:47,4593249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947835, endtime: 40948015, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:47,4593304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947836, endtime: 40948015, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:47,4593374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947836, endtime: 40948015, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:47,4593429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947837, endtime: 40948015, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:47,4593723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947838, endtime: 40948015, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:47,4593894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947838, endtime: 40948015, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:47,4594030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947839, endtime: 40948015, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:47,4594099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947839, endtime: 40948015, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,0754709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947320, endtime: 40948176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,0754962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947524, endtime: 40948176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,0755083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947524, endtime: 40948176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,0755203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947525, endtime: 40948176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,0755300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947526, endtime: 40948176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,0755416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947526, endtime: 40948176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,0755510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947527, endtime: 40948176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,0755624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947527, endtime: 40948176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,0755721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947528, endtime: 40948176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,0756194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947529, endtime: 40948176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,0756269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947529, endtime: 40948176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,0756333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947530, endtime: 40948176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,0756394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947530, endtime: 40948176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5800498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5800748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5801050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5801288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5801382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5801474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5801643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5801718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5801792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5801931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5802000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5802244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5802299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5802424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5802502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5802662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5802801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5802873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5803214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5803369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5803457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5803529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5803657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5803715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5803784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5803854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,5804868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54851 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,6545017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,6548134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948234, endtime: 40948234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,6607014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948235, endtime: 40948235, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,6665587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948235, endtime: 40948235, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,6723771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948236, endtime: 40948236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,6782410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948236, endtime: 40948236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,6842019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948237, endtime: 40948237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,6899228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948238, endtime: 40948238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,6958543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948238, endtime: 40948238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7016561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948239, endtime: 40948239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7076455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948239, endtime: 40948239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7133775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948240, endtime: 40948240, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7185169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948240, endtime: 40948240, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7239428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948241, endtime: 40948241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7299410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948242, endtime: 40948242, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7359496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948242, endtime: 40948242, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7416586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948243, endtime: 40948243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7474219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948243, endtime: 40948243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7533983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948244, endtime: 40948244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7596980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948245, endtime: 40948245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7805650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948247, endtime: 40948247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7866896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948247, endtime: 40948247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7925579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948248, endtime: 40948248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,7984642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948248, endtime: 40948248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,8042832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948249, endtime: 40948249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,8107178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948250, endtime: 40948250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,8168081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948250, endtime: 40948250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,8227933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948251, endtime: 40948251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:49,8285555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948251, endtime: 40948251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,3614069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54879 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,4363259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,4366686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948312, endtime: 40948312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,4423286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948313, endtime: 40948313, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,4482972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948313, endtime: 40948313, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,4540730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948314, endtime: 40948314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,4610036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948315, endtime: 40948315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,4693585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948316, endtime: 40948316, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,4772355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948316, endtime: 40948316, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,4828514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948317, endtime: 40948317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,4887042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948317, endtime: 40948317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,4946673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948318, endtime: 40948318, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5001062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948319, endtime: 40948319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5077886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948319, endtime: 40948319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5130358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948320, endtime: 40948320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5189825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948320, endtime: 40948321, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5350188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948322, endtime: 40948322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5437006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948323, endtime: 40948323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5495244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948323, endtime: 40948324, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5553306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948324, endtime: 40948324, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5605695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948325, endtime: 40948325, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5667980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948325, endtime: 40948325, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5733470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948326, endtime: 40948326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5789871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948326, endtime: 40948327, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5850299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948327, endtime: 40948327, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5906442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948328, endtime: 40948328, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,5966555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948328, endtime: 40948328, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,6899721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54870 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,7756511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,7760368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948346, endtime: 40948346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,7822448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948347, endtime: 40948347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,7880405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948347, endtime: 40948347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,7937839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948348, endtime: 40948348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,7995724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948349, endtime: 40948349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8054743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948349, endtime: 40948349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8112440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948350, endtime: 40948350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8171688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948350, endtime: 40948350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8225080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948351, endtime: 40948351, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8372152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948352, endtime: 40948352, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8429663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948353, endtime: 40948353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8488491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948353, endtime: 40948353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8527007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947913, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8527143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947913, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8527220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947915, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8527295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947917, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8527353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947918, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8527423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947919, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8527481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947919, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8527553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947920, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8527608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947922, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8527888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947922, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8527946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947923, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8528013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947923, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8528071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947924, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8543464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948354, endtime: 40948354, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8596069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948355, endtime: 40948355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8654680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948355, endtime: 40948355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8712213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948356, endtime: 40948356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8771168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948356, endtime: 40948356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,8980008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948358, endtime: 40948358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9040819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948359, endtime: 40948359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9115546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948360, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9115726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948329, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9115812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948330, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9115873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948330, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9115942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948331, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9115998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948331, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9116061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948332, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9116114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948333, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9116181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948333, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9116413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948334, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9116483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948334, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9116535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948335, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9116599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948335, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9116654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948336, endtime: 40948360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9385437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948362, endtime: 40948362, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9446708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948363, endtime: 40948363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9501690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948364, endtime: 40948364, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9563418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948364, endtime: 40948364, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9626861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948365, endtime: 40948365, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9944550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:50,9948100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948368, endtime: 40948368, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,0000904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948369, endtime: 40948369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,0094036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948370, endtime: 40948370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,0203371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948371, endtime: 40948371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,0270235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948371, endtime: 40948371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,0370665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948372, endtime: 40948372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,0500206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948374, endtime: 40948374, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,0557969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948374, endtime: 40948374, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,0623180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948375, endtime: 40948375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,0674862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948375, endtime: 40948375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,0732866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948376, endtime: 40948376, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,0791320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948377, endtime: 40948377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,0850806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948377, endtime: 40948377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,0915094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948378, endtime: 40948378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1001860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948379, endtime: 40948379, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1054700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948379, endtime: 40948379, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1157250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948380, endtime: 40948380, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1211331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948381, endtime: 40948381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1274697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948381, endtime: 40948381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1328997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948382, endtime: 40948382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1434550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948383, endtime: 40948383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1494665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948384, endtime: 40948384, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1595580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948385, endtime: 40948385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1659345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948385, endtime: 40948385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1718768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948386, endtime: 40948386, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1776101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948386, endtime: 40948386, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1885796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948387, endtime: 40948387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,1981854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948388, endtime: 40948388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,3142877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948252, endtime: 40948400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,3143057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948253, endtime: 40948400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,3143126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948253, endtime: 40948400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,3143196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948254, endtime: 40948400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,3143251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948254, endtime: 40948400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,3143315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948255, endtime: 40948400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,3143368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948256, endtime: 40948400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,3143431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948256, endtime: 40948400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,3143484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948257, endtime: 40948400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,3143778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948257, endtime: 40948400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,8931900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948366, endtime: 40948458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,8932080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948367, endtime: 40948458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,8932154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948367, endtime: 40948458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,8932232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948368, endtime: 40948458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,8932290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948368, endtime: 40948458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,8932362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948370, endtime: 40948458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,8932418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948371, endtime: 40948458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,8932487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948371, endtime: 40948458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,8932542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948372, endtime: 40948458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,8932833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948374, endtime: 40948458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,8932894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948374, endtime: 40948458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,8932961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948375, endtime: 40948458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:51,8933019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948375, endtime: 40948458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:52,3894056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948389, endtime: 40948508, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:52,3894217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948390, endtime: 40948508, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:52,3894289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948391, endtime: 40948508, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:52,3894358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948392, endtime: 40948508, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:52,3894411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948393, endtime: 40948508, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:52,3894475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948394, endtime: 40948508, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:52,3894527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948395, endtime: 40948508, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:52,3894591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948396, endtime: 40948508, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:52,3895796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948396, endtime: 40948508, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:52,3895874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948397, endtime: 40948508, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:52,7986105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54906 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,0564990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54883 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,0993911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54906 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,0994039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54906 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,1028275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54906 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40948579, endtime: 40948579, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,1029743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54906 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40948579, endtime: 40948579, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,7554055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948176, endtime: 40948644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,7554255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948177, endtime: 40948644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,7554338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948177, endtime: 40948644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,7554418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948178, endtime: 40948644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,7554479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948179, endtime: 40948644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,7554549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948179, endtime: 40948644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,7554610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948180, endtime: 40948644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,7554679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948180, endtime: 40948644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,7554734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948181, endtime: 40948644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,7555033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948182, endtime: 40948644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,7555094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948182, endtime: 40948644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,7555164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948183, endtime: 40948644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,7555222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948183, endtime: 40948644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,8783478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948258, endtime: 40948656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,8783633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948258, endtime: 40948656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,8783702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948259, endtime: 40948656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,8783771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948400, endtime: 40948656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,8783827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948401, endtime: 40948656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,8783891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948401, endtime: 40948656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,8783943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948402, endtime: 40948656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,8784007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948402, endtime: 40948656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,8784060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948403, endtime: 40948656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,8785248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948403, endtime: 40948656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,8785315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948404, endtime: 40948656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,8785376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948405, endtime: 40948656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:53,8785428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948405, endtime: 40948656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:54,4325616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947351, endtime: 40948712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:54,4325807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947352, endtime: 40948712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:54,4325901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947353, endtime: 40948712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:54,4325970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947353, endtime: 40948712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:54,4326045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947354, endtime: 40948712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:54,4326103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947354, endtime: 40948712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:54,4326330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947355, endtime: 40948712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:54,4326405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947356, endtime: 40948712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:54,4326483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947356, endtime: 40948712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:54,4326776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947357, endtime: 40948712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:54,4326854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947358, endtime: 40948712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:54,4326912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947358, endtime: 40948712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:54,4326984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40947359, endtime: 40948712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,8778405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948397, endtime: 40948956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,8778646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948398, endtime: 40948956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,8778784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948399, endtime: 40948956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,8778917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948508, endtime: 40948956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,8779023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948508, endtime: 40948956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,8779145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948509, endtime: 40948956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,8779244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948509, endtime: 40948956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,8779369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948510, endtime: 40948956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,8779472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948511, endtime: 40948956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,8779907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948511, endtime: 40948956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,8779998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948512, endtime: 40948956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,8780073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948513, endtime: 40948956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,8780131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948513, endtime: 40948956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,9527847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948354, endtime: 40948964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,9528027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948355, endtime: 40948964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,9528127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948355, endtime: 40948964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,9528202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948356, endtime: 40948964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,9528277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948356, endtime: 40948964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,9528337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948358, endtime: 40948964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,9528409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948359, endtime: 40948964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,9528468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948360, endtime: 40948964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,9528540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948362, endtime: 40948964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,9529199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948363, endtime: 40948964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,9529291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948364, endtime: 40948964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,9529351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948364, endtime: 40948964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:56,9530061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948365, endtime: 40948964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7595777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948656, endtime: 40949145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7595941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948657, endtime: 40949145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7596013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948658, endtime: 40949145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7596088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948658, endtime: 40949145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7596151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948659, endtime: 40949145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7596221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948660, endtime: 40949145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7596282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948660, endtime: 40949145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7596348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948661, endtime: 40949145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7596406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948661, endtime: 40949145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7596717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948663, endtime: 40949145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7596778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948664, endtime: 40949145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7596847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948664, endtime: 40949145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7596905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948665, endtime: 40949145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7760573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948644, endtime: 40949146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7760775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948645, endtime: 40949146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7760856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948645, endtime: 40949146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7760933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948647, endtime: 40949146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7760994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948648, endtime: 40949146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7761063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948648, endtime: 40949146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7761122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948649, endtime: 40949146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7761191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948650, endtime: 40949146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7761252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948651, endtime: 40949146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7761543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948652, endtime: 40949146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7761606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948653, endtime: 40949146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7761678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948653, endtime: 40949146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,7761737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948654, endtime: 40949146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,8330028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948360, endtime: 40949152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,8330217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948362, endtime: 40949152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,8330319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948363, endtime: 40949152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,8330394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948364, endtime: 40949152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,8330472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948364, endtime: 40949152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,8330536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948365, endtime: 40949152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,8330610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948366, endtime: 40949152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,8330674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948367, endtime: 40949152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,8330746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948367, endtime: 40949152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,8331037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948368, endtime: 40949152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,8331115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948368, endtime: 40949152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,8331176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948370, endtime: 40949152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:53:58,8331250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948371, endtime: 40949152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,2188181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949145, endtime: 40949390, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,2188344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949148, endtime: 40949390, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,2188416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949149, endtime: 40949390, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,2188488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949150, endtime: 40949390, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,2188544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949150, endtime: 40949390, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,2188607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949157, endtime: 40949390, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,2188663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949164, endtime: 40949390, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,2188729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949167, endtime: 40949390, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,2188782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949174, endtime: 40949390, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,2189087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949177, endtime: 40949391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,2189145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949177, endtime: 40949391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,2189211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949184, endtime: 40949391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,2189267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949184, endtime: 40949391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,4220151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948459, endtime: 40949411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,4220315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948460, endtime: 40949411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,4220398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948460, endtime: 40949411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,4220459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948461, endtime: 40949411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,4220528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948462, endtime: 40949411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,4220584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948463, endtime: 40949411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,4220647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948464, endtime: 40949411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,4220700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948465, endtime: 40949411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,4220764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948466, endtime: 40949411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,4221052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948466, endtime: 40949411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,4221118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948467, endtime: 40949411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,4222412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948468, endtime: 40949411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:01,4222501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948469, endtime: 40949411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,4907034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948964, endtime: 40949518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,4907195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948965, endtime: 40949518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,4907270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948965, endtime: 40949518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,4907342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948966, endtime: 40949518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,4907403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948966, endtime: 40949518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,4907472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948967, endtime: 40949518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,4907527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948967, endtime: 40949518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,4907591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948968, endtime: 40949518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,4907649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948969, endtime: 40949518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,4907946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948969, endtime: 40949518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,4908004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948970, endtime: 40949518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,4908070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948970, endtime: 40949518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,4908123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948971, endtime: 40949518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,9803936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949164, endtime: 40949567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,9804133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949167, endtime: 40949567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,9804213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949174, endtime: 40949567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,9804291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949177, endtime: 40949567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,9804355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949177, endtime: 40949567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,9804548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949184, endtime: 40949567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,9804629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949184, endtime: 40949567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,9804704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949185, endtime: 40949567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,9804767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949188, endtime: 40949567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,9805111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949193, endtime: 40949567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,9805172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949193, endtime: 40949567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,9805241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949194, endtime: 40949567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:02,9805299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949194, endtime: 40949567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,2608849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948957, endtime: 40949595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,2609010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948957, endtime: 40949595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,2609082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948958, endtime: 40949595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,2609154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948958, endtime: 40949595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,2609209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948959, endtime: 40949595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,2609276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948959, endtime: 40949595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,2609328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948960, endtime: 40949595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,2609395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948961, endtime: 40949595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,2609447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948961, endtime: 40949595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,2609735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948962, endtime: 40949595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,2609791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948962, endtime: 40949595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,2609855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948963, endtime: 40949595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,2609910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40948964, endtime: 40949595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,3960492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949411, endtime: 40949608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,3960669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949412, endtime: 40949608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,3960741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949412, endtime: 40949608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,3960816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949413, endtime: 40949608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,3960871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949414, endtime: 40949608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,3960935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949414, endtime: 40949608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,3960988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949415, endtime: 40949608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,3961054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949415, endtime: 40949608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,3961110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949416, endtime: 40949608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,3961400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949417, endtime: 40949608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,3961456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949417, endtime: 40949608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,3961520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949418, endtime: 40949608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,3961575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949418, endtime: 40949608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,7656871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949148, endtime: 40949645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,7657034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949149, endtime: 40949645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,7657106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949150, endtime: 40949645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,7657176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949150, endtime: 40949645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,7657231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949157, endtime: 40949645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,7657295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949164, endtime: 40949645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,7657347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949167, endtime: 40949645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,7657411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949174, endtime: 40949645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,7657464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949177, endtime: 40949645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,7657741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949177, endtime: 40949645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,7657796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949184, endtime: 40949645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,7657860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949184, endtime: 40949645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,7658043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949185, endtime: 40949645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:03,9212563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54888 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,6547688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949567, endtime: 40949834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,6547868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949567, endtime: 40949834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,6547946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949568, endtime: 40949834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,6548026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949568, endtime: 40949834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,6548087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949569, endtime: 40949834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,6548159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949570, endtime: 40949834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,6548217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949571, endtime: 40949834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,6548289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949571, endtime: 40949834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,6548348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949572, endtime: 40949834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,6548644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949573, endtime: 40949834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,6548708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949573, endtime: 40949834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,6548780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949574, endtime: 40949834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,6548838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949574, endtime: 40949834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,8186023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949391, endtime: 40949850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,8186175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949391, endtime: 40949850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,8186245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949392, endtime: 40949850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,8186317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949392, endtime: 40949850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,8186369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949393, endtime: 40949850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,8186433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949394, endtime: 40949850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,8186486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949394, endtime: 40949850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,8186549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949395, endtime: 40949850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,8186599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949395, endtime: 40949850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,8186887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949396, endtime: 40949850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,8186943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949397, endtime: 40949850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,8187004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949397, endtime: 40949850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:05,8187056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949398, endtime: 40949850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:06,6922019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949608, endtime: 40949938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:06,6922185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949609, endtime: 40949938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:06,6922257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949610, endtime: 40949938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:06,6922329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949610, endtime: 40949938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:06,6922382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949611, endtime: 40949938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:06,6922445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949612, endtime: 40949938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:06,6922498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949612, endtime: 40949938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:06,6922562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949613, endtime: 40949938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:06,6922611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949613, endtime: 40949938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:06,6922889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949614, endtime: 40949938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:06,6922944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949614, endtime: 40949938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:06,6923008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949615, endtime: 40949938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:06,6923060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949616, endtime: 40949938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,0105088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949519, endtime: 40949970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,0105229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949519, endtime: 40949970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,0105296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949520, endtime: 40949970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,0105365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949521, endtime: 40949970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,0105420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949521, endtime: 40949970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,0105484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949522, endtime: 40949970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,0105537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949523, endtime: 40949970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,0105600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949523, endtime: 40949970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,0105653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949524, endtime: 40949970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,0106323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949525, endtime: 40949970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,0106387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949525, endtime: 40949970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,0106454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949526, endtime: 40949970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,0107199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949526, endtime: 40949970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,1716717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949595, endtime: 40949986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,1717039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949595, endtime: 40949986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,1717155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949596, endtime: 40949986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,1717274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949596, endtime: 40949986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,1717371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949597, endtime: 40949986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,1717488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949598, endtime: 40949986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,1717584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949598, endtime: 40949986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,1717701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949599, endtime: 40949986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,1717795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949599, endtime: 40949986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,1718540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949600, endtime: 40949986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,1718615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949600, endtime: 40949986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,1718682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949601, endtime: 40949986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:07,1719709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949602, endtime: 40949986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,1237615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949645, endtime: 40950081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,1237793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949646, endtime: 40950081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,1237873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949646, endtime: 40950081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,1237953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949647, endtime: 40950081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,1238014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949648, endtime: 40950081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,1238086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949648, endtime: 40950081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,1238145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949649, endtime: 40950081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,1238217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949650, endtime: 40950081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,1238272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949651, endtime: 40950081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,1238552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949651, endtime: 40950081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,1238616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949652, endtime: 40950081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,1238685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949652, endtime: 40950081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,1238743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949653, endtime: 40950081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,3683075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949938, endtime: 40950105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,3683233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949938, endtime: 40950105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,3683303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949939, endtime: 40950105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,3683375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949940, endtime: 40950105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,3683430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949940, endtime: 40950105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,3683499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949941, endtime: 40950105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,3683552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949941, endtime: 40950105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,3683621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949942, endtime: 40950105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,3683674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949943, endtime: 40950105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,3683957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949943, endtime: 40950105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,3684012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949944, endtime: 40950105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,3688132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949944, endtime: 40950105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,3688254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949945, endtime: 40950105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8629108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949850, endtime: 40950155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8629274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949851, endtime: 40950155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8629352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949852, endtime: 40950155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8629429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949852, endtime: 40950155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8629490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949853, endtime: 40950155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8629562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949853, endtime: 40950155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8629620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949854, endtime: 40950155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8629692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949854, endtime: 40950155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8629751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949855, endtime: 40950155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8630050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949855, endtime: 40950155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8630111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949856, endtime: 40950155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8630183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949857, endtime: 40950155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8630363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949857, endtime: 40950155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:08,8769229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950081, endtime: 40950156, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:09,9770163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949970, endtime: 40950266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:09,9770357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949970, endtime: 40950266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:09,9770437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949971, endtime: 40950266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:09,9770518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949971, endtime: 40950266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:09,9770581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949972, endtime: 40950266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:09,9770653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949972, endtime: 40950266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:09,9770712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949973, endtime: 40950266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:09,9770784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949974, endtime: 40950266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:09,9770842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949974, endtime: 40950266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:09,9771548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949975, endtime: 40950266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:09,9771640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949975, endtime: 40950266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:09,9771715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949976, endtime: 40950266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,1930840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949976, endtime: 40950288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8628279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950105, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8628465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950106, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8628537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950107, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8628612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950107, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8628670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950108, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8628736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950108, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8628792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950109, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8628856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950110, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8628914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950110, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8629246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950111, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8629307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950111, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8629371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950116, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8629426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950124, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8629532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949834, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8629587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949835, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8629656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949835, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8629709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949836, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8629773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949836, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8629828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949837, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8630374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949838, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8630440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949838, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8630507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949839, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8630573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949839, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8630626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949840, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8630690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949840, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:10,8630745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949841, endtime: 40950355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:11,9405458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950082, endtime: 40950463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:11,9405613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950082, endtime: 40950463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:11,9405699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950083, endtime: 40950463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:11,9405760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950083, endtime: 40950463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:11,9405829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950084, endtime: 40950463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:11,9405881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950085, endtime: 40950463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:11,9405948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950085, endtime: 40950463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:11,9406001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950086, endtime: 40950463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:11,9406067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950087, endtime: 40950463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:11,9406613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950088, endtime: 40950463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:11,9406693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950088, endtime: 40950463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:11,9406746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950089, endtime: 40950463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,1520706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,1520969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,1521077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,1521185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,1521368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\CTF\DirectSwitchHotkeys</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,1521476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,1521570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\CTF\DirectSwitchHotkeys</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 288</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,1521653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\CTF\DirectSwitchHotkeys</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6041235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Windows\SysWOW64\imm32.dll</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 41 984, Length: 28 672, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6756372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6756516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6756663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\KnownClasses</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6770560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6770699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6770843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\TIP\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6771065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6771217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6771303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: {0000897b-83df-4b96-be07-0fb58b01c4a4}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6771494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6771574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6771694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: {03b5835f-f03c-411b-9ce2-aa23e1171e36}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6771785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6771851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{03b5835f-f03c-411b-9ce2-aa23e1171e36}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6771965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 2, Name: {07EB03D6-B001-41DF-9192-BF9B841EE71F}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6772051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6772115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6772231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 3, Name: {531fdebf-9b4c-4a43-a2aa-960e8fcdc732}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6772317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6772378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{531fdebf-9b4c-4a43-a2aa-960e8fcdc732}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6772478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 4, Name: {6a498709-e00b-4c45-a018-8f9e4081ae40}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6772561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6772624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{6a498709-e00b-4c45-a018-8f9e4081ae40}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6772738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 5, Name: {78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6772818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6772879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6772974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 6, Name: {81d4e9c9-1d3b-41bc-9e6c-4b40bf79e35e}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6773057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6773120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{81d4e9c9-1d3b-41bc-9e6c-4b40bf79e35e}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6773226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 7, Name: {8613E14C-D0C0-4161-AC0F-1DD2563286BC}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6773314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6773372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6773469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 8, Name: {a028ae76-01b1-46c2-99c4-acd9858ae02f}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6773555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6773616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{a028ae76-01b1-46c2-99c4-acd9858ae02f}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6773727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 9, Name: {a1e2b86b-924a-4d43-80f6-8a820df7190f}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6773807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6773871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{a1e2b86b-924a-4d43-80f6-8a820df7190f}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6773957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 10, Name: {AE6BE008-07FB-400D-8BEB-337A64F7051F}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6774037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6774098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6774190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 11, Name: {B115690A-EA02-48D5-A231-E3578D2FDF80}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6774273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6774334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{B115690A-EA02-48D5-A231-E3578D2FDF80}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6774431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 12, Name: {C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6774514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6774575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6774716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: {85F9794B-4D19-40D8-8864-4E747371A66D}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6774785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 1, Length: 288</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6775024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6775112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 13, Name: {DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6775226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6775298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6775880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 14, Name: {E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6776029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6776101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6776226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 15, Name: {F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6776312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6776376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6776487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 16, Name: {F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6776567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6776628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6776722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 17, Name: {FA445657-9379-11D6-B41A-00065B83EE53}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6776802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6776863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6776966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 18, Length: 288</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6777055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6777570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6777667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6777772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\TIP\</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6777861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6777991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6778057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: {0000897b-83df-4b96-be07-0fb58b01c4a4}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6778163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6778232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6778321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 1, Name: {03b5835f-f03c-411b-9ce2-aa23e1171e36}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6778404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6778465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{03b5835f-f03c-411b-9ce2-aa23e1171e36}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6778565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 2, Name: {07EB03D6-B001-41DF-9192-BF9B841EE71F}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6778650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6778711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6778800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 3, Name: {531fdebf-9b4c-4a43-a2aa-960e8fcdc732}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6778883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6778944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{531fdebf-9b4c-4a43-a2aa-960e8fcdc732}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6779033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 4, Name: {6a498709-e00b-4c45-a018-8f9e4081ae40}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6779113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6779174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{6a498709-e00b-4c45-a018-8f9e4081ae40}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6779263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 5, Name: {78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6779343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6779404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6779534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>SUCCESS</Result>
<Detail>Index: 0, Name: {34B45670-7526-11D2-A147-00105A2799B5}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6779601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 1, Length: 288</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6779667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6779717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 6, Name: {81d4e9c9-1d3b-41bc-9e6c-4b40bf79e35e}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6779803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6779864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{81d4e9c9-1d3b-41bc-9e6c-4b40bf79e35e}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6779966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 7, Name: {8613E14C-D0C0-4161-AC0F-1DD2563286BC}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6780050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6780110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6780210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 8, Name: {a028ae76-01b1-46c2-99c4-acd9858ae02f}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6780296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6780357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{a028ae76-01b1-46c2-99c4-acd9858ae02f}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6780457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 9, Name: {a1e2b86b-924a-4d43-80f6-8a820df7190f}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6780540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6780601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{a1e2b86b-924a-4d43-80f6-8a820df7190f}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6780690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 10, Name: {AE6BE008-07FB-400D-8BEB-337A64F7051F}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6780770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6780831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6780922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 11, Name: {B115690A-EA02-48D5-A231-E3578D2FDF80}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{B115690A-EA02-48D5-A231-E3578D2FDF80}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 12, Name: {C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 13, Name: {DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 14, Name: {E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 15, Name: {F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6781992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6782086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 16, Name: {F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6782166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6782230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6782316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Index: 17, Name: {FA445657-9379-11D6-B41A-00065B83EE53}</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6782399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6782460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6782549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 18, Length: 288</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:12,6782618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\Microsoft\CTF\TIP</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,1374548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950355, endtime: 40950582, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,1374708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950356, endtime: 40950582, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,1374777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950356, endtime: 40950582, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,1374850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950357, endtime: 40950582, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,1374902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950357, endtime: 40950582, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,1374966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950358, endtime: 40950582, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,1375019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950359, endtime: 40950582, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,1375082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950359, endtime: 40950582, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,1375135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950360, endtime: 40950582, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,1375448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950360, endtime: 40950582, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,1375501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950361, endtime: 40950582, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,1375564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950362, endtime: 40950582, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,1376601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950362, endtime: 40950582, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,7981489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950266, endtime: 40950648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,7981661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950267, endtime: 40950648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,7982171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950268, endtime: 40950648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,7982262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950268, endtime: 40950648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,7982340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950269, endtime: 40950648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,7982404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950269, endtime: 40950648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,7982478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950270, endtime: 40950648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,7982539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950271, endtime: 40950648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,7982611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950271, endtime: 40950648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,7983495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950272, endtime: 40950648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,7983614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950273, endtime: 40950648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,7983697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950273, endtime: 40950648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,7984758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950288, endtime: 40950648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8775003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950355, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8775169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950356, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8775235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950356, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8775307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950357, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8775363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950357, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8775427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950358, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8775479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950359, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8775543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950359, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8775593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950360, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8775911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950360, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8775967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950361, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8776031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950362, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8776083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950362, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8776197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950155, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8776263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950156, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8776316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950156, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8776380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950157, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8776432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950158, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8776496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950158, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8777017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950159, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8777089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950159, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8777142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950160, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8777205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950160, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8777258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950161, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8777319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950162, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:13,8777372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950162, endtime: 40950656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,0450995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949986, endtime: 40950673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,0451150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949986, endtime: 40950673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,0451372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949987, endtime: 40950673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,0451447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949988, endtime: 40950673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,0451538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949988, endtime: 40950673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,0451596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949989, endtime: 40950673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,0451666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949990, endtime: 40950673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,0451724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949990, endtime: 40950673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,0451793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949991, endtime: 40950673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,0452355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949991, endtime: 40950673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,0452433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949992, endtime: 40950673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,0452486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949993, endtime: 40950673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,6864646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950156, endtime: 40950737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,6864823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950463, endtime: 40950737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,6864917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950466, endtime: 40950737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,6864984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950467, endtime: 40950737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,6865059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950469, endtime: 40950737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,6865120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950470, endtime: 40950737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,6865189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950472, endtime: 40950737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,6865250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950473, endtime: 40950737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,6865319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950478, endtime: 40950737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,6865377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950480, endtime: 40950737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,6865693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950483, endtime: 40950737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,6865754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950485, endtime: 40950737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,6865826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950486, endtime: 40950737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8735001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950737, endtime: 40950756, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8753711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8754287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNetworkOpenInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, AllocationSize: 01.01.1601 3:00:00, EndOfFile: 01.01.1601 3:00:00, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8754390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8757130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8760925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 16 384, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8761408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 0, Length: 16 384, I/O Flags: Non-cached, Paging I/O, Priority: Normal</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8847785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail>Offset: 16 384, Length: 16</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8912417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>ReadFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>END OF FILE</Result>
<Detail>Offset: 16 400, Length: 16 368</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8912636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8912755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, FileAttributes: A, AllocationSize: 20 480, EndOfFile: 16 400, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x2100000002039d, EaSize: 0, Access: Generic Read, Position: 16 400, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8912916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryInformationVolume</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>VolumeCreationTime: 19.07.2018 19:30:42, VolumeSerialNumber: B6D8-C2CA, SupportsObjects: True, VolumeLabel: Winb</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8912988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryAllInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>CreationTime: 24.08.2018 12:30:32, LastAccessTime: 24.08.2018 12:30:32, LastWriteTime: 24.08.2018 12:30:32, ChangeTime: 24.08.2018 12:30:32, FileAttributes: A, AllocationSize: 20 480, EndOfFile: 16 400, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x2100000002039d, EaSize: 0, Access: Generic Read, Position: 16 400, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Word</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8913436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\icon.png</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8919659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\System\CurrentControlSet\Control\WMI\Security\79172b48-631e-5d2c-9f04-1ad99f6e1046</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 524</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8921338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryNameInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Name: \Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8924635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8924835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryBasicInformationFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail>CreationTime: 24.08.2018 12:30:11, LastAccessTime: 24.08.2018 12:30:11, LastWriteTime: 24.08.2018 12:38:31, ChangeTime: 24.08.2018 12:38:31, FileAttributes: A</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8924923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData\Roaming\MCLauncher\MCLauncher.exe</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8925253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8925439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail>Filter: Users, 1: Users</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8925641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8926586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8926946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>Filter: User, 1: User</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8927134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8928096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8928295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail>Filter: AppData, 1: AppData</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8928472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8929392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8929581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>QueryDirectory</Operation>
<Path>C:\Users\User\AppData\Roaming</Path>
<Result>SUCCESS</Result>
<Detail>Filter: Roaming, 1: Roaming</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8929722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>CloseFile</Operation>
<Path>C:\Users\User\AppData</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8930639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8930761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8930910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8931146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8931260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8931332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8931456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8931525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8931697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 32, Data: ProgramFilesX86</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8931852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8931972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8932085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8932193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8932298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8932407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalizedName</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21817</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8932534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8932642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8932750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8932855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8932961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8933069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8933174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PreCreate</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8933296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8933404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8933512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8933617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Attributes</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 1</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8933734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8933842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8934202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8934274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8934401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8934529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8934606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8934701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8934834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 46, Data: C:\Program Files (x86)</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8934991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8935676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8935762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8935861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8935997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8936078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8936136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8936230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8936280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8936424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 20, Data: SystemX86</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8936673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8936798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8936906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8937020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8937172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8937377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8937499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8937690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8937798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8937903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8938011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8938114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8938219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8938324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8938430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8938532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8938635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8938743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8938845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8938989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8939056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8939158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8939350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8939433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8939527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8939654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8939732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8939790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8939881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8939926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Category</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 2</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8940059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Name</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_SZ, Length: 16, Data: Windows</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8940192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParentFolder</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8940303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Description</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8940408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\RelativePath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8940510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParsingName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8940616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InfoTip</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8940721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalizedName</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8940826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Icon</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8940929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Security</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8941034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResource</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8941209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResourceType</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8941314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalRedirectOnly</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8941416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Roamable</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8941522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PreCreate</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8941621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Stream</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8941727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PublishExpandedPath</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8941832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\DefinitionFlags</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8941937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Attributes</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8942040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\FolderTypeID</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8942142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InitFolderHandler</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 144</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8942278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x400</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8942339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:14,8942441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:15,6326786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950582, endtime: 40950832, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:15,6326935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950584, endtime: 40950832, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:15,6327005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950586, endtime: 40950832, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:15,6327077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950587, endtime: 40950832, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:15,6327132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950589, endtime: 40950832, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:15,6327196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950591, endtime: 40950832, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:15,6327249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950592, endtime: 40950832, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:15,6327312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950595, endtime: 40950832, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:15,6327365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950597, endtime: 40950832, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:15,6327656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950598, endtime: 40950832, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:15,6327711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950600, endtime: 40950832, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:15,6327772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950601, endtime: 40950832, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:15,6327825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950601, endtime: 40950832, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:17,8610235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950656, endtime: 40951055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:17,8610404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950658, endtime: 40951055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:17,8610476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950661, endtime: 40951055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:17,8610548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950662, endtime: 40951055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:17,8610606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950664, endtime: 40951055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:17,8610675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950666, endtime: 40951055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:17,8610731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950666, endtime: 40951055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:17,8610797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950667, endtime: 40951055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:17,8610850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950669, endtime: 40951055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:17,8611174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950670, endtime: 40951055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:17,8611232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950672, endtime: 40951055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:17,8611299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950675, endtime: 40951055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:17,8611354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950677, endtime: 40951055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0832812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950656, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0833003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950658, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0833080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950661, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0833155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950662, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0833213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950664, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0833283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950666, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0833343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950666, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0833410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950667, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0833465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950669, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0833776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950670, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0833834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950672, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0833903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950675, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0833959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950677, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,0834078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951055, endtime: 40951077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,1454143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950832, endtime: 40951083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,1454401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950834, endtime: 40951083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,1454498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950836, endtime: 40951083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,1454589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950839, endtime: 40951083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,1454661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950841, endtime: 40951083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,1454741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950842, endtime: 40951083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,1454811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950844, endtime: 40951083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,1454888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950848, endtime: 40951083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,1454955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950850, endtime: 40951083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,1455271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950853, endtime: 40951083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,1455343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950855, endtime: 40951083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,1455420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950856, endtime: 40951083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,1455487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950858, endtime: 40951083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,2643830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951083, endtime: 40951095, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,9447337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950648, endtime: 40951163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,9447684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950650, endtime: 40951163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,9447828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950651, endtime: 40951163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,9447966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950653, endtime: 40951163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,9448072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950655, endtime: 40951163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,9448199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950656, endtime: 40951163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,9448307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950658, endtime: 40951163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,9448434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950661, endtime: 40951163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,9448537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950662, endtime: 40951163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,9448917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950664, endtime: 40951163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,9448989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950666, endtime: 40951163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,9449061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950666, endtime: 40951163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:18,9449124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950667, endtime: 40951163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:19,3234940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950739, endtime: 40951201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:19,3235084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950741, endtime: 40951201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:19,3235170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950742, endtime: 40951201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:19,3235228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950744, endtime: 40951201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:19,3235297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950747, endtime: 40951201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:19,3235353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950748, endtime: 40951201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:19,3235419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950750, endtime: 40951201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:19,3235486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950751, endtime: 40951201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:19,3235539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950753, endtime: 40951201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:19,3236336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950755, endtime: 40951201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:19,3236447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950758, endtime: 40951201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:19,3236558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950759, endtime: 40951201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:19,3244235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950763, endtime: 40951201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,1227140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951084, endtime: 40951281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,1227309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951086, endtime: 40951281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,1227411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951089, endtime: 40951281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,1227489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951091, endtime: 40951281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,1227569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951092, endtime: 40951281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,1227641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951095, endtime: 40951281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,1227719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951097, endtime: 40951281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,1227785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951100, endtime: 40951281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,1227863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951102, endtime: 40951281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,1228539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951104, endtime: 40951281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,1228642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951106, endtime: 40951281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,1228708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951107, endtime: 40951281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,1234329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951108, endtime: 40951281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2535055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40949993, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2535230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950673, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2535315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950675, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2535379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950677, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2535448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950678, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2535504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950680, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2535568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950683, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2535620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950686, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2535684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950687, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2535739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950689, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2536030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950692, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2536086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950694, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2536152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40950697, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,2538587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951294, endtime: 40951294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9260169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951056, endtime: 40951361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9260358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951058, endtime: 40951361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9260449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951062, endtime: 40951361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9260518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951067, endtime: 40951361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9282423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951069, endtime: 40951361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9282569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951073, endtime: 40951361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9282658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951075, endtime: 40951361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9282725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951077, endtime: 40951361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9282799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951078, endtime: 40951361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9282860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951080, endtime: 40951361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9282930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951083, endtime: 40951361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9282988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951084, endtime: 40951361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9283063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951086, endtime: 40951361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9472746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951077, endtime: 40951363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9472926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951078, endtime: 40951363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9472998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951080, endtime: 40951363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9473073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951083, endtime: 40951363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9473131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951084, endtime: 40951363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9473201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951086, endtime: 40951363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9473256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951089, endtime: 40951363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9473328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951092, endtime: 40951363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9473386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951095, endtime: 40951363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9473683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951097, endtime: 40951363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9473741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951100, endtime: 40951363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9473940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951102, endtime: 40951363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:20,9474048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951104, endtime: 40951363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,2039612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951163, endtime: 40951389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,2039776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951164, endtime: 40951389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,2039851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951164, endtime: 40951389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,2039923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951165, endtime: 40951389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,2039984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951165, endtime: 40951389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,2040050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951166, endtime: 40951389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,2040105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951167, endtime: 40951389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,2040172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951167, endtime: 40951389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,2040230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951168, endtime: 40951389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,2040942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951168, endtime: 40951389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,2041142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951169, endtime: 40951389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,2041252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951170, endtime: 40951389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,2051889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951171, endtime: 40951389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,3221090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951281, endtime: 40951401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,3221373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951282, endtime: 40951401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,3221481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951282, endtime: 40951401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,3221583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951284, endtime: 40951401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,3221661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951284, endtime: 40951401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,3221747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951285, endtime: 40951401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,3221824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951286, endtime: 40951401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,3221910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951286, endtime: 40951401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,3221985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951287, endtime: 40951401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,3222683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951287, endtime: 40951401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,3222841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951288, endtime: 40951401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,3222988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951289, endtime: 40951401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,8501679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951201, endtime: 40951454, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,8501914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951202, endtime: 40951454, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,8502019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951202, endtime: 40951454, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,8502116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951203, endtime: 40951454, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,8502194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951204, endtime: 40951454, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,8502280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951204, endtime: 40951454, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,8502357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951205, endtime: 40951454, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,8502449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951205, endtime: 40951454, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,8502526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951206, endtime: 40951454, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,8503402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951207, endtime: 40951454, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,8503496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951207, endtime: 40951454, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,8503585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951208, endtime: 40951454, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:21,8504100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951209, endtime: 40951454, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,1235133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951295, endtime: 40951581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,1235374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951295, endtime: 40951581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,1235471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951296, endtime: 40951581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,1235560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951297, endtime: 40951581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,1235632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951297, endtime: 40951581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,1235709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951298, endtime: 40951581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,1235773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951298, endtime: 40951581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,1235989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951299, endtime: 40951581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,1236078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951300, endtime: 40951581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,1236668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951300, endtime: 40951581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,1236754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951301, endtime: 40951581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,1236831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951302, endtime: 40951581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,1582603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54912 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,3177650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54906 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,4358627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54912 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,4358757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54912 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,4362880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54912 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40951612, endtime: 40951612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:23,4364040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54912 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40951612, endtime: 40951612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,0631580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951289, endtime: 40951675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,0631766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951401, endtime: 40951675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,0631838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951405, endtime: 40951675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,0631907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951407, endtime: 40951675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,0631963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951409, endtime: 40951675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,0632026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951411, endtime: 40951675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,0632079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951411, endtime: 40951675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,0632140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951412, endtime: 40951675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,0632192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951413, endtime: 40951675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,0632508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951413, endtime: 40951675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,0632564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951414, endtime: 40951675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,0632627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951415, endtime: 40951675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,0632677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951415, endtime: 40951675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,3471000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951361, endtime: 40951703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,3471155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951362, endtime: 40951703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,3471225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951366, endtime: 40951703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,3471297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951367, endtime: 40951703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,3471352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951369, endtime: 40951703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,3471416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951372, endtime: 40951703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,3471471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951373, endtime: 40951703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,3471535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951375, endtime: 40951703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,3471590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951377, endtime: 40951703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,3472252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951379, endtime: 40951703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,3472322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951381, endtime: 40951703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,3472388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951384, endtime: 40951703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,3473164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951386, endtime: 40951703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,8631219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951363, endtime: 40951755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,8631557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951366, endtime: 40951755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,8631637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951367, endtime: 40951755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,8631723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951369, endtime: 40951755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,8631781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951372, endtime: 40951755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,8631853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951373, endtime: 40951755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,8631912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951375, endtime: 40951755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,8631981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951377, endtime: 40951755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,8632039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951379, endtime: 40951755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,8632391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951381, endtime: 40951755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,8632446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951384, endtime: 40951755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,8632510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951386, endtime: 40951755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:24,8632565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951388, endtime: 40951755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,3239104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951389, endtime: 40951801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,3239273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951391, endtime: 40951801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,3239343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951394, endtime: 40951801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,3239415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951397, endtime: 40951801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,3239470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951400, endtime: 40951801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,3239536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951402, endtime: 40951801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,3239589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951405, endtime: 40951801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,3239656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951407, endtime: 40951801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,3239708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951409, endtime: 40951801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,3240420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951411, endtime: 40951801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,3240634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951411, endtime: 40951801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,3240750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951412, endtime: 40951801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,3241628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951413, endtime: 40951801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,7339207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951302, endtime: 40951842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,7339434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951581, endtime: 40951842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,7339525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951583, endtime: 40951842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,7339609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951586, endtime: 40951842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,7339675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951588, endtime: 40951842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,7339750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951589, endtime: 40951842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,7339811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951591, endtime: 40951842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,7339883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951596, endtime: 40951842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,7339941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951597, endtime: 40951842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,7340249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951599, endtime: 40951842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,7340312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951603, endtime: 40951842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,7340384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951604, endtime: 40951842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:25,7340617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951604, endtime: 40951842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,1218410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951454, endtime: 40951881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,1218573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951455, endtime: 40951881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,1218643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951458, endtime: 40951881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,1218712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951465, endtime: 40951881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,1218764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951467, endtime: 40951881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,1218828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951469, endtime: 40951881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,1218881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951470, endtime: 40951881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,1218945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951472, endtime: 40951881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,1218997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951474, endtime: 40951881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,1219537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951477, endtime: 40951881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,1220643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951480, endtime: 40951881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,1220768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951483, endtime: 40951881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,5161563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951675, endtime: 40951920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,5161779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951676, endtime: 40951920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,5161882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951678, endtime: 40951920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,5161990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951680, endtime: 40951920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,5162075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951681, endtime: 40951920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,5162175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951683, endtime: 40951920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,5162261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951684, endtime: 40951920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,5162364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951686, endtime: 40951920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,5162441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951689, endtime: 40951920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,5162799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951692, endtime: 40951920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,5163646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951694, endtime: 40951920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,5163807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951695, endtime: 40951920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:26,5163907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951697, endtime: 40951920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8693626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951755, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8693778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951756, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8693845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951759, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8693917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951761, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8693972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951762, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8694036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951764, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8694091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951769, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8694155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951770, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8694208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951772, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8694537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951773, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8694593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951775, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8694656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951777, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8694709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951778, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8694848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951703, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8694911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951705, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8694964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951708, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8695028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951709, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8695080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951711, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8695878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951712, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8695942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951714, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8696006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951716, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8696058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951717, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8696122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951720, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8696175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951722, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8696238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951723, endtime: 40952056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:27,8828594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951725, endtime: 40952057, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:28,2972172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951801, endtime: 40952098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:28,2972357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951803, endtime: 40952098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:28,2972449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951806, endtime: 40952098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:28,2972538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951808, endtime: 40952098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:28,2972607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951809, endtime: 40952098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:28,2972682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951811, endtime: 40952098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:28,2972748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951812, endtime: 40952098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:28,2972826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951814, endtime: 40952098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:28,2972887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951817, endtime: 40952098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:28,2973446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951819, endtime: 40952098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:28,2973527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951820, endtime: 40952098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:28,2973604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951826, endtime: 40952098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:28,5963599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951827, endtime: 40952128, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2207716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951484, endtime: 40952191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2207891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951881, endtime: 40952191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2207963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951883, endtime: 40952191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2208035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951884, endtime: 40952191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2208093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951886, endtime: 40952191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2208157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951887, endtime: 40952191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2208212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951889, endtime: 40952191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2208278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951890, endtime: 40952191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2208331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951892, endtime: 40952191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2208619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951895, endtime: 40952191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2208677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951895, endtime: 40952191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2208741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951897, endtime: 40952191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2208797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951898, endtime: 40952191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2938407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951842, endtime: 40952198, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2938590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951844, endtime: 40952198, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2938670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951845, endtime: 40952198, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2938748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951847, endtime: 40952198, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2938809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951848, endtime: 40952198, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2938881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951850, endtime: 40952198, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2938942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951851, endtime: 40952198, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2939011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951852, endtime: 40952198, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2939072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951852, endtime: 40952198, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2939648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951855, endtime: 40952198, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2939875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951856, endtime: 40952198, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2939964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951858, endtime: 40952198, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,2940028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951861, endtime: 40952198, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,3673126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952198, endtime: 40952205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,9021713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952056, endtime: 40952259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,9021860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952056, endtime: 40952259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,9021940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952058, endtime: 40952259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,9021998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952059, endtime: 40952259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,9022065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952061, endtime: 40952259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,9022117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952062, endtime: 40952259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,9022181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952066, endtime: 40952259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,9022234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952067, endtime: 40952259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,9022295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952069, endtime: 40952259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,9022868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952070, endtime: 40952259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,9022946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952072, endtime: 40952259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:29,9022998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952073, endtime: 40952259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,6887808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952200, endtime: 40952437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,6887999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952205, endtime: 40952437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,6888093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952209, endtime: 40952437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,6888160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952210, endtime: 40952437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,6888232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952213, endtime: 40952437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,6888293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952214, endtime: 40952437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,6888362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952216, endtime: 40952437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,6888420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952219, endtime: 40952437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,6888489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952221, endtime: 40952437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,6889041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952222, endtime: 40952438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,6889129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952225, endtime: 40952438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,6889295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952228, endtime: 40952438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,7179235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952099, endtime: 40952440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,7179384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952100, endtime: 40952440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,7179465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952100, endtime: 40952440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,7179526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952101, endtime: 40952440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,7179592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952102, endtime: 40952440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,7179645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952105, endtime: 40952440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,7179711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952107, endtime: 40952440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,7179764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952110, endtime: 40952440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,7179828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952112, endtime: 40952440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,7180384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952114, endtime: 40952440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,7180465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952116, endtime: 40952440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,7181446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952117, endtime: 40952440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,8254952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952056, endtime: 40952451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,8255129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952056, endtime: 40952451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,8255207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952058, endtime: 40952451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,8255282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952059, endtime: 40952451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,8255340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952061, endtime: 40952451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,8255406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952062, endtime: 40952451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,8255464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952066, endtime: 40952451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,8255528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952067, endtime: 40952451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,8255841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952069, endtime: 40952451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,8256282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952070, endtime: 40952451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,8256343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952072, endtime: 40952451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,8256409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952073, endtime: 40952451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:31,8256467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952075, endtime: 40952451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:32,1064666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952191, endtime: 40952479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:32,1064854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952192, endtime: 40952479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:32,1064937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952194, endtime: 40952479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:32,1065018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952195, endtime: 40952479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:32,1065081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952197, endtime: 40952479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:32,1065153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952198, endtime: 40952479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:32,1065214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952200, endtime: 40952479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:32,1065286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952203, endtime: 40952479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:32,1065342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952205, endtime: 40952479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:32,1065926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952206, endtime: 40952479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:32,1066004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952208, endtime: 40952479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:32,1066076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952209, endtime: 40952479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:32,1066134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952210, endtime: 40952479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,0309117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951920, endtime: 40952572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,0309361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951922, endtime: 40952572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,0309480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951923, endtime: 40952572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,0309569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951925, endtime: 40952572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,0309660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951927, endtime: 40952572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,0309735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951928, endtime: 40952572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,0309821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951930, endtime: 40952572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,0309896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951931, endtime: 40952572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,0309979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951933, endtime: 40952572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,0310054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951934, endtime: 40952572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,0310361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951937, endtime: 40952572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,0310442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951939, endtime: 40952572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,0310528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40951941, endtime: 40952572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,1108887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952572, endtime: 40952580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,8416584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952451, endtime: 40952653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,8416742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952453, endtime: 40952653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,8416814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952456, endtime: 40952653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,8416891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952459, endtime: 40952653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,8416949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952461, endtime: 40952653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,8417019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952463, endtime: 40952653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,8417077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952464, endtime: 40952653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,8417146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952466, endtime: 40952653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,8417201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952467, endtime: 40952653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,8417514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952470, endtime: 40952653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,8417567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952472, endtime: 40952653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,8417631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952473, endtime: 40952653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:33,8417792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952476, endtime: 40952653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4155234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952075, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4155464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952259, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4155583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952261, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4155672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952262, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4155777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952264, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4155872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952266, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4155944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952269, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4155999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952270, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4156068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952274, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4156124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952275, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4156462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952276, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4156517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952278, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4156586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952280, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,4158595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952710, endtime: 40952710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7411530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952128, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7411682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952440, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7411765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952442, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7411826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952444, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7411890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952445, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7411942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952447, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7412009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952448, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7412061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952450, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7412125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952452, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7412178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952453, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7413657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952456, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7413771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952459, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7413854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952461, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:34,7414497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952743, endtime: 40952743, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:35,2859759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952573, endtime: 40952797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:35,2859906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952575, endtime: 40952797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:35,2859986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952578, endtime: 40952797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:35,2860044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952580, endtime: 40952797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:35,2860108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952581, endtime: 40952797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:35,2860164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952583, endtime: 40952797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:35,2860225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952586, endtime: 40952797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:35,2860277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952587, endtime: 40952797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:35,2860341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952589, endtime: 40952797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:35,2861003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952592, endtime: 40952797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:35,2861205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952595, endtime: 40952797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:35,2861264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952597, endtime: 40952797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:35,2861829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952599, endtime: 40952797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0412354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952230, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0412556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952438, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0412675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952439, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0412761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952441, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0412856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952442, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0413263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952444, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0413374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952445, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0413459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952447, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0413562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952448, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0413645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952450, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0414063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952452, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0415731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952453, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0415862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952456, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,0420167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952873, endtime: 40952873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,2194672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54912 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,5604794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952653, endtime: 40952925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,5604952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952655, endtime: 40952925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,5605019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952656, endtime: 40952925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,5605091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952658, endtime: 40952925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,5605143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952659, endtime: 40952925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,5605207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952661, endtime: 40952925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,5605260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952662, endtime: 40952925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,5605321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952664, endtime: 40952925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,5605373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952667, endtime: 40952925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,5606016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952669, endtime: 40952925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,5606080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952670, endtime: 40952925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,5607554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952672, endtime: 40952925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,5607620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952674, endtime: 40952925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,8270337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952479, endtime: 40952951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,8270517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952481, endtime: 40952951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,8270589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952483, endtime: 40952951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,8270658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952484, endtime: 40952951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,8270714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952486, endtime: 40952951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,8270777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952488, endtime: 40952951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,8270830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952489, endtime: 40952951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,8270894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952492, endtime: 40952951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,8270946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952494, endtime: 40952951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,8271251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952495, endtime: 40952951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,8271309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952499, endtime: 40952951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,8271373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952500, endtime: 40952951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:36,8272581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952501, endtime: 40952951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:37,9226493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:38,8533598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:38,9951912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:38,9952034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 6, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:38,9965529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 9, startime: 40953168, endtime: 40953168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:38,9967438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 103, startime: 40953168, endtime: 40953168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0900120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952797, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0900308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952798, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0900388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952800, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0900466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952801, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0900527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952803, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0900599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952806, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0900654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952808, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0900724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952809, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0900779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952813, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0901488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952814, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0901560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952816, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0901629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952817, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0901774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952745, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0901846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952748, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0901904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952750, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0901976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952753, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0902034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952755, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0903031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952756, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0903103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952758, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0903173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952759, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0903231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952761, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0903300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952762, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0903358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952764, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0903425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952767, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0903572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952819, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,0912285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952769, endtime: 40953178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,9163020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952951, endtime: 40953260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,9163197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952955, endtime: 40953260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,9163266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952959, endtime: 40953260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,9163338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952962, endtime: 40953260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,9163394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952966, endtime: 40953260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,9163463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952967, endtime: 40953260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,9163516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952969, endtime: 40953260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,9163582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952970, endtime: 40953260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,9163635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952973, endtime: 40953260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,9164114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952975, endtime: 40953260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,9164186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952977, endtime: 40953260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,9165491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952978, endtime: 40953260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:39,9165607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952981, endtime: 40953260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,0899915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952925, endtime: 40953278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,0900070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952928, endtime: 40953278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,0900139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952930, endtime: 40953278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,0900208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952931, endtime: 40953278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,0900264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952934, endtime: 40953278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,0900327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952936, endtime: 40953278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,0900380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952937, endtime: 40953278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,0900444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952939, endtime: 40953278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,0900494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952941, endtime: 40953278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,0901350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952944, endtime: 40953278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,0901452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952945, endtime: 40953278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,0901563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952947, endtime: 40953278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,0902660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952949, endtime: 40953278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,3451357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952711, endtime: 40953303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,3451470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952713, endtime: 40953303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,3451515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952716, endtime: 40953303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,3451554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952717, endtime: 40953303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,3451587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952720, endtime: 40953303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,3451617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952723, endtime: 40953303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,3451648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952725, endtime: 40953303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,3451678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952727, endtime: 40953303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,3451709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952728, endtime: 40953303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,3451739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952730, endtime: 40953303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,3451770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952731, endtime: 40953303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,3451800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952733, endtime: 40953303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:40,6569448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Retransmit</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,1680168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952873, endtime: 40953385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,1680323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952876, endtime: 40953385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,1680404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952878, endtime: 40953385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,1680462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952880, endtime: 40953385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,1680528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952883, endtime: 40953385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,1680584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952884, endtime: 40953385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,1680647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952886, endtime: 40953385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,1680700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952887, endtime: 40953385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,1680764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952889, endtime: 40953385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,1681357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952891, endtime: 40953385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,1681434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952892, endtime: 40953385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,1681490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952894, endtime: 40953385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,1819214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54903 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,2668178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Retransmit</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,3050504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,3053945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953399, endtime: 40953399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,3128911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953400, endtime: 40953400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,3198485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953401, endtime: 40953401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,3251530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953401, endtime: 40953401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,3531504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953404, endtime: 40953404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,3759978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953406, endtime: 40953406, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,3915354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953408, endtime: 40953408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,4080305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953409, endtime: 40953409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,4414221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953413, endtime: 40953413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,4582884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953414, endtime: 40953414, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,4886175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953417, endtime: 40953417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,5167076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953420, endtime: 40953420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,5320363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953422, endtime: 40953422, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,5487184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953423, endtime: 40953423, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,5898033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953426, endtime: 40953428, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,6100586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953430, endtime: 40953430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,6294126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953431, endtime: 40953432, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,6440196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953433, endtime: 40953433, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,6582844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953434, endtime: 40953434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,6901431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953437, endtime: 40953438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,7047165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953439, endtime: 40953439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,7204668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953441, endtime: 40953441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,7553244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953444, endtime: 40953444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,7660974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953445, endtime: 40953445, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,7824770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953447, endtime: 40953447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:41,8005261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953448, endtime: 40953449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,0136453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953450, endtime: 40953470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,0136608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953453, endtime: 40953470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,0136683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953455, endtime: 40953470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,0136755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953456, endtime: 40953470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,0136811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953461, endtime: 40953470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,0136877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953462, endtime: 40953470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,0136930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953464, endtime: 40953470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,0136996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953466, endtime: 40953470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,0137049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953469, endtime: 40953470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,0399449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953472, endtime: 40953473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,0565799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953474, endtime: 40953474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,1016838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953479, endtime: 40953479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4574340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953178, endtime: 40953514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4574517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953180, endtime: 40953514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4574600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953181, endtime: 40953514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4574683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953183, endtime: 40953514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4574747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953184, endtime: 40953514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4574825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953186, endtime: 40953514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4574888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953190, endtime: 40953514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4574963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953191, endtime: 40953514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4575027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953192, endtime: 40953514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4575711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953194, endtime: 40953514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4575792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953195, endtime: 40953514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4575866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953199, endtime: 40953514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4576537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953201, endtime: 40953514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,4748326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Retransmit</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,6461441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54904 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,9926894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953260, endtime: 40953568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,9927082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953262, endtime: 40953568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,9927154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953264, endtime: 40953568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,9927229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953268, endtime: 40953568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,9927287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953271, endtime: 40953568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,9927351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953274, endtime: 40953568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,9927406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953275, endtime: 40953568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,9927470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953277, endtime: 40953568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,9927523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953278, endtime: 40953568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,9927813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953280, endtime: 40953568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,9927872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953281, endtime: 40953568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,9927935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953284, endtime: 40953568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:42,9927991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953286, endtime: 40953568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:43,0770978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953568, endtime: 40953576, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8162116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953514, endtime: 40953750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8162279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953516, endtime: 40953750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8162354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953519, endtime: 40953750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8162429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953520, endtime: 40953750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8162484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953523, endtime: 40953750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8162551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953525, endtime: 40953750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8162606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953526, endtime: 40953750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8162673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953529, endtime: 40953750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8162725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953533, endtime: 40953750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8163523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953534, endtime: 40953750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8163595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953537, endtime: 40953750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8163928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953539, endtime: 40953750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8165853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953541, endtime: 40953750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:44,8754877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Retransmit</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,1249360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953570, endtime: 40953781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,1249507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953572, endtime: 40953781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,1249592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953573, endtime: 40953781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,1249656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953577, endtime: 40953781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,1249725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953578, endtime: 40953781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,1249784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953580, endtime: 40953781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,1249853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953581, endtime: 40953781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,1249908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953583, endtime: 40953781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,1249978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953584, endtime: 40953781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,1250521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953586, endtime: 40953781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,1250604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953587, endtime: 40953781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,1250665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953589, endtime: 40953781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2938097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40952895, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2938260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953385, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2938341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953387, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2938399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953389, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2938468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953391, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2938521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953392, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2938584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953394, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2938634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953395, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2938698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953399, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2938751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953400, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2939047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953401, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2939102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953404, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2939166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953406, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,2941003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953798, endtime: 40953798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6500583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953480, endtime: 40953834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6500760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953481, endtime: 40953834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6500830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953484, endtime: 40953834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6500899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953486, endtime: 40953834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6500954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953489, endtime: 40953834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6501021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953491, endtime: 40953834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6501073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953494, endtime: 40953834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6501134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953497, endtime: 40953834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6501187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953499, endtime: 40953834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6501470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953500, endtime: 40953834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6501528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953501, endtime: 40953834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6501592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953503, endtime: 40953834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6502772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953505, endtime: 40953834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:45,6562818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54927 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:46,9529648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953834, endtime: 40953964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:46,9529809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953834, endtime: 40953964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:46,9529881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953836, endtime: 40953964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:46,9529950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953839, endtime: 40953964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:46,9530005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953841, endtime: 40953964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:46,9530069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953842, endtime: 40953964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:46,9530122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953845, endtime: 40953964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:46,9530185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953847, endtime: 40953964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:46,9530238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953848, endtime: 40953964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:46,9530521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953850, endtime: 40953964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:46,9530579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953853, endtime: 40953964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:46,9530640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953855, endtime: 40953964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:46,9530692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953856, endtime: 40953964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0976695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953591, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0976834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953781, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0976914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953783, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0976972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953786, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0977036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953789, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0977088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953791, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0977149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953792, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0977202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953795, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0977263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953797, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0977316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953800, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0977595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953801, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0977648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953803, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0978870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953806, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:48,0979651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954078, endtime: 40954078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,0095540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953800, endtime: 40954170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,0095743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953801, endtime: 40954170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,0095845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953803, endtime: 40954170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,0095939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953806, endtime: 40954170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,0096017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953808, endtime: 40954170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,0096106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953809, endtime: 40954170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,0096178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953812, endtime: 40954170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,0096261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953814, endtime: 40954170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,0096336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953816, endtime: 40954170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,0096898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953819, endtime: 40954170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,0096992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953820, endtime: 40954170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,0097075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953822, endtime: 40954170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,1698988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953750, endtime: 40954186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,1699144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953751, endtime: 40954186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,1699216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953753, endtime: 40954186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,1699288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953755, endtime: 40954186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,1699343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953756, endtime: 40954186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,1699412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953758, endtime: 40954186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,1699468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953761, endtime: 40954186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,1699537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953762, endtime: 40954186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,1699592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953764, endtime: 40954186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,1699870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953766, endtime: 40954186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,1699928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953767, endtime: 40954186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,1699994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953769, endtime: 40954186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,1700050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953770, endtime: 40954186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:49,6882721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Retransmit</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,1037664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,1037805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,1041673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40954279, endtime: 40954279, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,4330711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54876 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,5213749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,5217149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954321, endtime: 40954321, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,5327616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954322, endtime: 40954322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,5640003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954325, endtime: 40954325, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,5798313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954327, endtime: 40954327, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,5951610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954328, endtime: 40954328, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6123017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953964, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6123175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953967, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6123255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953969, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6123330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953970, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6123388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953974, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6123457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953977, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6123513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953978, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6123579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953980, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6123634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953981, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6123909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953983, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6123970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953984, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6124039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953987, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6124094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953989, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6137019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954330, endtime: 40954330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6438620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954333, endtime: 40954333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6733784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954336, endtime: 40954336, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6829557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6833059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954337, endtime: 40954337, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,6994028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954338, endtime: 40954339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,7046544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954339, endtime: 40954339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,7203114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954341, endtime: 40954341, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,7204605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954341, endtime: 40954341, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,7357891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954342, endtime: 40954342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,7367685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954342, endtime: 40954342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,7510627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954344, endtime: 40954344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,7512154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954344, endtime: 40954344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,7673311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954345, endtime: 40954345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,7674982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954345, endtime: 40954345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,7828330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954347, endtime: 40954347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,7841712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954347, endtime: 40954347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,7980345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954348, endtime: 40954348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,8003510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954348, endtime: 40954349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,8138128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954350, endtime: 40954350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,8142592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954350, endtime: 40954350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,8294784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954352, endtime: 40954352, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,8294989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954352, endtime: 40954352, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,8450221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954353, endtime: 40954353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,8468399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954353, endtime: 40954353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,8630280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954355, endtime: 40954355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,8633266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954355, endtime: 40954355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,8762086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954356, endtime: 40954356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,8763228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954356, endtime: 40954356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,9091556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954359, endtime: 40954360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,9092855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954359, endtime: 40954360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,9234195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954361, endtime: 40954361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,9235232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954361, endtime: 40954361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,9388233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954362, endtime: 40954362, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,9389579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954362, endtime: 40954363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,9547233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954364, endtime: 40954364, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,9548518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954364, endtime: 40954364, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,9714054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954366, endtime: 40954366, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,9715334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954366, endtime: 40954366, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,9853105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954367, endtime: 40954367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:50,9854668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954367, endtime: 40954367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,0013438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954369, endtime: 40954369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,0014585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954369, endtime: 40954369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,0219135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954370, endtime: 40954371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,0331936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954372, endtime: 40954372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,0639166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954375, endtime: 40954375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,0790971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954376, endtime: 40954377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,0948693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954378, endtime: 40954378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,2328368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954186, endtime: 40954392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,2328532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954187, endtime: 40954392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,2328598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954189, endtime: 40954392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,2328670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954191, endtime: 40954392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,2328726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954192, endtime: 40954392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,2328792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954194, endtime: 40954392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,2328845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954195, endtime: 40954392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,2328909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954199, endtime: 40954392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,2328961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954200, endtime: 40954392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,2329260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954201, endtime: 40954392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,2329316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954202, endtime: 40954392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,2329380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954205, endtime: 40954392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,2329435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954207, endtime: 40954392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,6265133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954370, endtime: 40954431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,6265363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954372, endtime: 40954431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,6265457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954375, endtime: 40954431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,6265543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954376, endtime: 40954431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,6265615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954378, endtime: 40954431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,6265692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954380, endtime: 40954431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,6265759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954381, endtime: 40954431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,6265834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954383, endtime: 40954431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,6265900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954384, endtime: 40954431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,6266474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954386, endtime: 40954431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,6266559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954387, endtime: 40954431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,6266634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954389, endtime: 40954431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,6725331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54927 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,7804007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954380, endtime: 40954447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,7804184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954381, endtime: 40954447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,7804262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954383, endtime: 40954447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,7804334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954384, endtime: 40954447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,7804392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954386, endtime: 40954447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,7804459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954387, endtime: 40954447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,7804514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954389, endtime: 40954447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,7804578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954391, endtime: 40954447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,7804633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954392, endtime: 40954447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,7804913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954394, endtime: 40954447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,7804971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954395, endtime: 40954447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,7805038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954397, endtime: 40954447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:51,7805090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954399, endtime: 40954447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:52,5945468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40953823, endtime: 40954528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:52,5945634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954170, endtime: 40954528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:52,5945706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954172, endtime: 40954528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:52,5945784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954175, endtime: 40954528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:52,5945839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954178, endtime: 40954528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:52,5945909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954180, endtime: 40954528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:52,5945964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954182, endtime: 40954528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:52,5946028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954183, endtime: 40954528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:52,5946080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954186, endtime: 40954528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:52,5946629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954187, endtime: 40954528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:52,5946726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954189, endtime: 40954528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:52,5946795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954191, endtime: 40954528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:52,5946853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954192, endtime: 40954528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,5643122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954330, endtime: 40954625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,5643294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954333, endtime: 40954625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,5643366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954336, endtime: 40954625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,5643438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954338, endtime: 40954625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,5643494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954341, endtime: 40954625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,5643560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954342, endtime: 40954625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,5643613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954344, endtime: 40954625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,5643676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954345, endtime: 40954625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,5643732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954347, endtime: 40954625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,5644017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954348, endtime: 40954625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,5644075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954350, endtime: 40954625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,5644142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954352, endtime: 40954625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,5644195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954353, endtime: 40954625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,8210351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954391, endtime: 40954651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,8210520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954431, endtime: 40954651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,8210592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954433, endtime: 40954651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,8210664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954436, endtime: 40954651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,8210717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954437, endtime: 40954651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,8210784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954441, endtime: 40954651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,8210836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954442, endtime: 40954651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,8210900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954444, endtime: 40954651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,8210953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954445, endtime: 40954651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,8211221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954446, endtime: 40954651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,8212391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954448, endtime: 40954651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,8212518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954450, endtime: 40954651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:53,8212590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954453, endtime: 40954651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,2209315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54905 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,8612883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954392, endtime: 40954755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,8613014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954394, endtime: 40954755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,8613097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954395, endtime: 40954755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,8613180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954397, endtime: 40954755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,8613246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954398, endtime: 40954755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,8613321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954399, endtime: 40954755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,8613382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954400, endtime: 40954755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,8613454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954401, endtime: 40954755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,8613518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954403, endtime: 40954755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,8614185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954405, endtime: 40954755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,8614263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954406, endtime: 40954755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,8614335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954408, endtime: 40954755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:54,8615463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954409, endtime: 40954755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,7657807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,8656495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,8660060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954855, endtime: 40954855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,8719949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954856, endtime: 40954856, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,8772548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954856, endtime: 40954856, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,8827702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954857, endtime: 40954857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,8895126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954858, endtime: 40954858, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,8953579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954858, endtime: 40954858, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9012044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954859, endtime: 40954859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9070403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954859, endtime: 40954859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9129025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954860, endtime: 40954860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9188415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954860, endtime: 40954860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9251129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954861, endtime: 40954861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9310469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954862, endtime: 40954862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9363894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954862, endtime: 40954862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9422109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954863, endtime: 40954863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9661934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954865, endtime: 40954865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9714913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954866, endtime: 40954866, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9773859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954866, endtime: 40954866, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9828821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954867, endtime: 40954867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9882628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954867, endtime: 40954867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9942381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954868, endtime: 40954868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:55,9999056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954869, endtime: 40954869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,0084126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954869, endtime: 40954869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,0282337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954871, endtime: 40954871, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,0340561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954872, endtime: 40954872, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,0399211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954873, endtime: 40954873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,0474038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954873, endtime: 40954873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,0630901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954875, endtime: 40954875, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,0788230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954876, endtime: 40954876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,0942393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954878, endtime: 40954878, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1120241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954880, endtime: 40954880, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1423949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954883, endtime: 40954883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1615467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954884, endtime: 40954885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1817291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954886, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1875584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954651, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1875747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954653, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1875817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954656, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1875886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954658, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1875939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954659, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1876002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954663, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1876058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954664, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1876119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954666, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1876171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954667, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1876473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954669, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1876526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954671, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1876590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954673, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,1876640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954675, endtime: 40954887, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,2040286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954889, endtime: 40954889, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,7713756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954891, endtime: 40954946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,7713908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954894, endtime: 40954946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,7713978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954897, endtime: 40954946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:56,7714053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954898, endtime: 40954946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,2350641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,2965495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,2968703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954998, endtime: 40954998, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,3142858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955000, endtime: 40955000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,3199133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955001, endtime: 40955001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,3495714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955003, endtime: 40955004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,3654533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955005, endtime: 40955005, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,3873956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955006, endtime: 40955007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4073328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955009, endtime: 40955009, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4269988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955011, endtime: 40955011, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4554090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955014, endtime: 40955014, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4824413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954900, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4824593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954903, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4824668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954905, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4824751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954906, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4824815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954909, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4824890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954910, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4824945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954911, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4825017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954912, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4825076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954914, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4825427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954946, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4825483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954947, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4825549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954948, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4825602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954952, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,4864063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955017, endtime: 40955017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,5179355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955020, endtime: 40955020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,5333329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955022, endtime: 40955022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,5641715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955025, endtime: 40955025, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,5808935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955027, endtime: 40955027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,5946690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955028, endtime: 40955028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,6105440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955030, endtime: 40955030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,6270657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955031, endtime: 40955031, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,6589770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955034, endtime: 40955035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,6947990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955037, endtime: 40955038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,7339603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955041, endtime: 40955042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,7558713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955044, endtime: 40955044, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,7669832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955045, endtime: 40955045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,7976671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955047, endtime: 40955048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,8144825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955050, endtime: 40955050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,8465969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955053, endtime: 40955053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,8639445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955055, endtime: 40955055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,9706279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955056, endtime: 40955066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,9706440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955058, endtime: 40955066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,9706515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955061, endtime: 40955066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,9706593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955063, endtime: 40955066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,9706651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955065, endtime: 40955066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:57,9711175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955066, endtime: 40955066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,0018533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955069, endtime: 40955069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,0162785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955070, endtime: 40955070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,0507212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955074, endtime: 40955074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,0812600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955076, endtime: 40955077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1034229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955078, endtime: 40955079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1123078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955080, endtime: 40955080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1986390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954625, endtime: 40955088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1986534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954627, endtime: 40955088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1986603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954630, endtime: 40955088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1986675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954631, endtime: 40955088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1986728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954633, endtime: 40955088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1986794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954636, endtime: 40955088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1986847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954637, endtime: 40955088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1986911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954639, endtime: 40955088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1986961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954642, endtime: 40955088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1987238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954644, endtime: 40955088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1987293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954645, endtime: 40955088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1987357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954648, endtime: 40955088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:58,1987409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954650, endtime: 40955088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,1822672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954887, endtime: 40955187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,1822838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954889, endtime: 40955187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,1822910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954891, endtime: 40955187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,1822982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954894, endtime: 40955187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,1823038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954897, endtime: 40955187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,1823104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954898, endtime: 40955187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,1823162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954900, endtime: 40955187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,1823226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954903, endtime: 40955187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,1823279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954905, endtime: 40955187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,1823578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954906, endtime: 40955187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,1823633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954909, endtime: 40955187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,1823700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954910, endtime: 40955187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,1823752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954911, endtime: 40955187, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:54:59,2985911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54900 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,1275489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,1275597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,1279204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40955281, endtime: 40955281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,4881240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955088, endtime: 40955317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,4881578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955091, endtime: 40955317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,4881703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955093, endtime: 40955317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,4881808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955095, endtime: 40955317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,4881869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955097, endtime: 40955317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,4881939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955098, endtime: 40955317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,4881994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955100, endtime: 40955317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,4882063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955101, endtime: 40955317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,4882119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955101, endtime: 40955317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,4882446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955103, endtime: 40955317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,4882504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955106, endtime: 40955317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,4882567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955108, endtime: 40955317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,4882623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955111, endtime: 40955317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,6159862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954447, endtime: 40955330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,6160164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954448, endtime: 40955330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,6160259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954450, endtime: 40955330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,6160322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954453, endtime: 40955330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,6160394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954456, endtime: 40955330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,6160452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954458, endtime: 40955330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,6160522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954459, endtime: 40955330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,6160577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954462, endtime: 40955330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,6160649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954464, endtime: 40955330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,6160940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954466, endtime: 40955330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,6161009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954469, endtime: 40955330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,6161062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954471, endtime: 40955330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:00,6161128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954472, endtime: 40955330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:01,7939108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954755, endtime: 40955448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:01,7939319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954756, endtime: 40955448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:01,7939449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954758, endtime: 40955448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:01,7939546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954761, endtime: 40955448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:01,7939654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954762, endtime: 40955448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:01,7939745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954764, endtime: 40955448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:01,7939850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954766, endtime: 40955448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:01,7939939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954769, endtime: 40955448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:01,7940044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954773, endtime: 40955448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:01,7941067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954774, endtime: 40955448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:01,7941155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954777, endtime: 40955448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:01,7941211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954778, endtime: 40955448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,0803685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955187, endtime: 40955477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,0803867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955187, endtime: 40955477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,0803940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955189, endtime: 40955477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,0804014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955191, endtime: 40955477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,0804073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955192, endtime: 40955477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,0804139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955194, endtime: 40955477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,0804194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955195, endtime: 40955477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,0804261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955197, endtime: 40955477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,0804319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955198, endtime: 40955477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,0804599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955202, endtime: 40955477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,0804657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955205, endtime: 40955477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,0804721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955206, endtime: 40955477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,0804776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955209, endtime: 40955477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,2523654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955317, endtime: 40955494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,2523859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955319, endtime: 40955494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,2523942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955320, endtime: 40955494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,2524020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955322, endtime: 40955494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,2524081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955323, endtime: 40955494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,2524150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955325, endtime: 40955494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,2524208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955327, endtime: 40955494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,2524277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955328, endtime: 40955494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,2524336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955330, endtime: 40955494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,2524635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955331, endtime: 40955494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,2524699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955333, endtime: 40955494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,2524768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955334, endtime: 40955494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,2524829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955336, endtime: 40955494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,5866078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955017, endtime: 40955527, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,5866238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955020, endtime: 40955527, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,5866308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955022, endtime: 40955527, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,5866380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955025, endtime: 40955527, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,5866435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955027, endtime: 40955527, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,5866499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955028, endtime: 40955527, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,5866551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955030, endtime: 40955527, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,5866615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955031, endtime: 40955527, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,5866671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955034, endtime: 40955527, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,5866950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955037, endtime: 40955527, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,5867006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955041, endtime: 40955527, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,5868122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955044, endtime: 40955527, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:02,5868233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955045, endtime: 40955527, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:04,1311545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955330, endtime: 40955682, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:04,1311761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955331, endtime: 40955682, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:04,1311869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955333, endtime: 40955682, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:04,1311986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955334, endtime: 40955682, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:04,1312077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955336, endtime: 40955682, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:04,1312188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955337, endtime: 40955682, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:04,1312279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955339, endtime: 40955682, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:04,1312384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955341, endtime: 40955682, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:04,1312476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955342, endtime: 40955682, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:04,1312875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955344, endtime: 40955682, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:04,1312972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955345, endtime: 40955682, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:04,1313077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955347, endtime: 40955682, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:04,1313174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955348, endtime: 40955682, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:05,9589148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955527, endtime: 40955865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:05,9589304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955528, endtime: 40955865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:05,9589373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955530, endtime: 40955865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:05,9589445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955531, endtime: 40955865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:05,9589498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955533, endtime: 40955865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:05,9589561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955534, endtime: 40955865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:05,9589614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955538, endtime: 40955865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:05,9589675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955541, endtime: 40955865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:05,9589728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955544, endtime: 40955865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:05,9590035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955545, endtime: 40955865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:05,9590090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955547, endtime: 40955865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:05,9590151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955548, endtime: 40955865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:05,9590204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955550, endtime: 40955865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,1236696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955494, endtime: 40955881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,1236862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955497, endtime: 40955881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,1236934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955498, endtime: 40955881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,1237003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955503, endtime: 40955881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,1237056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955503, endtime: 40955881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,1237122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955504, endtime: 40955881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,1237175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955505, endtime: 40955881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,1237239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955505, endtime: 40955881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,1237288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955508, endtime: 40955881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,1237737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955509, endtime: 40955881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,1237848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955511, endtime: 40955881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,1237948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955512, endtime: 40955881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,1238012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955514, endtime: 40955881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,2350502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955477, endtime: 40955892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,2350710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955478, endtime: 40955892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,2350782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955480, endtime: 40955892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,2350854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955483, endtime: 40955892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,2350910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955484, endtime: 40955892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,2350976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955486, endtime: 40955892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,2351029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955489, endtime: 40955892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,2351095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955491, endtime: 40955892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,2351148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955494, endtime: 40955892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,2351458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955497, endtime: 40955892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,2351514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955498, endtime: 40955892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,2351577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955503, endtime: 40955892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,2351630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955503, endtime: 40955892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,8645479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955682, endtime: 40955955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,8645642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955683, endtime: 40955955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,8645856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955685, endtime: 40955955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,8667965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955687, endtime: 40955955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,8668081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955690, endtime: 40955955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,8668164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955691, endtime: 40955955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,8668223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955692, endtime: 40955955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,8669120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955694, endtime: 40955955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,8669184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955695, endtime: 40955955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,8669248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955697, endtime: 40955955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,8669300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955700, endtime: 40955955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,8669361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955701, endtime: 40955955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:06,8669414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955701, endtime: 40955955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,4109609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,4113033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956110, endtime: 40956110, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,4226490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956111, endtime: 40956111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,4391220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956112, endtime: 40956113, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,4707936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956116, endtime: 40956116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5011102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956119, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5049026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955865, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5049145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955866, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5049214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955867, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5049283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955869, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5049339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955872, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5049402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955873, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5049455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955877, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5049519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955878, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5049571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955880, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5049840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955881, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5049898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955883, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5049959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955884, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5050012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955886, endtime: 40956119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5177843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956120, endtime: 40956120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5627591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956124, endtime: 40956125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,5911764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956126, endtime: 40956128, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,6105066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956130, endtime: 40956130, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,6276223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956131, endtime: 40956131, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,6422711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956133, endtime: 40956133, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,6594893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956134, endtime: 40956135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,6746268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956136, endtime: 40956136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,7079184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956139, endtime: 40956139, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,7140691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956140, endtime: 40956140, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,7204785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956141, endtime: 40956141, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,7266554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956141, endtime: 40956141, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,7328565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956142, endtime: 40956142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,7384120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956142, endtime: 40956142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,7449708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956143, endtime: 40956143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,7506712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956144, endtime: 40956144, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,7566867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956144, endtime: 40956144, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,7624273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956145, endtime: 40956145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,7686380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956145, endtime: 40956145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,7741805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956146, endtime: 40956146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,8805038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956147, endtime: 40956157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,8805235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956147, endtime: 40956157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,8805315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956148, endtime: 40956157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,8805396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956148, endtime: 40956157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,8805454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956149, endtime: 40956157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,8805523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956150, endtime: 40956157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,8805579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956150, endtime: 40956157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,8805648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956151, endtime: 40956157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,8805706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956151, endtime: 40956157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,8805991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956152, endtime: 40956157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,8806052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956153, endtime: 40956157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,8806122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956153, endtime: 40956157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:08,8806180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956154, endtime: 40956157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,2072042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,2072105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,2133507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40956289, endtime: 40956290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4008298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955881, endtime: 40956309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4008467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955883, endtime: 40956309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4008533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955884, endtime: 40956309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4008600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955886, endtime: 40956309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4008655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955887, endtime: 40956309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4008722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955891, endtime: 40956309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4008774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955894, endtime: 40956309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4008838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955895, endtime: 40956309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4008888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955897, endtime: 40956309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4009212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955900, endtime: 40956309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4009267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955901, endtime: 40956309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4009331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955903, endtime: 40956309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4010481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955905, endtime: 40956309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4849908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40954781, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4850074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955448, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4850157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955450, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4850216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955452, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4850285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955453, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4850340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955456, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4850404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955458, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4850459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955459, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4850523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955461, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4874231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955462, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4874353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955464, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4874425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955466, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4874497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955467, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,4874569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956317, endtime: 40956317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6517799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956119, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6517966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956120, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6518035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956124, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6518107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956125, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6518162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956126, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6518229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956128, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6518281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956130, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6518345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956131, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6518398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956133, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6518725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956134, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6518777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956136, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6518841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956139, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6518894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956140, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6519013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955892, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6519079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955894, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6519132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955895, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6519201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955897, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6519257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955900, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6519838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955901, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6519902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955903, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6519966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955905, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6520019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955907, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6520082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955908, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6520135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955909, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6520199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955911, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:10,6520251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955912, endtime: 40956334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,3966121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955955, endtime: 40956408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,3966299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955956, endtime: 40956408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,3966376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955958, endtime: 40956408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,3966451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955961, endtime: 40956408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,3966509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955963, endtime: 40956408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,3966576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955967, endtime: 40956408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,3966634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955969, endtime: 40956408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,3966701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955972, endtime: 40956408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,3966756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955975, endtime: 40956408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,3967039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955976, endtime: 40956408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,3967097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955978, endtime: 40956408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,3967163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955980, endtime: 40956408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,3967221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955983, endtime: 40956408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,6136579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956334, endtime: 40956430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,6136750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956336, endtime: 40956430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,6136822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956337, endtime: 40956430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,6136894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956341, endtime: 40956430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,6137088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956342, endtime: 40956430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,6137210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956344, endtime: 40956430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,6137271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956345, endtime: 40956430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,6137343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956347, endtime: 40956430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,6137401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956348, endtime: 40956430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,6137720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956350, endtime: 40956430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,6137775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956352, endtime: 40956430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,6137842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956353, endtime: 40956430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:11,6137900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956355, endtime: 40956430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,1531234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956319, endtime: 40956584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,1531389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956320, endtime: 40956584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,1531467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956322, endtime: 40956584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,1531547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956323, endtime: 40956584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,1531608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956325, endtime: 40956584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,1531683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956327, endtime: 40956584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,1531741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956328, endtime: 40956584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,1531813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956330, endtime: 40956584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,1531874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956331, endtime: 40956584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,1532683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956333, endtime: 40956584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,1532771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956334, endtime: 40956584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,1532843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956336, endtime: 40956584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,1534758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956337, endtime: 40956584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,2192572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956408, endtime: 40956591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,2192769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956409, endtime: 40956591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,2192844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956411, endtime: 40956591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,2192921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956412, endtime: 40956591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,2192982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956414, endtime: 40956591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,2193051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956417, endtime: 40956591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,2193107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956420, endtime: 40956591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,2193173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956422, endtime: 40956591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,2193229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956423, endtime: 40956591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,2193525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956425, endtime: 40956591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,2193664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956429, endtime: 40956591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,2193830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956430, endtime: 40956591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,2193927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956431, endtime: 40956591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,5146317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955081, endtime: 40956620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,5146643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955083, endtime: 40956620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,5146757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955083, endtime: 40956620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,5146826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955084, endtime: 40956620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,5146901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955084, endtime: 40956620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,5146962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955087, endtime: 40956620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,5147037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955089, endtime: 40956620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,5147101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955091, endtime: 40956620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,5147175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955093, endtime: 40956620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,5147236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955095, endtime: 40956620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,5147544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955097, endtime: 40956620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,5147608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955098, endtime: 40956620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:13,5147677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40955100, endtime: 40956620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2462527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956430, endtime: 40956693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2462713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956431, endtime: 40956693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2462788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956433, endtime: 40956693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2462862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956434, endtime: 40956693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2462918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956436, endtime: 40956693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2462984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956437, endtime: 40956693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2463040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956439, endtime: 40956693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2463106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956441, endtime: 40956693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2463159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956442, endtime: 40956693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2463469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956445, endtime: 40956693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2463527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956447, endtime: 40956693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2463594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956450, endtime: 40956693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2463647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956452, endtime: 40956693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2717682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2717909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2718197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2718427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2718521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2718613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2718779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2718851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2718926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2719070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2719139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2719366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2719422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2719549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2719624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2719774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2719912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2719984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2720059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2720184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2720253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2720325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2720441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2720497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2720558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2720627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,2721566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54877 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3485141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956334, endtime: 40956703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3485310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956334, endtime: 40956703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3485379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956336, endtime: 40956703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3485449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956337, endtime: 40956703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3485504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956341, endtime: 40956703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3485573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956342, endtime: 40956703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3485626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956344, endtime: 40956703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3485692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956345, endtime: 40956703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3485745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956347, endtime: 40956703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3486025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956348, endtime: 40956703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3486083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956350, endtime: 40956703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3486150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956352, endtime: 40956703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3486205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956353, endtime: 40956703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3599366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3604101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956705, endtime: 40956705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3765627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956706, endtime: 40956706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,3922499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956708, endtime: 40956708, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,4231173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956711, endtime: 40956711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,4380863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956712, endtime: 40956712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,4851817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956717, endtime: 40956717, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,5086960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956719, endtime: 40956719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,5252983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956720, endtime: 40956721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,5879975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956727, endtime: 40956727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,6482350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956733, endtime: 40956733, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,6835657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956736, endtime: 40956737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,7244670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956741, endtime: 40956741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,7559946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956744, endtime: 40956744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,7873213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956747, endtime: 40956747, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,7992857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956749, endtime: 40956749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,8151175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956750, endtime: 40956750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,8312258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956751, endtime: 40956752, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,8477694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956753, endtime: 40956753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,8796422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956756, endtime: 40956757, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,8930786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956758, endtime: 40956758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,8995307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956759, endtime: 40956759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,9053078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956759, endtime: 40956759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,9111152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956760, endtime: 40956760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,9220514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956761, endtime: 40956761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,9277438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956761, endtime: 40956761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,9336750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956762, endtime: 40956762, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,9408572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956763, endtime: 40956763, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,9549748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956764, endtime: 40956764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,9628366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956765, endtime: 40956765, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:14,9832750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956767, endtime: 40956767, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,0180137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956768, endtime: 40956870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,0180331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956769, endtime: 40956870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,0180408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956769, endtime: 40956870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,0180483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956770, endtime: 40956870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,0180541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956770, endtime: 40956870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,0180611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956771, endtime: 40956870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,0180666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956771, endtime: 40956870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,0180732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956772, endtime: 40956870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2593661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956591, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2593830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956592, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2593904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956594, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2593976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956597, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2594287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956598, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2594373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956600, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2594434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956601, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2594506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956601, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2594564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956603, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2594924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956605, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2594985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956606, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2595051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956612, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2595110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956614, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2595226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956309, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2595281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956311, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2595348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956312, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2595401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956314, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2595473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956316, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2595528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956319, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2596068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956320, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2596129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956322, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2596196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956323, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2596251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956325, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2596315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956327, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2596370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956328, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:16,2596434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956330, endtime: 40956895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:17,5212852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956157, endtime: 40957021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:17,5213018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956157, endtime: 40957021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:17,5213104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956158, endtime: 40957021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:17,5213170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956158, endtime: 40957021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:17,5213239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956159, endtime: 40957021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:17,5213298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956160, endtime: 40957021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:17,5213367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956160, endtime: 40957021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:17,5213422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956161, endtime: 40957021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:17,5213492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956161, endtime: 40957021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:17,5213788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956162, endtime: 40957021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:17,5213863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956163, endtime: 40957021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:17,5213921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956166, endtime: 40957021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:17,5213987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956167, endtime: 40957021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,0879526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956693, endtime: 40957077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,0879714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956695, endtime: 40957077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,0879789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956698, endtime: 40957077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,0880000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956700, endtime: 40957077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,0880080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956700, endtime: 40957077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,0880155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956703, endtime: 40957077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,0880216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956705, endtime: 40957077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,0880288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956706, endtime: 40957077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,0880349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956708, endtime: 40957077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,0880692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956711, endtime: 40957077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,0880753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956712, endtime: 40957077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,0880823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956717, endtime: 40957077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,0880878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956719, endtime: 40957077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:18,5707305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54937 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,2396261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956895, endtime: 40957193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,2396433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956895, endtime: 40957193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,2396505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956897, endtime: 40957193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,2396577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956900, endtime: 40957193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,2396632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956900, endtime: 40957193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,2396699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956901, endtime: 40957193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,2396754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956905, endtime: 40957193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,2396821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956906, endtime: 40957193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,2396873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956908, endtime: 40957193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,2397178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956910, endtime: 40957193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,2397233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956911, endtime: 40957193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,2397300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956914, endtime: 40957193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,2397355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956916, endtime: 40957193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,7235366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956773, endtime: 40957241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,7235549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956774, endtime: 40957241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,7235629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956774, endtime: 40957241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,7235710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956776, endtime: 40957241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,7235771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956777, endtime: 40957241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,7235840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956870, endtime: 40957241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,7235898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956872, endtime: 40957241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,7235967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956873, endtime: 40957241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,7236026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956875, endtime: 40957241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,7236308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956876, endtime: 40957241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,7236372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956878, endtime: 40957241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,7236441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956880, endtime: 40957241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,7236499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956881, endtime: 40957241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,8318356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956703, endtime: 40957252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,8318517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956705, endtime: 40957252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,8318603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956706, endtime: 40957252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,8318664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956708, endtime: 40957252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,8318733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956711, endtime: 40957252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,8318791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956712, endtime: 40957252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,8318858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956717, endtime: 40957252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,8318913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956719, endtime: 40957252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,8318980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956720, endtime: 40957252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,8319237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956727, endtime: 40957252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,8319309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956733, endtime: 40957252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,8319365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956736, endtime: 40957252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:19,8319431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956738, endtime: 40957252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,3431384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,3431503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,3434986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40957303, endtime: 40957303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,4534937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956895, endtime: 40957314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,4535303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956895, endtime: 40957314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,4535433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956897, endtime: 40957314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,4535574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956900, endtime: 40957314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,4535663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956900, endtime: 40957314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,4535746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956901, endtime: 40957314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,4535810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956905, endtime: 40957314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,4535887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956906, endtime: 40957314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,4535954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956908, endtime: 40957314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,4536286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956910, endtime: 40957314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,4536350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956911, endtime: 40957314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,4536422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956914, endtime: 40957314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,4536483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40956916, endtime: 40957314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,7532678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957077, endtime: 40957344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,7532852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957078, endtime: 40957344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,7532924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957080, endtime: 40957344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,7532996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957081, endtime: 40957344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,7533055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957083, endtime: 40957344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,7533121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957084, endtime: 40957344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,7533177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957086, endtime: 40957344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,7533243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957087, endtime: 40957344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,7533296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957090, endtime: 40957344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,7533564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957092, endtime: 40957344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,7533620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957094, endtime: 40957344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,7533686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957095, endtime: 40957344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:20,7534587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957097, endtime: 40957344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:22,0554154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957193, endtime: 40957474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:22,0554478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957194, endtime: 40957474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:22,0554578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957195, endtime: 40957474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:22,0554675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957198, endtime: 40957474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:22,0554744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957198, endtime: 40957474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:22,0554825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957200, endtime: 40957474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:22,0554894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957201, endtime: 40957474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:22,0554977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957201, endtime: 40957474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:22,0555041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957203, endtime: 40957474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:22,0555384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957205, endtime: 40957474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:22,0555451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957206, endtime: 40957474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:22,0555520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957208, endtime: 40957474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:22,0555581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957209, endtime: 40957474, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,1553540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957252, endtime: 40957584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,1553706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957255, endtime: 40957584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,1553778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957258, endtime: 40957584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,1553850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957261, endtime: 40957584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,1553905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957262, endtime: 40957584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,1553972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957264, endtime: 40957584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,1554027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957266, endtime: 40957584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,1554091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957267, endtime: 40957584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,1554144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957269, endtime: 40957584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,1554448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957270, endtime: 40957584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,1554504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957272, endtime: 40957584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,1554567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957274, endtime: 40957584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,1554623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957277, endtime: 40957584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,8700300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957021, endtime: 40957656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,8700491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957023, endtime: 40957656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,8700591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957027, endtime: 40957656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,8700666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957034, endtime: 40957656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,8700721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957037, endtime: 40957656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,8700788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957039, endtime: 40957656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,8700843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957041, endtime: 40957656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,8700910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957042, endtime: 40957656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,8700965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957044, endtime: 40957656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,8701259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957045, endtime: 40957656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,8701314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957047, endtime: 40957656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,8701381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957048, endtime: 40957656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:23,8701433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957052, endtime: 40957656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,3280701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957314, endtime: 40957701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,3280868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957316, endtime: 40957701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,3280942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957319, endtime: 40957701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,3281017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957323, endtime: 40957701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,3281073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957325, endtime: 40957701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,3281139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957328, endtime: 40957701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,3281195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957330, endtime: 40957701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,3281261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957334, endtime: 40957701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,3281317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957336, endtime: 40957701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,3281610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957339, endtime: 40957701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,3281668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957341, endtime: 40957701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,3281732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957342, endtime: 40957701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,3281788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957344, endtime: 40957701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,5811509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957344, endtime: 40957727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,5811725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957345, endtime: 40957727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,5811808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957349, endtime: 40957727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,5811891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957352, endtime: 40957727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,5811955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957353, endtime: 40957727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,5812027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957355, endtime: 40957727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,5812088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957356, endtime: 40957727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,5812160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957358, endtime: 40957727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,5812221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957359, endtime: 40957727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,5812514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957361, endtime: 40957727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,5812578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957364, endtime: 40957727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,5812647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957366, endtime: 40957727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:24,5812708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957368, endtime: 40957727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:25,3094656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957241, endtime: 40957800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:25,3094827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957244, endtime: 40957800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:25,3094897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957245, endtime: 40957800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:25,3094969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957249, endtime: 40957800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:25,3095021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957252, endtime: 40957800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:25,3095088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957255, endtime: 40957800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:25,3095140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957258, endtime: 40957800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:25,3095207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957261, endtime: 40957800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:25,3095257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957262, endtime: 40957800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:25,3095562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957264, endtime: 40957800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:25,3095617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957266, endtime: 40957800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:25,3095681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957267, endtime: 40957800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:25,3095733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957269, endtime: 40957800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,1515868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957701, endtime: 40957884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,1516167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957703, endtime: 40957884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,1516251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957705, endtime: 40957884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,1516334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957708, endtime: 40957884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,1516392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957711, endtime: 40957884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,1516469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957714, endtime: 40957884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,1516528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957716, endtime: 40957884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,1516600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957717, endtime: 40957884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,1516658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957719, endtime: 40957884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,1516985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957722, endtime: 40957884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,1517043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957725, endtime: 40957884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,1517109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957728, endtime: 40957884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,1517165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957730, endtime: 40957884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,2357584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957474, endtime: 40957892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,2357781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957475, endtime: 40957892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,2357858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957477, endtime: 40957892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,2357939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957477, endtime: 40957892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,2358000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957478, endtime: 40957892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,2358072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957478, endtime: 40957892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,2358130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957479, endtime: 40957892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,2358199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957480, endtime: 40957892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,2358254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957480, endtime: 40957892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,2358540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957481, endtime: 40957892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,2358601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957481, endtime: 40957892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,2358670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957482, endtime: 40957892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,2358728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957483, endtime: 40957892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,4015853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957584, endtime: 40957909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,4016039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957586, endtime: 40957909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,4016119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957588, endtime: 40957909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,4016197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957588, endtime: 40957909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,4016258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957591, endtime: 40957909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,4016330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957594, endtime: 40957909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,4016385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957596, endtime: 40957909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,4016457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957597, endtime: 40957909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,4016512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957599, endtime: 40957909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,4016823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957602, endtime: 40957909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,4016884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957605, endtime: 40957909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,4016950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957606, endtime: 40957909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,4017008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957610, endtime: 40957909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,6934392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957656, endtime: 40957938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,6934602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957658, endtime: 40957938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,6934683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957659, endtime: 40957938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,6934763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957661, endtime: 40957938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,6934827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957665, endtime: 40957938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,6934896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957667, endtime: 40957938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,6934954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957669, endtime: 40957938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,6935026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957670, endtime: 40957938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,6935082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957672, endtime: 40957938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,6935384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957673, endtime: 40957938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,6935445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957675, endtime: 40957938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,6935514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957677, endtime: 40957938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:26,6935713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957678, endtime: 40957938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:27,9754665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957727, endtime: 40958066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:27,9754856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957728, endtime: 40958066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:27,9754933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957730, endtime: 40958066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:27,9755014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957731, endtime: 40958066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:27,9755075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957734, endtime: 40958066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:27,9755147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957734, endtime: 40958066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:27,9755205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957736, endtime: 40958066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:27,9755274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957737, endtime: 40958066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:27,9755332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957739, endtime: 40958066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:27,9755631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957741, endtime: 40958066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:27,9755695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957744, endtime: 40958066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:27,9755762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957745, endtime: 40958066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:27,9755823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957749, endtime: 40958066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:28,4069926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957884, endtime: 40958109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:28,4070081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957886, endtime: 40958109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:28,4070159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957887, endtime: 40958109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:28,4070231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957889, endtime: 40958109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:28,4070286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957891, endtime: 40958109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:28,4070353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957894, endtime: 40958109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:28,4070408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957895, endtime: 40958109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:28,4070475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957897, endtime: 40958109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:28,4070527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957898, endtime: 40958109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:28,4070838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957900, endtime: 40958109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:28,4070899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957901, endtime: 40958109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:28,4070962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957901, endtime: 40958109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:28,4071018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957903, endtime: 40958109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2851785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957909, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2851982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957911, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2852065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957912, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2852146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957914, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2852209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957916, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2852281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957917, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2852342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957919, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2852414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957922, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2852475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957923, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2852816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957926, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2852880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957930, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2852949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957931, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2853007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957934, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2853124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957892, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2853196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957894, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2853254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957895, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2853323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957897, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2853381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957898, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2853451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957900, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2854007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957901, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2854093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957901, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2854151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957903, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2854221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957905, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2854279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957908, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2854348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957909, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,2854409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957911, endtime: 40958197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:29,3560171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958197, endtime: 40958204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6156322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958200, endtime: 40958330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6156460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958201, endtime: 40958330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6156549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958203, endtime: 40958330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6156610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958206, endtime: 40958330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6156679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958208, endtime: 40958330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6156734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958211, endtime: 40958330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6156804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958212, endtime: 40958330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6156859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958214, endtime: 40958330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6156926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958217, endtime: 40958330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6157699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958219, endtime: 40958330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6157784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958222, endtime: 40958330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6157845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958223, endtime: 40958330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6165489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958227, endtime: 40958330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6248822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6248925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6252252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40958331, endtime: 40958331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6418411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958066, endtime: 40958333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6418599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958067, endtime: 40958333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6418674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958069, endtime: 40958333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6418752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958070, endtime: 40958333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6418810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958072, endtime: 40958333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6419032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958073, endtime: 40958333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6419134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958075, endtime: 40958333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6419253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958077, endtime: 40958333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6419331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958078, endtime: 40958333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6419644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958080, endtime: 40958333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6419705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958081, endtime: 40958333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6419774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958083, endtime: 40958333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:30,6419832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958086, endtime: 40958333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,5561668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957800, endtime: 40958424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,5561829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957802, endtime: 40958424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,5561917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957802, endtime: 40958424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,5561981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957803, endtime: 40958424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,5562050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957805, endtime: 40958424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,5562108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957806, endtime: 40958424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,5562175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957808, endtime: 40958424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,5562233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957809, endtime: 40958424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,5584378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957811, endtime: 40958424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,5584478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957812, endtime: 40958424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,5584561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957814, endtime: 40958424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,5584619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957817, endtime: 40958424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,5584686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957817, endtime: 40958424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8312230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957938, endtime: 40958452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8312397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957941, endtime: 40958452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8312480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957942, endtime: 40958452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8312541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957944, endtime: 40958452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8312610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957947, endtime: 40958452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8312665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957949, endtime: 40958452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8312732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957951, endtime: 40958452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8312785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957954, endtime: 40958452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8312851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957957, endtime: 40958452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8313292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957959, endtime: 40958452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8313372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957961, endtime: 40958452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8313427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957963, endtime: 40958452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8313494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40957965, endtime: 40958452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8650303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958109, endtime: 40958455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8650552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958110, endtime: 40958455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8650671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958110, endtime: 40958455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8650793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958111, endtime: 40958455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8650887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958112, endtime: 40958455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8650995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958113, endtime: 40958455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8651087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958113, endtime: 40958455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8651200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958116, endtime: 40958455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8651292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958121, endtime: 40958455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8652164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958122, endtime: 40958455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8652239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958126, endtime: 40958455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8652308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958128, endtime: 40958455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:31,8653439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958130, endtime: 40958455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:32,9386778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958330, endtime: 40958562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:32,9386950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958331, endtime: 40958562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:32,9387022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958333, endtime: 40958562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:32,9387097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958334, endtime: 40958562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:32,9387155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958336, endtime: 40958562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:32,9387222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958337, endtime: 40958562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:32,9387277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958339, endtime: 40958562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:32,9387344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958342, endtime: 40958562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:32,9387396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958344, endtime: 40958562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:32,9388064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958347, endtime: 40958562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:32,9388266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958350, endtime: 40958562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:32,9388391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958352, endtime: 40958562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4737595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958424, endtime: 40958616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4737761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958425, endtime: 40958616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4737831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958428, endtime: 40958616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4737903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958430, endtime: 40958616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4737958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958431, endtime: 40958616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4738025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958433, endtime: 40958616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4738077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958434, endtime: 40958616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4738141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958436, endtime: 40958616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4738196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958439, endtime: 40958616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4738476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958442, endtime: 40958616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4738532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958444, endtime: 40958616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4738595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958445, endtime: 40958616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4738651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958448, endtime: 40958616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,4894353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54925 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6342415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6346194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958632, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6378130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958452, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6378268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958455, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6378343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958456, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6378418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958459, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6378623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958461, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6378756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958464, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6378859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958466, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6378978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958469, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6379069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958472, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6379415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958475, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6379479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958478, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6379548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958480, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6379609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958481, endtime: 40958632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6412399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958633, endtime: 40958633, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6581223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958634, endtime: 40958634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,6893268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958638, endtime: 40958638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,7213462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958641, endtime: 40958641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,7368724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958642, endtime: 40958642, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,7552041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958644, endtime: 40958644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,7860216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958647, endtime: 40958647, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,8207046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958651, endtime: 40958651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,8404460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958651, endtime: 40958653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,8692157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958655, endtime: 40958656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,8774232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958656, endtime: 40958656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,9107628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958659, endtime: 40958660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,9243640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958661, endtime: 40958661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,9551062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958664, endtime: 40958664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:33,9867155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958667, endtime: 40958667, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,0028947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958669, endtime: 40958669, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,0346088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958672, endtime: 40958672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,0687163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958675, endtime: 40958675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,0947740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958678, endtime: 40958678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,1098001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958680, endtime: 40958680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,1259924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958681, endtime: 40958681, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,1413543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958683, endtime: 40958683, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,1594087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958684, endtime: 40958685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,1735117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958686, endtime: 40958686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,4561698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958687, endtime: 40958714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,4561889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958691, endtime: 40958714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,4561972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958692, endtime: 40958714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,4562052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958696, endtime: 40958714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,4562113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958698, endtime: 40958714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,4562188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958700, endtime: 40958714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,4562249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958701, endtime: 40958714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,4562318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958701, endtime: 40958714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,4562379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958703, endtime: 40958714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,4562659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958705, endtime: 40958714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,4562723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958706, endtime: 40958714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,4562795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958708, endtime: 40958714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:34,4562853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958709, endtime: 40958714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,6930627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958455, endtime: 40958838, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,6930818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958456, endtime: 40958838, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,6930898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958459, endtime: 40958838, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,6930979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958461, endtime: 40958838, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,6931040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958464, endtime: 40958838, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,6931112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958466, endtime: 40958838, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,6931170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958469, endtime: 40958838, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,6931239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958472, endtime: 40958838, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,6931294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958475, endtime: 40958838, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,6932234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958478, endtime: 40958838, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,6932311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958480, endtime: 40958838, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,6932383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958481, endtime: 40958838, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,6932854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958484, endtime: 40958838, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8180972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958333, endtime: 40958850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8181186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958334, endtime: 40958850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8181319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958336, endtime: 40958850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8181396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958337, endtime: 40958850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8181482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958339, endtime: 40958850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8181546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958342, endtime: 40958850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8181629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958344, endtime: 40958850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8181693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958347, endtime: 40958850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8181773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958350, endtime: 40958850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8182089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958352, endtime: 40958850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8182164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958355, endtime: 40958850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8182222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958356, endtime: 40958850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8182294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958359, endtime: 40958850, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8668101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958616, endtime: 40958855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8668303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958617, endtime: 40958855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8668386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958619, endtime: 40958855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8668464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958620, endtime: 40958855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8668527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958622, endtime: 40958855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8668599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958623, endtime: 40958855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8668657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958625, endtime: 40958855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8668727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958628, endtime: 40958855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8668921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958630, endtime: 40958855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8669267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958631, endtime: 40958855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8669331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958633, endtime: 40958855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8669400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958634, endtime: 40958855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:35,8669458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958638, endtime: 40958855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,7757029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958632, endtime: 40958946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,7757210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958634, endtime: 40958946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,7757295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958638, endtime: 40958946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,7757379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958641, endtime: 40958946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,7757445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958642, endtime: 40958946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,7757520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958644, endtime: 40958946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,7757578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958647, endtime: 40958946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,7757647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958651, endtime: 40958946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,7757703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958651, endtime: 40958946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,7758027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958655, endtime: 40958946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,7758088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958656, endtime: 40958946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,7758154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958659, endtime: 40958946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,7758218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958661, endtime: 40958946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,9106755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958355, endtime: 40958960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,9106966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958562, endtime: 40958960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,9107046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958564, endtime: 40958960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,9107126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958566, endtime: 40958960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,9107190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958567, endtime: 40958960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,9107259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958570, endtime: 40958960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,9107318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958572, endtime: 40958960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,9107390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958573, endtime: 40958960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,9107445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958575, endtime: 40958960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,9107717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958578, endtime: 40958960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,9107777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958580, endtime: 40958960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,9107847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958581, endtime: 40958960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:36,9107905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958584, endtime: 40958960, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,2445350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958838, endtime: 40959093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,2445591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958839, endtime: 40959093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,2445718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958841, endtime: 40959093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,2445848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958842, endtime: 40959093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,2445943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958844, endtime: 40959093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,2446020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958845, endtime: 40959093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,2446084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958848, endtime: 40959093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,2446156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958851, endtime: 40959093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,2446222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958853, endtime: 40959093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,2446563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958855, endtime: 40959093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,2446641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958858, endtime: 40959093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,2446713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958859, endtime: 40959093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,2446774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958861, endtime: 40959093, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,4541229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958850, endtime: 40959114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,4541378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958851, endtime: 40959114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,4541448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958853, endtime: 40959114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,4541517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958855, endtime: 40959114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,4541570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958858, endtime: 40959114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,4541636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958859, endtime: 40959114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,4541686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958861, endtime: 40959114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,4541750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958863, endtime: 40959114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,4541802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958864, endtime: 40959114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,4542079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958866, endtime: 40959114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,4542135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958867, endtime: 40959114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,4542196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958869, endtime: 40959114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:38,4542248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958870, endtime: 40959114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7665199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958855, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7665363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958858, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7665432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958859, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7665501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958861, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7665554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958863, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7665618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958864, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7665670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958866, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7665734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958867, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7665784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958869, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7666518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958870, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7666701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958872, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7667039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958873, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7667103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958875, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7667205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958960, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7667274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958961, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7667330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958964, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7667399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958966, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7667455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958969, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7667524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958970, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7668083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958972, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7668155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958975, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7668208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958977, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7668269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958980, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7668319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958981, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7668380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958983, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,7668433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958985, endtime: 40959245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:39,8502244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959245, endtime: 40959254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,2447874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54948 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,3300882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,3305542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959302, endtime: 40959302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,3456624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959303, endtime: 40959303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,3762020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959306, endtime: 40959306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,3929101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959308, endtime: 40959308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,4075129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959309, endtime: 40959309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,4227660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959311, endtime: 40959311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,4388197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959312, endtime: 40959312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,4544512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959314, endtime: 40959314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,4700772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959316, endtime: 40959316, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,4852554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959317, endtime: 40959317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,5022339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959319, endtime: 40959319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,5345500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959322, endtime: 40959322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,5476432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959323, endtime: 40959323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,5634827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959325, endtime: 40959325, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,5794528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959327, endtime: 40959327, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,6074856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959329, endtime: 40959329, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,6266169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959331, endtime: 40959331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,6595469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,6595586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,6629148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40959335, endtime: 40959335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,6630126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959335, endtime: 40959335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,6968739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959338, endtime: 40959338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,7205954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959341, endtime: 40959341, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,7388983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959342, endtime: 40959342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,7518958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959344, endtime: 40959344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,7826922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959347, endtime: 40959347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,8004765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959348, endtime: 40959349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,8306013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959351, endtime: 40959352, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:40,8445744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959353, endtime: 40959353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,0678536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959093, endtime: 40959375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,0678727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959094, endtime: 40959375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,0678813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959095, endtime: 40959375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,0678890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959097, endtime: 40959375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,0678954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959098, endtime: 40959375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,0679026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959100, endtime: 40959375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,0679087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959100, endtime: 40959375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,0679159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959103, endtime: 40959375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,0679217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959107, endtime: 40959375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,0679511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959108, endtime: 40959375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,0679575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959110, endtime: 40959375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,0679644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959111, endtime: 40959375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,0687022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959112, endtime: 40959375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,3010328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959114, endtime: 40959399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,3010491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959116, endtime: 40959399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,3010563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959117, endtime: 40959399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,3010638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959119, endtime: 40959399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,3010694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959122, endtime: 40959399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,3010760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959123, endtime: 40959399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,3010813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959125, endtime: 40959399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,3010879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959127, endtime: 40959399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,3010938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959130, endtime: 40959399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,3011215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959131, endtime: 40959399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,3011273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959133, endtime: 40959399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,3011336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959134, endtime: 40959399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,3011389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959136, endtime: 40959399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,4054599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959354, endtime: 40959409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,4054766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959356, endtime: 40959409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,4054843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959358, endtime: 40959409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,4054918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959359, endtime: 40959409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,4054979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959363, endtime: 40959409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,4055051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959366, endtime: 40959409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,4055109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959367, endtime: 40959409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,4055178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959369, endtime: 40959409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,4055237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959370, endtime: 40959409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,4055921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959372, endtime: 40959409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,4055998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959376, endtime: 40959409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,4056068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959376, endtime: 40959409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,6329950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54936 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,7253885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,7257608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959441, endtime: 40959441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,7510613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959444, endtime: 40959444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,7666105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959445, endtime: 40959445, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,7821863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959447, endtime: 40959447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,7978043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959448, endtime: 40959448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,8132227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959450, endtime: 40959450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,8419216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959452, endtime: 40959453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,8849780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959457, endtime: 40959457, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,8959453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959458, endtime: 40959458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,9193249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959459, endtime: 40959461, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,9391131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959462, endtime: 40959463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,9546903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959464, endtime: 40959464, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,9701004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959466, endtime: 40959466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:41,9858760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959467, endtime: 40959467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,0013853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959469, endtime: 40959469, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,0171454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959470, endtime: 40959470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,0324367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959472, endtime: 40959472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,0480964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959473, endtime: 40959473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,0726904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959475, endtime: 40959476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,0959712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959478, endtime: 40959478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,1121944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959480, endtime: 40959480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,1421680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959483, endtime: 40959483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,1588518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959484, endtime: 40959484, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,1758195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959486, endtime: 40959486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,1975632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959488, endtime: 40959488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,2048996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959489, endtime: 40959489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,2213504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959491, endtime: 40959491, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,2376834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959492, endtime: 40959492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,2669965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959495, endtime: 40959495, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,2821052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959497, endtime: 40959497, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,2989865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959498, endtime: 40959499, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,3046282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959499, endtime: 40959499, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,3103984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959500, endtime: 40959500, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,3242994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959501, endtime: 40959501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,3449972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959503, endtime: 40959503, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:42,3602206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959505, endtime: 40959505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,4147388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959245, endtime: 40959610, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,4147565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959247, endtime: 40959610, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,4147646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959248, endtime: 40959610, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,4147723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959252, endtime: 40959610, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,4147784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959255, endtime: 40959610, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,4147856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959258, endtime: 40959610, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,4147912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959261, endtime: 40959610, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,4147981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959264, endtime: 40959610, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,4148039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959266, endtime: 40959610, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,4148325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959267, endtime: 40959610, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,4148386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959269, endtime: 40959610, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,4148455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959270, endtime: 40959610, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,4148513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959272, endtime: 40959610, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,5171806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959375, endtime: 40959620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,5171977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959376, endtime: 40959620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,5172061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959378, endtime: 40959620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,5172146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959380, endtime: 40959620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,5172210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959381, endtime: 40959620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,5172282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959383, endtime: 40959620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,5172346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959384, endtime: 40959620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,5172418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959386, endtime: 40959620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,5172479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959388, endtime: 40959620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,5172759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959392, endtime: 40959620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,5172825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959394, endtime: 40959620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,5172897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959397, endtime: 40959620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:43,5172958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959399, endtime: 40959620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:44,7502833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:44,7507438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959744, endtime: 40959744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:44,7679953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959745, endtime: 40959745, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:44,7996628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959748, endtime: 40959749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:44,8127980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959750, endtime: 40959750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:44,8296607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959751, endtime: 40959752, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:44,8445647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959753, endtime: 40959753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:44,8602355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959755, endtime: 40959755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:44,8768481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959756, endtime: 40959756, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:44,9103979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959759, endtime: 40959760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:44,9420202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959762, endtime: 40959763, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:44,9541545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959764, endtime: 40959764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:44,9717880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959766, endtime: 40959766, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,0079854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959769, endtime: 40959769, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,0323150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959772, endtime: 40959772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,0479945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959773, endtime: 40959773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,0657335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959775, endtime: 40959775, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,0863645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959776, endtime: 40959777, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,0950045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959778, endtime: 40959778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,1214811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959780, endtime: 40959781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,1416217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959783, endtime: 40959783, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,1627137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959785, endtime: 40959785, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,2001478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959787, endtime: 40959789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,2203438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959791, endtime: 40959791, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,2369140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959792, endtime: 40959792, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,2520623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959794, endtime: 40959794, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,2689334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959795, endtime: 40959796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,2825690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959797, endtime: 40959797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,2993513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959798, endtime: 40959799, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,3024716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959506, endtime: 40959799, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,3025641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959508, endtime: 40959799, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,3156140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959800, endtime: 40959800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,3450659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959803, endtime: 40959803, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,3605142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959805, endtime: 40959805, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,3759047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959806, endtime: 40959806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,3915575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959808, endtime: 40959808, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,4073467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959809, endtime: 40959809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:45,4324987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959811, endtime: 40959812, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1935993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959378, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1936184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959409, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1936256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959411, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1936329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959413, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1936384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959416, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1936450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959420, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1936503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959420, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1936572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959422, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1936625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959423, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1936955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959425, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1937013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959427, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1937077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959430, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1937132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959431, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1937271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958714, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1937331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958716, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1937398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958717, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1937453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958719, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1937523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958720, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1937578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958722, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1938179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958723, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1938249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958725, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1938315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958726, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1938368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958728, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1938434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958730, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1938490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958731, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,1938556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40958733, endtime: 40959888, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,4068405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959620, endtime: 40959909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,4068577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959622, endtime: 40959909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,4068649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959623, endtime: 40959909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,4068724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959625, endtime: 40959909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,4068779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959627, endtime: 40959909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,4068846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959629, endtime: 40959909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,4068904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959631, endtime: 40959909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,4068973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959635, endtime: 40959909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,4069028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959638, endtime: 40959909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,4069339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959639, endtime: 40959909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,4069397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959641, endtime: 40959909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,4069466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959642, endtime: 40959909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,4069522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959644, endtime: 40959909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,5089545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959399, endtime: 40959920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,5089728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959400, endtime: 40959920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,5089825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959401, endtime: 40959920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,5089894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959403, endtime: 40959920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,5089969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959405, endtime: 40959920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,5090030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959406, endtime: 40959920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,5090102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959409, endtime: 40959920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,5090163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959411, endtime: 40959920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,5090393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959413, endtime: 40959920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,5090775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959416, endtime: 40959920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,5090853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959420, endtime: 40959920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,5090916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959420, endtime: 40959920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,5090988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959422, endtime: 40959920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,9278056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959610, endtime: 40959961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,9278220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959611, endtime: 40959961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,9278294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959612, endtime: 40959961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,9278369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959614, endtime: 40959961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,9278427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959616, endtime: 40959961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,9278491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959620, endtime: 40959961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,9278549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959620, endtime: 40959961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,9278613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959622, endtime: 40959961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,9278668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959623, endtime: 40959961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,9279419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959625, endtime: 40959961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,9279488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959627, endtime: 40959961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,9279555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959629, endtime: 40959961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:46,9280852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959631, endtime: 40959961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,4982748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959510, endtime: 40960018, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,4982942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959513, endtime: 40960018, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,4983017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959516, endtime: 40960018, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,4983097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959517, endtime: 40960018, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,4983155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959519, endtime: 40960018, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,4983225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959520, endtime: 40960018, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,4983283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959522, endtime: 40960018, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,4983352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959525, endtime: 40960018, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,4983405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959528, endtime: 40960018, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,4983707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959530, endtime: 40960018, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,4983768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959531, endtime: 40960018, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,4983837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959799, endtime: 40960018, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,4983892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959800, endtime: 40960018, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,6147780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959812, endtime: 40960030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,6147957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959814, endtime: 40960030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,6148032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959816, endtime: 40960030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:47,6148110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959817, endtime: 40960030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:48,2298108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959909, endtime: 40960092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:48,2298299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959911, endtime: 40960092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:48,2298377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959912, endtime: 40960092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:48,2298455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959914, endtime: 40960092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:48,2298513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959916, endtime: 40960092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:48,2298582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959919, endtime: 40960092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:48,2298637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959920, endtime: 40960092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:48,2298704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959922, endtime: 40960092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:48,2298759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959925, endtime: 40960092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:48,2299070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959926, endtime: 40960092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:48,2299131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959928, endtime: 40960092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:48,2299194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959930, endtime: 40960092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:48,2299422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959931, endtime: 40960092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,2884256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959888, endtime: 40960197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,2884445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959889, endtime: 40960197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,2884520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959891, endtime: 40960197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,2884594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959892, endtime: 40960197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,2884653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959894, endtime: 40960197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,2884722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959895, endtime: 40960197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,2884777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959897, endtime: 40960197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,2884844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959898, endtime: 40960197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,2884896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959900, endtime: 40960197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,2885196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959901, endtime: 40960197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,2885254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959901, endtime: 40960197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,2885320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959903, endtime: 40960197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,2885376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959905, endtime: 40960197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,4607925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959920, endtime: 40960215, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,4608260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959920, endtime: 40960215, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,4608401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959922, endtime: 40960215, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,4608504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959925, endtime: 40960215, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,4608570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959926, endtime: 40960215, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,4608650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959928, endtime: 40960215, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,4608714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959930, endtime: 40960215, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,4608789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959931, endtime: 40960215, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,4608855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959933, endtime: 40960215, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,4609169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959936, endtime: 40960215, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,4609232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959938, endtime: 40960215, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,4609302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959941, endtime: 40960215, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,4609357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959942, endtime: 40960215, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,7085036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959820, endtime: 40960239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,7085246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959822, endtime: 40960239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,7085332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959825, endtime: 40960239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,7085412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959827, endtime: 40960239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,7085476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959828, endtime: 40960239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,7085551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959830, endtime: 40960239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,7085612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959832, endtime: 40960239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,7085684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959833, endtime: 40960239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,7085742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959836, endtime: 40960239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,7086036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960030, endtime: 40960239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,7086097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960031, endtime: 40960239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,7086169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960033, endtime: 40960239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:49,7086230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960034, endtime: 40960239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,0301881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960239, endtime: 40960272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,0302064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960241, endtime: 40960272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,0302138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960242, endtime: 40960272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,0302213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960244, endtime: 40960272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,0302274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960247, endtime: 40960272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,0302343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960248, endtime: 40960272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,0302399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960250, endtime: 40960272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,0302465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960253, endtime: 40960272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,0302521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960255, endtime: 40960272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,0303136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960258, endtime: 40960272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,0303213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960259, endtime: 40960272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,0303283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960263, endtime: 40960272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,8255384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,8255509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:50,8258659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40960351, endtime: 40960351, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,5608598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960197, endtime: 40960425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,5608798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960198, endtime: 40960425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,5608878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960200, endtime: 40960425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,5608956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960201, endtime: 40960425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,5609020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960201, endtime: 40960425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,5609089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960205, endtime: 40960425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,5609147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960206, endtime: 40960425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,5609219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960211, endtime: 40960425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,5609277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960212, endtime: 40960425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,5609585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960214, endtime: 40960425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,5609646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960216, endtime: 40960425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,5609718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960217, endtime: 40960425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,5609776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960219, endtime: 40960425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6342930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960425, endtime: 40960432, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6493407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960092, endtime: 40960434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6493585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960094, endtime: 40960434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6493659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960095, endtime: 40960434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6493731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960098, endtime: 40960434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6493787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960099, endtime: 40960434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6493853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960100, endtime: 40960434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6493909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960104, endtime: 40960434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6493973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960105, endtime: 40960434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6494028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960108, endtime: 40960434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6494513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960109, endtime: 40960434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6494615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960111, endtime: 40960434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6494726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960112, endtime: 40960434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:51,6494818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960114, endtime: 40960434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,1341805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960215, endtime: 40960482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,1342002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960216, endtime: 40960482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,1342079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960217, endtime: 40960482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,1342157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960219, endtime: 40960482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,1342215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960219, endtime: 40960482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,1342284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960222, endtime: 40960482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,1342343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960223, endtime: 40960482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,1342409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960225, endtime: 40960482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,1342464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960226, endtime: 40960482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,1342764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960228, endtime: 40960482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,1342830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960231, endtime: 40960482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,1342899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960233, endtime: 40960482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,1342955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960234, endtime: 40960482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,2307561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959961, endtime: 40960492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,2307819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959962, endtime: 40960492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,2307913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959964, endtime: 40960492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,2307980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959966, endtime: 40960492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,2308143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959967, endtime: 40960492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,2308210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959969, endtime: 40960492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,2308282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959970, endtime: 40960492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,2308340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959972, endtime: 40960492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,2308415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959973, endtime: 40960492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,2309080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959975, endtime: 40960492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,2309163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959978, endtime: 40960492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,2309221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959981, endtime: 40960492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,8279485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960018, endtime: 40960551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,8279651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960020, endtime: 40960551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,8279723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960022, endtime: 40960551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,8279798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960023, endtime: 40960551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,8279856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960025, endtime: 40960551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,8279928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960026, endtime: 40960551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,8279984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960029, endtime: 40960551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,8280053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960031, endtime: 40960551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,8280109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960033, endtime: 40960551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,8280408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960034, endtime: 40960551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,8280469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960036, endtime: 40960551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,8280535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960038, endtime: 40960551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:52,8280593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960041, endtime: 40960551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:53,7705691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960434, endtime: 40960646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:53,7705868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960434, endtime: 40960646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:53,7705943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960437, endtime: 40960646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:53,7706015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960439, endtime: 40960646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:53,7706071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960441, endtime: 40960646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:53,7706137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960445, endtime: 40960646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:53,7706192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960447, endtime: 40960646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:53,7706259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960448, endtime: 40960646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:53,7706312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960450, endtime: 40960646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:53,7706619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960451, endtime: 40960646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:53,7706677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960453, endtime: 40960646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:53,7706741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960456, endtime: 40960646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:53,7706794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960458, endtime: 40960646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4011331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960264, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4011523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960272, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4011597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960273, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4011672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960275, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4011730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960277, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4011797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960278, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4011855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960281, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4011919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960283, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4011974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960284, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4012315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960286, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4012373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960288, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4012440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960290, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4012492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960291, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4012628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960426, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4012684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960428, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4012747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960430, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4012803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960431, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4012869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960434, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4012925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960437, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4013894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960439, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4013961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960441, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4014027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960445, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4014094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960447, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4014146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960448, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4014210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960450, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:54,4015573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960451, endtime: 40960709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,3129348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54956 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,7606544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40959985, endtime: 40960845, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,7606718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960492, endtime: 40960845, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,7606807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960495, endtime: 40960845, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,7606871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960497, endtime: 40960845, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,7606943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960500, endtime: 40960845, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,7606998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960501, endtime: 40960845, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,7607067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960503, endtime: 40960845, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,7607120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960505, endtime: 40960845, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,7607189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960508, endtime: 40960845, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,7607242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960511, endtime: 40960845, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,7607572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960513, endtime: 40960845, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,7607630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960515, endtime: 40960845, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:55,7607696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960517, endtime: 40960845, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,3234137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960646, endtime: 40960901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,3234331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960648, endtime: 40960901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,3234408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960650, endtime: 40960901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,3234486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960652, endtime: 40960901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,3234547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960653, endtime: 40960901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,3234613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960655, endtime: 40960901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,3234671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960656, endtime: 40960901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,3234741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960658, endtime: 40960901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,3234796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960661, endtime: 40960901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,3235289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960664, endtime: 40960901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,3235400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960667, endtime: 40960901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,3235514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960670, endtime: 40960901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,3235611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960672, endtime: 40960901, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,5509241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960551, endtime: 40960924, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,5509429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960553, endtime: 40960924, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,5509507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960556, endtime: 40960924, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,5509581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960559, endtime: 40960924, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,5509640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960561, endtime: 40960924, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,5509706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960563, endtime: 40960924, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,5509764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960564, endtime: 40960924, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,5509833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960566, endtime: 40960924, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,5509892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960568, endtime: 40960924, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,5510185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960569, endtime: 40960924, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,5510243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960569, endtime: 40960924, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,5510310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960572, endtime: 40960924, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,5510368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960573, endtime: 40960924, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,7910990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960709, endtime: 40960948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,7911167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960711, endtime: 40960948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,7911239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960712, endtime: 40960948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,7911314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960716, endtime: 40960948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,7911372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960717, endtime: 40960948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,7911438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960720, endtime: 40960948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,7911494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960722, endtime: 40960948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,7911799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960724, endtime: 40960948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,7911912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960725, endtime: 40960948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,7912907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960727, endtime: 40960948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,7912979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960728, endtime: 40960948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,7913045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960730, endtime: 40960948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:56,7913680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960731, endtime: 40960948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:57,1717643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960709, endtime: 40960986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:57,1717859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960711, endtime: 40960986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:57,1717942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960712, endtime: 40960986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:57,1718022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960716, endtime: 40960986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:57,1718080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960717, endtime: 40960986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:57,1718150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960720, endtime: 40960986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:57,1718208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960722, endtime: 40960986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:57,1718280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960724, endtime: 40960986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:57,1718338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960725, endtime: 40960986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:57,1718615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960727, endtime: 40960986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:57,1718676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960728, endtime: 40960986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:57,1718745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960730, endtime: 40960986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:57,1718804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960731, endtime: 40960986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:58,4758466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960845, endtime: 40961116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:58,4758682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960845, endtime: 40961116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:58,4758759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960847, endtime: 40961116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:58,4758840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960848, endtime: 40961116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:58,4758901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960850, endtime: 40961116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:58,4758970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960852, endtime: 40961116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:58,4759028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960853, endtime: 40961116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:58,4759095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960855, endtime: 40961116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:58,4759153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960856, endtime: 40961116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:58,4759441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960858, endtime: 40961116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:58,4759502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960859, endtime: 40961116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:58,4759571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960862, endtime: 40961116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:58,4759629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960863, endtime: 40961116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,0302809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960482, endtime: 40961172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,0302983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960483, endtime: 40961172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,0303080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960484, endtime: 40961172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,0303152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960486, endtime: 40961172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,0303227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960487, endtime: 40961172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,0303288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960489, endtime: 40961172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,0303363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960491, endtime: 40961172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,0303421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960492, endtime: 40961172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,0303493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960495, endtime: 40961172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,0303784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960497, endtime: 40961172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,0303859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960500, endtime: 40961172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,0303920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960501, endtime: 40961172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,0303992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960501, endtime: 40961172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,4389798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960901, endtime: 40961213, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,4389998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960903, endtime: 40961213, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,4390081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960905, endtime: 40961213, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,4390164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960908, endtime: 40961213, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,4390225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960909, endtime: 40961213, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,4390297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960911, endtime: 40961213, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,4390358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960912, endtime: 40961213, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,4390427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960914, endtime: 40961213, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,4390485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960918, endtime: 40961213, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,4390787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960921, endtime: 40961213, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,4390851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960924, endtime: 40961213, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,4390920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960925, endtime: 40961213, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,4391078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960927, endtime: 40961213, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,6082819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960948, endtime: 40961229, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,6083029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960948, endtime: 40961229, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,6083107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960952, endtime: 40961229, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,6083187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960955, endtime: 40961229, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,6083339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960956, endtime: 40961229, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,6083411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960958, endtime: 40961229, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,6083470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960961, endtime: 40961229, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,6083542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960962, endtime: 40961229, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,6083597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960964, endtime: 40961229, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,6084245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960966, endtime: 40961229, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,6084317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960968, endtime: 40961229, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,6084384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960969, endtime: 40961229, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,9417174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960924, endtime: 40961263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,9417346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960925, endtime: 40961263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,9417557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960927, endtime: 40961263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,9417679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960930, endtime: 40961263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,9417770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960933, endtime: 40961263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,9417881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960936, endtime: 40961263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,9417947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960937, endtime: 40961263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,9418019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960938, endtime: 40961263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,9418075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960941, endtime: 40961263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,9418385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960942, endtime: 40961263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,9418440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960945, endtime: 40961263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,9418507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960948, endtime: 40961263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:55:59,9418562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960952, endtime: 40961263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,0597062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960986, endtime: 40961275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,0597245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960987, endtime: 40961275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,0597319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960989, endtime: 40961275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,0597391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960991, endtime: 40961275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,0597450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960992, endtime: 40961275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,0597516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960994, endtime: 40961275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,0597572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960995, endtime: 40961275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,0597635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960997, endtime: 40961275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,0597688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960998, endtime: 40961275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,0597971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960999, endtime: 40961275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,0598029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961002, endtime: 40961275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,0598092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961005, endtime: 40961275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,0598148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961006, endtime: 40961275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,9361126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,9361245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:00,9365054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40961362, endtime: 40961362, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,2337187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40960970, endtime: 40961392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,2337395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961229, endtime: 40961392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,2337475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961231, endtime: 40961392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,2337553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961233, endtime: 40961392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,2337614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961234, endtime: 40961392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,2337683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961236, endtime: 40961392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,2337738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961237, endtime: 40961392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,2337808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961239, endtime: 40961392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,2337863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961241, endtime: 40961392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,2338165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961242, endtime: 40961392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,2338226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961246, endtime: 40961392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,2338293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961249, endtime: 40961392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,2338351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961252, endtime: 40961392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,7215266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961116, endtime: 40961441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,7215454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961117, endtime: 40961441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,7215532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961119, endtime: 40961441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,7215607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961120, endtime: 40961441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,7215665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961122, endtime: 40961441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,7215731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961123, endtime: 40961441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,7215787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961126, endtime: 40961441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,7215853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961128, endtime: 40961441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,7215906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961130, endtime: 40961441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,7216202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961133, endtime: 40961441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,7216260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961134, endtime: 40961441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,7216327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961136, endtime: 40961441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,7216380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961138, endtime: 40961441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,9042631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961213, endtime: 40961459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,9042808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961214, endtime: 40961459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,9042885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961216, endtime: 40961459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,9042966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961217, endtime: 40961459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,9043149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961219, endtime: 40961459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,9043254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961220, endtime: 40961459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,9043318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961222, endtime: 40961459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,9043395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961223, endtime: 40961459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,9043459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961225, endtime: 40961459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,9043758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961227, endtime: 40961459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,9043822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961228, endtime: 40961459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,9043894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961230, endtime: 40961459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:01,9043952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961231, endtime: 40961459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,6541989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961441, endtime: 40961534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,6542175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961442, endtime: 40961534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,6542252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961444, endtime: 40961534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,6542333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961447, endtime: 40961534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,6542394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961448, endtime: 40961534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,6542463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961452, endtime: 40961534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,6542521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961453, endtime: 40961534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,6542590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961455, endtime: 40961534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,6542649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961456, endtime: 40961534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,6542926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961459, endtime: 40961534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,6563594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961461, endtime: 40961534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,6563716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961462, endtime: 40961534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,6563788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961464, endtime: 40961534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,7389016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961534, endtime: 40961543, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,9455214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961275, endtime: 40961563, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,9455408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961278, endtime: 40961563, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,9455488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961280, endtime: 40961563, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,9455569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961281, endtime: 40961563, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,9455630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961283, endtime: 40961563, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,9455702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961287, endtime: 40961563, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,9455760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961287, endtime: 40961563, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,9455829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961289, endtime: 40961563, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,9456023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961291, endtime: 40961563, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,9456489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961292, endtime: 40961563, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,9456561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961294, endtime: 40961563, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,9456635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961295, endtime: 40961563, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:02,9456699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961297, endtime: 40961563, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:03,3329109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961563, endtime: 40961602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:04,1642017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961263, endtime: 40961685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:04,1642378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961264, endtime: 40961685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:04,1642511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961267, endtime: 40961685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:04,1642644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961269, endtime: 40961685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:04,1642727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961270, endtime: 40961685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:04,1642804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961273, endtime: 40961685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:04,1642868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961273, endtime: 40961685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:04,1642946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961275, endtime: 40961685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:04,1643007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961278, endtime: 40961685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:04,1643336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961280, endtime: 40961685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:04,1643400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961281, endtime: 40961685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:04,1643475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961283, endtime: 40961685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:04,1643533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961287, endtime: 40961685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,3830807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961536, endtime: 40961807, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,3830971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961539, endtime: 40961807, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,3831059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961541, endtime: 40961807, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,3831126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961542, endtime: 40961807, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,3831201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961544, endtime: 40961807, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,3831262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961545, endtime: 40961807, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,3831331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961547, endtime: 40961807, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,3831389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961549, endtime: 40961807, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,3831458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961550, endtime: 40961807, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,3832223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961552, endtime: 40961807, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,3832312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961553, endtime: 40961807, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,3832373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961555, endtime: 40961807, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,3832996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961555, endtime: 40961807, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,4598809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961564, endtime: 40961815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,4598973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961566, endtime: 40961815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,4599059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961567, endtime: 40961815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,4599120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961569, endtime: 40961815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,4599186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961570, endtime: 40961815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,4599242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961573, endtime: 40961815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,4599308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961577, endtime: 40961815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,4599364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961578, endtime: 40961815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,4599427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961580, endtime: 40961815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,4600159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961583, endtime: 40961815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,4600239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961586, endtime: 40961815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,4600294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961588, endtime: 40961815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,4602032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961602, endtime: 40961815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,9446470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961172, endtime: 40961863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,9446642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961173, endtime: 40961863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,9446717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961177, endtime: 40961863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,9446789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961178, endtime: 40961863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,9446847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961180, endtime: 40961863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,9446911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961183, endtime: 40961863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,9446966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961184, endtime: 40961863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,9449235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961186, endtime: 40961863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,9450019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961189, endtime: 40961863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,9450113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961192, endtime: 40961863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,9450188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961194, endtime: 40961863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,9450244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961195, endtime: 40961863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:05,9450310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961199, endtime: 40961863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,1574862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961459, endtime: 40961884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,1575036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961461, endtime: 40961884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,1575111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961462, endtime: 40961884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,1575186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961464, endtime: 40961884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,1575241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961466, endtime: 40961884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,1575308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961467, endtime: 40961884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,1575363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961472, endtime: 40961884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,1575430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961475, endtime: 40961884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,1575485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961477, endtime: 40961884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,1575793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961478, endtime: 40961884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,1575848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961480, endtime: 40961884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,1575912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961481, endtime: 40961884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,1575970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961483, endtime: 40961884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,5437117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961392, endtime: 40961923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,5437300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961394, endtime: 40961923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,5437386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961395, endtime: 40961923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,5437450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961397, endtime: 40961923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,5437516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961398, endtime: 40961923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,5437572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961400, endtime: 40961923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,5437635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961401, endtime: 40961923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,5437691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961401, endtime: 40961923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,5437755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961403, endtime: 40961923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,5437807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961405, endtime: 40961923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,5438115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961406, endtime: 40961923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,5438173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961408, endtime: 40961923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,5438239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961409, endtime: 40961923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,6288948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961923, endtime: 40961931, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,8929303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961807, endtime: 40961958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,8929481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961808, endtime: 40961958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,8929556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961809, endtime: 40961958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,8929633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961811, endtime: 40961958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,8929691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961814, endtime: 40961958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,8929761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961816, endtime: 40961958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,8929819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961817, endtime: 40961958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,8929888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961819, endtime: 40961958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,8929943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961820, endtime: 40961958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,8930744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961822, endtime: 40961958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,8930822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961823, endtime: 40961958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,8930891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961825, endtime: 40961958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:06,8932235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961827, endtime: 40961958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:07,3436645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961685, endtime: 40962003, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:07,3436792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961686, endtime: 40962003, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:07,3436861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961689, endtime: 40962003, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:07,3436931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961692, endtime: 40962003, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:07,3436986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961694, endtime: 40962003, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:07,3437050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961695, endtime: 40962003, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:07,3437102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961699, endtime: 40962003, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:07,3437166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961700, endtime: 40962003, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:07,3437219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961700, endtime: 40962003, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:07,3437676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961701, endtime: 40962003, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:07,3437740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961703, endtime: 40962003, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:07,3437803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961706, endtime: 40962003, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:07,3437856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961708, endtime: 40962003, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,1961646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961863, endtime: 40962088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,1961812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961865, endtime: 40962088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,1961887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961867, endtime: 40962088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,1961959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961869, endtime: 40962088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,1962017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961870, endtime: 40962088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,1962089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961874, endtime: 40962088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,1962145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961877, endtime: 40962088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,1962217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961878, endtime: 40962088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,1962272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961880, endtime: 40962088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,1962599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961883, endtime: 40962088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,1962657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961884, endtime: 40962088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,1962726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961886, endtime: 40962088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,1962782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961888, endtime: 40962088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,8162737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54961 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9095620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9100449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962160, endtime: 40962160, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9226399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962161, endtime: 40962161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9393436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962163, endtime: 40962163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9707271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962166, endtime: 40962166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9864825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962167, endtime: 40962167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9968843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961815, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9969026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961816, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9969100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961817, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9969175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961819, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9969233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961820, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9969300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961822, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9969358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961823, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9969425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961825, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9969480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961827, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9970283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961828, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9970358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961831, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9970425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961837, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9970569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961958, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9970638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961959, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9970693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961962, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9970757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961964, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9970813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961967, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9971785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961970, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9971854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961972, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9971921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961975, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9971976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961977, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9972043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961978, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9972095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961980, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9972162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961981, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9972311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961837, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:08,9973555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961983, endtime: 40962168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,0292475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962170, endtime: 40962172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,0516106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962174, endtime: 40962174, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,0634370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962175, endtime: 40962175, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,0834862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962176, endtime: 40962177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,1031574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962178, endtime: 40962179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,1120213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962180, endtime: 40962180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,1272893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962181, endtime: 40962181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,1428543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962183, endtime: 40962183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,1585454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962184, endtime: 40962184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,1749113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962186, endtime: 40962186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2068138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962189, endtime: 40962189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2416079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962192, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2416281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962088, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2416367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962089, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2416433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962091, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2416503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962092, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2416558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962095, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2416625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962097, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2416677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962098, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2416744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962102, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2416988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962105, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2417057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962106, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2417109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962108, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2417176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962111, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2417229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962113, endtime: 40962193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2512070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962194, endtime: 40962194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2671932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962195, endtime: 40962195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,2847186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962197, endtime: 40962197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,3151108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962200, endtime: 40962200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,3497545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962203, endtime: 40962204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,3884135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962206, endtime: 40962207, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,4073561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962209, endtime: 40962209, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,4239587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962211, endtime: 40962211, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7244163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962214, endtime: 40962241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7244343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962216, endtime: 40962241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7244418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962219, endtime: 40962241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7244490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962220, endtime: 40962241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7244545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962224, endtime: 40962241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7244612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962225, endtime: 40962241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7244664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962227, endtime: 40962241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7244731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962228, endtime: 40962241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7244783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962231, endtime: 40962241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7245035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962233, endtime: 40962241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7245091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962238, endtime: 40962241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7245157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962239, endtime: 40962241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7245337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962241, endtime: 40962241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7536637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961927, endtime: 40962244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7536809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961930, endtime: 40962244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7536897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961931, endtime: 40962244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7536967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961936, endtime: 40962244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7537036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961938, endtime: 40962244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7537094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961939, endtime: 40962244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7537161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961941, endtime: 40962244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7537219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961943, endtime: 40962244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7537288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961945, endtime: 40962244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7537875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961947, endtime: 40962244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7537964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961949, endtime: 40962244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:09,7538147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961950, endtime: 40962244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,0870530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961952, endtime: 40962277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,0870729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962244, endtime: 40962277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,0870821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962247, endtime: 40962277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,0870885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962248, endtime: 40962277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,0870957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962252, endtime: 40962277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,0871026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962255, endtime: 40962277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,0871084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962258, endtime: 40962277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,0871153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962259, endtime: 40962277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,0871209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962261, endtime: 40962277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,0871508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962264, endtime: 40962277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,0871572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962266, endtime: 40962277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,0871638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962267, endtime: 40962277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,0871696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962269, endtime: 40962277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,6508080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961884, endtime: 40962334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,6508269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961886, endtime: 40962334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,6508349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961888, endtime: 40962334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,6508427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961891, endtime: 40962334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,6508485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961892, endtime: 40962334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,6508554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961895, endtime: 40962334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,6508612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961897, endtime: 40962334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,6508679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961898, endtime: 40962334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,6508737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961901, endtime: 40962334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,6509036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961905, endtime: 40962334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,6509097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961906, endtime: 40962334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,6509164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961908, endtime: 40962334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:10,6509224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40961909, endtime: 40962334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,1891207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,1891324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,1906359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40962388, endtime: 40962388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5105046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962168, endtime: 40962420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5105318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962170, endtime: 40962420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5105412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962174, endtime: 40962420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5105501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962175, endtime: 40962420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5105567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962176, endtime: 40962420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5105642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962178, endtime: 40962420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5105706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962180, endtime: 40962420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5105780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962181, endtime: 40962420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5105844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962183, endtime: 40962420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5106179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962184, endtime: 40962420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5106240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962186, endtime: 40962420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5106312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962189, endtime: 40962420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5106371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962193, endtime: 40962420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5252335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962193, endtime: 40962421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5252520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962194, endtime: 40962421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5252601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962195, endtime: 40962421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5252678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962197, endtime: 40962421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5252739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962200, endtime: 40962421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5252811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962201, endtime: 40962421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5252872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962203, endtime: 40962421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5252944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962206, endtime: 40962421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5253005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962209, endtime: 40962421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5253313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962211, endtime: 40962421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5253377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962214, endtime: 40962421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5253449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962216, endtime: 40962421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:11,5253509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962219, endtime: 40962421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:12,2311424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962168, endtime: 40962492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:12,2311634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962170, endtime: 40962492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:12,2311720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962174, endtime: 40962492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:12,2311800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962175, endtime: 40962492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:12,2311864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962176, endtime: 40962492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:12,2311939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962178, endtime: 40962492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:12,2311997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962180, endtime: 40962492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:12,2312069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962181, endtime: 40962492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:12,2312127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962183, endtime: 40962492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:12,2312934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962184, endtime: 40962492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:12,2313014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962186, endtime: 40962492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:12,2313089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962189, endtime: 40962492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:12,2314294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962193, endtime: 40962492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:13,3930550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962420, endtime: 40962608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:13,3930736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962422, endtime: 40962608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:13,3930813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962425, endtime: 40962608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:13,3930897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962427, endtime: 40962608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:13,3930958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962429, endtime: 40962608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:13,3931032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962431, endtime: 40962608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:13,3931096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962433, endtime: 40962608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:13,3931174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962435, endtime: 40962608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:13,3931232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962436, endtime: 40962608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:13,3931595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962438, endtime: 40962608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:13,3931653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962439, endtime: 40962608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:13,3931722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962441, endtime: 40962608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:13,3931778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962442, endtime: 40962608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:14,5270582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962334, endtime: 40962721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:14,5270737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962334, endtime: 40962721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:14,5270814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962336, endtime: 40962721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:14,5270892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962339, endtime: 40962721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:14,5270956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962341, endtime: 40962721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:14,5271025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962342, endtime: 40962721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:14,5271083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962345, endtime: 40962721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:14,5271155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962347, endtime: 40962721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:14,5271213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962348, endtime: 40962721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:14,5271513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962352, endtime: 40962721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:14,5271576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962353, endtime: 40962721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:14,5271646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962355, endtime: 40962721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:14,5271707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962356, endtime: 40962721, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,2424792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962277, endtime: 40962793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,2424947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962278, endtime: 40962793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,2425028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962280, endtime: 40962793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,2425091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962281, endtime: 40962793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,2425158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962283, endtime: 40962793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,2425213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962284, endtime: 40962793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,2425283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962286, endtime: 40962793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,2425335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962287, endtime: 40962793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,2425402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962291, endtime: 40962793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,2425695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962292, endtime: 40962793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,2425767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962294, endtime: 40962793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,2425820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962295, endtime: 40962793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,2425889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962297, endtime: 40962793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,3224343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962421, endtime: 40962801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,3224575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962422, endtime: 40962801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,3224678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962425, endtime: 40962801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,3224758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962427, endtime: 40962801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,3224816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962429, endtime: 40962801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,3224888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962431, endtime: 40962801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,3224944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962433, endtime: 40962801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,3225010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962435, endtime: 40962801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,3225069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962436, endtime: 40962801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,3225376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962438, endtime: 40962801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,3225434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962439, endtime: 40962801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,3225501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962441, endtime: 40962801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,3225556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962442, endtime: 40962801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,8004607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962492, endtime: 40962849, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,8004795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962494, endtime: 40962849, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,8004873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962495, endtime: 40962849, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,8004950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962497, endtime: 40962849, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,8005009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962498, endtime: 40962849, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,8005081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962500, endtime: 40962849, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,8005139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962501, endtime: 40962849, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,8005211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962503, endtime: 40962849, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,8005269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962506, endtime: 40962849, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,8005601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962508, endtime: 40962849, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,8005660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962508, endtime: 40962849, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,8005726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962509, endtime: 40962849, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,8005781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962509, endtime: 40962849, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,9203367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962242, endtime: 40962861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,9203539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962244, endtime: 40962861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,9203631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962247, endtime: 40962861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,9203697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962248, endtime: 40962861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,9203769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962252, endtime: 40962861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,9203827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962255, endtime: 40962861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,9203897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962258, endtime: 40962861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,9203955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962259, endtime: 40962861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,9204021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962261, endtime: 40962861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,9204320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962264, endtime: 40962861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,9204392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962266, endtime: 40962861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,9204647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962267, endtime: 40962861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:15,9204794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962269, endtime: 40962861, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,2403512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962608, endtime: 40962893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,2403708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962609, endtime: 40962893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,2403789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962611, endtime: 40962893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,2403869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962613, endtime: 40962893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,2403935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962616, endtime: 40962893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,2404007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962617, endtime: 40962893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,2404071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962620, endtime: 40962893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,2404143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962622, endtime: 40962893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,2404204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962624, endtime: 40962893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,2404506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962625, endtime: 40962893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,2404570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962627, endtime: 40962893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,2404639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962628, endtime: 40962893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,2404700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962630, endtime: 40962893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,7409997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962721, endtime: 40962943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,7410153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962723, endtime: 40962943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,7410222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962725, endtime: 40962943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,7410294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962728, endtime: 40962943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,7410349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962730, endtime: 40962943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,7410416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962731, endtime: 40962943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,7410468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962733, endtime: 40962943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,7410535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962734, endtime: 40962943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,7410588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962736, endtime: 40962943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,7410887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962737, endtime: 40962943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,7410942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962739, endtime: 40962943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,7411006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962741, endtime: 40962943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:16,7411061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962742, endtime: 40962943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:17,5707892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962849, endtime: 40963026, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:17,5708053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962850, endtime: 40963026, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:17,5708122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962853, endtime: 40963026, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:17,5708197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962855, endtime: 40963026, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:17,5708255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962856, endtime: 40963026, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:17,5708325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962858, endtime: 40963026, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:17,5708380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962859, endtime: 40963026, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:17,5708447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962861, endtime: 40963026, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:17,5708502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962862, endtime: 40963026, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:17,5708807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962864, endtime: 40963026, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:17,5708865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962866, endtime: 40963026, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:17,5708931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962867, endtime: 40963026, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:17,5708987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962869, endtime: 40963026, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,1161331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962861, endtime: 40963080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,1161486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962862, endtime: 40963080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,1161555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962864, endtime: 40963080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,1161627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962866, endtime: 40963080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,1161685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962867, endtime: 40963080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,1161752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962869, endtime: 40963080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,1161807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962870, endtime: 40963080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,1161871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962872, endtime: 40963080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,1161926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962873, endtime: 40963080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,1162209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962875, endtime: 40963080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,1162267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962877, endtime: 40963080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,1162331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962878, endtime: 40963080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,1162389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962880, endtime: 40963080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,4045376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962801, endtime: 40963109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,4045562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962803, endtime: 40963109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,4045642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962805, endtime: 40963109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,4045722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962806, endtime: 40963109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,4045786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962808, endtime: 40963109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,4045858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962811, endtime: 40963109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,4045922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962813, endtime: 40963109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,4045994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962816, endtime: 40963109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,4046052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962819, endtime: 40963109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,4046354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962820, endtime: 40963109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,4046421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962822, endtime: 40963109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,4046490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962824, endtime: 40963109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:18,4046551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962825, endtime: 40963109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:19,1112062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962793, endtime: 40963180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:19,1112261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962794, endtime: 40963180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:19,1112342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962795, endtime: 40963180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:19,1112419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962797, endtime: 40963180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:19,1112477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962798, endtime: 40963180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:19,1112549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962800, endtime: 40963180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:19,1112605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962800, endtime: 40963180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:19,1112677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962803, endtime: 40963180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:19,1112732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962805, endtime: 40963180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:19,1113048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962806, endtime: 40963180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:19,1113109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962808, endtime: 40963180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:19,1113178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962811, endtime: 40963180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:19,1113239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962813, endtime: 40963180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,1393825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963080, endtime: 40963283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,1394050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963083, endtime: 40963283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,1394163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963084, endtime: 40963283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,1394285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963086, endtime: 40963283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,1394382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963088, endtime: 40963283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,1394487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963091, endtime: 40963283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,1394545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963092, endtime: 40963283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,1394617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963094, endtime: 40963283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,1394676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963095, endtime: 40963283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,1394991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963097, endtime: 40963283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,1395050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963100, endtime: 40963283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,1395116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963101, endtime: 40963283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,1395172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963103, endtime: 40963283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8133128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963026, endtime: 40963350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8133294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963028, endtime: 40963350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8133363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963030, endtime: 40963350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8133438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963031, endtime: 40963350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8133490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963033, endtime: 40963350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8133554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963034, endtime: 40963350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8133610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963036, endtime: 40963350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8133673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963038, endtime: 40963350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8133726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963041, endtime: 40963350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8134505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963042, endtime: 40963350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8134571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963044, endtime: 40963350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8134637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963047, endtime: 40963350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8136364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963049, endtime: 40963350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8968781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962893, endtime: 40963358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8968964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962894, endtime: 40963358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8969044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962895, endtime: 40963358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8969125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962897, endtime: 40963358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8969188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962898, endtime: 40963358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8969263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962900, endtime: 40963358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8969324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962901, endtime: 40963358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8969396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962902, endtime: 40963358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8969454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962905, endtime: 40963358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8969759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962906, endtime: 40963358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8969820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962908, endtime: 40963358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8969892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962911, endtime: 40963358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:20,8969953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962912, endtime: 40963358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,1379263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962943, endtime: 40963382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,1379446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962944, endtime: 40963382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,1379523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962945, endtime: 40963382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,1379601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962947, endtime: 40963382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,1379662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962948, endtime: 40963382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,1379734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962951, endtime: 40963382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,1379792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962953, endtime: 40963382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,1379859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962955, endtime: 40963382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,1379917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962956, endtime: 40963382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,1380216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962958, endtime: 40963382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,1380277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962959, endtime: 40963382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,1380346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962961, endtime: 40963382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,1380404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40962964, endtime: 40963382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,2019753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,2019875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,2024369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40963389, endtime: 40963389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8076398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963109, endtime: 40963449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8076594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963111, endtime: 40963449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8076675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963112, endtime: 40963449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8076755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963116, endtime: 40963449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8076813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963117, endtime: 40963449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8076882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963119, endtime: 40963449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8076943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963122, endtime: 40963449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8077013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963124, endtime: 40963449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8077071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963126, endtime: 40963449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8077389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963129, endtime: 40963449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8077450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963131, endtime: 40963449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8077520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963135, endtime: 40963449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8077730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963138, endtime: 40963449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8933177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963283, endtime: 40963458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8933349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963284, endtime: 40963458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8933418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963286, endtime: 40963458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8933493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963287, endtime: 40963458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8933551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963289, endtime: 40963458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8933617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963291, endtime: 40963458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8933670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963292, endtime: 40963458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8933736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963294, endtime: 40963458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8933789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963295, endtime: 40963458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8934091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963299, endtime: 40963458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8934149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963300, endtime: 40963458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8934216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963301, endtime: 40963458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:21,8941336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963303, endtime: 40963458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4030299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963180, endtime: 40963609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4030482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963183, endtime: 40963609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4030559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963184, endtime: 40963609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4030634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963186, endtime: 40963609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4030692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963187, endtime: 40963609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4030761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963189, endtime: 40963609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4030814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963191, endtime: 40963609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4030881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963192, endtime: 40963609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4030936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963194, endtime: 40963609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4031232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963195, endtime: 40963609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4031291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963197, endtime: 40963609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4031357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963198, endtime: 40963609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4031413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963200, endtime: 40963609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4869285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963382, endtime: 40963617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4869463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963384, endtime: 40963617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4869543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963386, endtime: 40963617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4869621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963387, endtime: 40963617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4869679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963389, endtime: 40963617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4869751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963391, endtime: 40963617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4869806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963392, endtime: 40963617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4869876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963394, endtime: 40963617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4869931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963395, endtime: 40963617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4870247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963397, endtime: 40963617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4870311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963398, endtime: 40963617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4870380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963400, endtime: 40963617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,4870435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963401, endtime: 40963617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,5743084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963358, endtime: 40963626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,5743273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963359, endtime: 40963626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,5743353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963361, endtime: 40963626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,5743433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963363, endtime: 40963626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,5743494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963366, endtime: 40963626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,5743566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963371, endtime: 40963626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,5743622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963373, endtime: 40963626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,5743694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963374, endtime: 40963626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,5743752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963375, endtime: 40963626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,5744370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963376, endtime: 40963626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,5744442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963378, endtime: 40963626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,5744517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963380, endtime: 40963626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:23,5744580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963381, endtime: 40963626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:24,1608300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963449, endtime: 40963685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:24,1608646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963451, endtime: 40963685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:24,1608760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963453, endtime: 40963685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:24,1608848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963455, endtime: 40963685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:24,1608918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963456, endtime: 40963685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:24,1608995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963458, endtime: 40963685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:24,1609059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963461, endtime: 40963685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:24,1609139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963462, endtime: 40963685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:24,1609203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963464, endtime: 40963685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:24,1609541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963466, endtime: 40963685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:24,1609605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963467, endtime: 40963685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:24,1609677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963469, endtime: 40963685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:24,1609738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963470, endtime: 40963685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,8309017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963617, endtime: 40963852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,8309199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963619, endtime: 40963852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,8309274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963622, endtime: 40963852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,8309349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963623, endtime: 40963852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,8309407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963625, endtime: 40963852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,8309474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963626, endtime: 40963852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,8309532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963628, endtime: 40963852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,8309598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963631, endtime: 40963852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,8309651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963635, endtime: 40963852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,8309950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963639, endtime: 40963852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,8310008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963641, endtime: 40963852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,8310075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963642, endtime: 40963852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,8310249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963644, endtime: 40963852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,9187606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963685, endtime: 40963860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,9187819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963686, endtime: 40963860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,9187899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963687, endtime: 40963860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,9187977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963691, endtime: 40963860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,9188041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963692, endtime: 40963860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,9188110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963694, endtime: 40963860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,9188168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963695, endtime: 40963860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,9188243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963697, endtime: 40963860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,9188301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963700, endtime: 40963860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,9188794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963703, endtime: 40963860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,9188869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963706, endtime: 40963860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,9188941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963708, endtime: 40963860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:25,9189002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963709, endtime: 40963860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,1315391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963626, endtime: 40963882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,1315568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963628, endtime: 40963882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,1315645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963631, endtime: 40963882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,1315723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963635, endtime: 40963882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,1315781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963639, endtime: 40963882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,1315850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963641, endtime: 40963882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,1315906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963642, endtime: 40963882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,1315975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963644, endtime: 40963882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,1316031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963647, endtime: 40963882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,1316526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963648, endtime: 40963882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,1316601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963650, endtime: 40963882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,1316679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963653, endtime: 40963882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,1316745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963655, endtime: 40963882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,6562608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963458, endtime: 40963934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,6562802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963461, endtime: 40963934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,6562885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963462, endtime: 40963934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,6562962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963464, endtime: 40963934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,6563026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963466, endtime: 40963934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,6563098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963467, endtime: 40963934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,6563159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963469, endtime: 40963934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,6563231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963470, endtime: 40963934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,6563292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963472, endtime: 40963934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,6563594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963473, endtime: 40963934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,6563658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963475, endtime: 40963934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,6563730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963477, endtime: 40963934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:26,6563791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963478, endtime: 40963934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,3003593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963609, endtime: 40963999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,3003801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963612, endtime: 40963999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,3003886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963616, endtime: 40963999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,3003978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963619, endtime: 40963999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,3004050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963622, endtime: 40963999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,3004133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963623, endtime: 40963999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,3004202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963625, endtime: 40963999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,3004280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963626, endtime: 40963999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,3004349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963628, endtime: 40963999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,3004684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963631, endtime: 40963999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,3004748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963635, endtime: 40963999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,3004826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963639, endtime: 40963999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,3004887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963641, endtime: 40963999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,5541656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963852, endtime: 40964024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,5541856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963853, endtime: 40964024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,5541933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963855, endtime: 40964024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,5542014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963858, endtime: 40964024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,5542074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963859, endtime: 40964024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,5542144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963862, endtime: 40964024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,5542199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963864, endtime: 40964024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,5542268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963866, endtime: 40964024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,5542327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963867, endtime: 40964024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,5542629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963869, endtime: 40964024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,5542687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963870, endtime: 40964024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,5542756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963874, endtime: 40964024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:27,5542811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963875, endtime: 40964024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,1869710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963350, endtime: 40964087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,1869924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963352, endtime: 40964087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,1870023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963355, endtime: 40964087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,1870101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963356, endtime: 40964087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,1870179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963359, endtime: 40964087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,1870248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963361, endtime: 40964087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,1870325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963363, endtime: 40964087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,1870386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963366, endtime: 40964087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,1870464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963371, endtime: 40964087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,1871126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963373, endtime: 40964087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,1871218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963374, endtime: 40964087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,1871279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963375, endtime: 40964087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,4510260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54963 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,5374818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,5378894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964122, endtime: 40964122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,5476254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964123, endtime: 40964123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,5642466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964125, endtime: 40964125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,5956354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964128, endtime: 40964128, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,6288951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964131, endtime: 40964131, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,6417114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964133, endtime: 40964133, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,6722100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964136, endtime: 40964136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,6898871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964137, endtime: 40964138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,7178304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964140, endtime: 40964140, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,7368902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964142, endtime: 40964142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,7522673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964144, endtime: 40964144, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,7685070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964145, endtime: 40964145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,7999844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964148, endtime: 40964149, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8146374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964150, endtime: 40964150, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8461802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964153, endtime: 40964153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8585361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963934, endtime: 40964154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8585521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963936, endtime: 40964154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8585593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963939, endtime: 40964154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8585665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963941, endtime: 40964154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8585721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963942, endtime: 40964154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8585784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963945, endtime: 40964154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8585840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963947, endtime: 40964154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8585904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963950, endtime: 40964154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8585962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963954, endtime: 40964154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8607669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963955, endtime: 40964155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8607777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963957, endtime: 40964155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8607858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963958, endtime: 40964155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8607916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963961, endtime: 40964155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8608071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964155, endtime: 40964155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8776488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964156, endtime: 40964156, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,8931284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964158, endtime: 40964158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,9087109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964159, endtime: 40964159, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,9409173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964162, endtime: 40964163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,9767135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964165, endtime: 40964166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:28,9861447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964167, endtime: 40964167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:29,0022198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964169, endtime: 40964169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:29,0346672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964172, endtime: 40964172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:29,0652088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964175, endtime: 40964175, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:29,0804582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964177, endtime: 40964177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:29,1120252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964180, endtime: 40964180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:29,1279877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964181, endtime: 40964181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:29,1459169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54935 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:29,1572183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964184, endtime: 40964184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:29,1752726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964186, endtime: 40964186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:29,2083769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964189, endtime: 40964189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:29,2374878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964192, endtime: 40964192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:29,2517877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964194, endtime: 40964194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:29,3065678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964199, endtime: 40964199, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:30,7151870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964202, endtime: 40964340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:30,7152025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964205, endtime: 40964340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:30,7152094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964206, endtime: 40964340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:30,7152164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964208, endtime: 40964340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:30,9276566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54959 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,0872428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963860, endtime: 40964377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,0872613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963862, endtime: 40964377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,0872830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963864, endtime: 40964377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,0872921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963866, endtime: 40964377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,0872990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963867, endtime: 40964377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,0873068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963869, endtime: 40964377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,0873131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963870, endtime: 40964377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,0873209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963874, endtime: 40964377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,0873273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963875, endtime: 40964377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,0873630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963878, endtime: 40964377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,0873697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963881, endtime: 40964377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,0873766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963883, endtime: 40964377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,0873830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963887, endtime: 40964377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,3736195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,3736320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,3740601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40964406, endtime: 40964406, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:31,9943149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54931 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0889816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40963376, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0890018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964087, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0890112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964089, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0890182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964091, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0890256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964092, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0890317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964095, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0890389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964097, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0890450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964100, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0890522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964101, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0890580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964102, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0890913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964105, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0890977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964106, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0891049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964108, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,0892827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964478, endtime: 40964478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,1563475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,8503743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964154, endtime: 40964554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,8503956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964156, endtime: 40964554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,8504036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964158, endtime: 40964554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,8504119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964159, endtime: 40964554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,8504183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964162, endtime: 40964554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,8504252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964165, endtime: 40964554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,8504311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964167, endtime: 40964554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,8504383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964169, endtime: 40964554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,8504441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964172, endtime: 40964554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,8504748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964175, endtime: 40964554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,8504812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964177, endtime: 40964554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,8504881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964180, endtime: 40964554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:32,8504940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964181, endtime: 40964554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,8568884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964480, endtime: 40964654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,8569034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964481, endtime: 40964654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,8569103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964483, endtime: 40964654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,8569172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964484, endtime: 40964654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,8569225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964486, endtime: 40964654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,8569289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964489, endtime: 40964654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,8569341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964491, endtime: 40964654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,8569405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964494, endtime: 40964654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,8569460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964495, endtime: 40964654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,8570267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964497, endtime: 40964654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,8570336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964498, endtime: 40964654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,8570400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964500, endtime: 40964654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,8571228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964501, endtime: 40964654, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:33,9383163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,0330005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,0341702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964672, endtime: 40964672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,0481673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964673, endtime: 40964673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,0794741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964676, endtime: 40964677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,0966555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964678, endtime: 40964678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,1107224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964680, endtime: 40964680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,1260791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964681, endtime: 40964681, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,1433026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964683, endtime: 40964683, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,1573244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964684, endtime: 40964684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,1730789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964686, endtime: 40964686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,1885497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964687, endtime: 40964687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,2160719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964689, endtime: 40964690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,2362563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964692, endtime: 40964692, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,2612608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964694, endtime: 40964695, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,2676401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964695, endtime: 40964695, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,2825717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964697, endtime: 40964697, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,3004784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964698, endtime: 40964699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,3147681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964700, endtime: 40964700, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,3202389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964701, endtime: 40964701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,3260424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964701, endtime: 40964701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,3453332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964703, endtime: 40964703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,3621198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964705, endtime: 40964705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,3763760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964706, endtime: 40964706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,3952263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964708, endtime: 40964708, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,4232026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964711, endtime: 40964711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,4420391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964712, endtime: 40964713, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,4558916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964714, endtime: 40964714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,5291591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964716, endtime: 40964722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,5291790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964719, endtime: 40964722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,5291871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964720, endtime: 40964722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,5326627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964722, endtime: 40964722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,5497053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964723, endtime: 40964724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,5676361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964725, endtime: 40964725, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,5792769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964726, endtime: 40964727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,5952652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964728, endtime: 40964728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,6107607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964730, endtime: 40964730, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,6278226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964731, endtime: 40964731, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,6442246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964733, endtime: 40964733, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,6572598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964734, endtime: 40964734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,8628490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964554, endtime: 40964755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,8628689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964555, endtime: 40964755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,8628775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964556, endtime: 40964755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,8628858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964558, endtime: 40964755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,8628922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964559, endtime: 40964755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,8629000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964561, endtime: 40964755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,8629061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964562, endtime: 40964755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,8629135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964564, endtime: 40964755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,8629194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964566, endtime: 40964755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,8629975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964567, endtime: 40964755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,8630058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964569, endtime: 40964755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,8630130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964572, endtime: 40964755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:34,8630934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964573, endtime: 40964755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,0005766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,6687468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964654, endtime: 40964835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,6687682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964656, endtime: 40964835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,6687765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964658, endtime: 40964835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,6687848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964659, endtime: 40964835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,6688042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964661, endtime: 40964835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,6688175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964662, endtime: 40964835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,6688247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964666, endtime: 40964835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,6688330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964667, endtime: 40964835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,6688399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964669, endtime: 40964835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,6689183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964670, endtime: 40964836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,6689267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964672, endtime: 40964836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,6689347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964673, endtime: 40964836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:35,8867617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964677, endtime: 40964857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,1216044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964209, endtime: 40964881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,1216229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964211, endtime: 40964881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,1216324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964212, endtime: 40964881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,1216390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964214, endtime: 40964881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,1216468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964216, endtime: 40964881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,1216529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964217, endtime: 40964881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,1216723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964220, endtime: 40964881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,1216792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964222, endtime: 40964881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,1216872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964223, endtime: 40964881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,1216936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964340, endtime: 40964881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,1217282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964342, endtime: 40964881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,1217346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964345, endtime: 40964881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,1217418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964347, endtime: 40964881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,9385388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964755, endtime: 40964962, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,9385612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964756, endtime: 40964962, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,9385842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964759, endtime: 40964962, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,9386005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964761, endtime: 40964962, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,9386116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964762, endtime: 40964962, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,9386233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964764, endtime: 40964962, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,9386302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964766, endtime: 40964962, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,9386385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964767, endtime: 40964962, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,9386454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964769, endtime: 40964962, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,9387363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964770, endtime: 40964962, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,9387443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964772, endtime: 40964962, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,9387518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964775, endtime: 40964962, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:36,9388064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964777, endtime: 40964962, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,3810934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964881, endtime: 40965007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,3811086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964883, endtime: 40965007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,3811158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964885, endtime: 40965007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,3811228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964887, endtime: 40965007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,3811283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964887, endtime: 40965007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,3811375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964889, endtime: 40965007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,3811455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964891, endtime: 40965007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,3811555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964892, endtime: 40965007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,3811632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964894, endtime: 40965007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,3811984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964895, endtime: 40965007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,3812073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964897, endtime: 40965007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,3813588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964900, endtime: 40965007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,3813699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964903, endtime: 40965007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,9809524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964836, endtime: 40965067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,9809707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964837, endtime: 40965067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,9809801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964841, endtime: 40965067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,9809874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964842, endtime: 40965067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,9809948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964847, endtime: 40965067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,9810009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964848, endtime: 40965067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,9810081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964850, endtime: 40965067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,9810142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964853, endtime: 40965067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,9810212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964855, endtime: 40965067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,9811026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964856, endtime: 40965067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,9811117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964859, endtime: 40965067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,9811178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964860, endtime: 40965067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:37,9811968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964861, endtime: 40965067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,1566187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,2536052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,2543608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965094, endtime: 40965094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,2675919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965095, endtime: 40965095, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,2988111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965098, endtime: 40965098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,3141553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965100, endtime: 40965100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,3209553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965101, endtime: 40965101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,3458012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965103, endtime: 40965103, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,3771495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965106, endtime: 40965106, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,3914140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965108, endtime: 40965108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,4090644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965109, endtime: 40965110, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,4248547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965111, endtime: 40965111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,4392369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965112, endtime: 40965113, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,4741499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965115, endtime: 40965116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,4861636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965117, endtime: 40965117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,5168650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965120, endtime: 40965120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,5362027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965122, endtime: 40965122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,5752271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965125, endtime: 40965126, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,6146871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965130, endtime: 40965130, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,6284033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965131, endtime: 40965131, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,6449020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965133, endtime: 40965133, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,6771993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965136, endtime: 40965136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,6889204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965137, endtime: 40965138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,7054490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965139, endtime: 40965139, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,7204026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965141, endtime: 40965141, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,7526674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965144, endtime: 40965144, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,7687475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965145, endtime: 40965145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,7868786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965147, endtime: 40965147, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9846387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964962, endtime: 40965167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9846669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964964, endtime: 40965167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9846800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964967, endtime: 40965167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9846933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964969, endtime: 40965167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9847043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964970, endtime: 40965167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9847129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964972, endtime: 40965167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9847193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964973, endtime: 40965167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9847268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964977, endtime: 40965167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9847331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964978, endtime: 40965167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9848041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964980, endtime: 40965167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9848118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964981, endtime: 40965167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9848190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964984, endtime: 40965167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9989680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965148, endtime: 40965169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9989857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965150, endtime: 40965169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9989932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965153, endtime: 40965169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9990010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965155, endtime: 40965169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9990068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965156, endtime: 40965169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9990137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965159, endtime: 40965169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9990193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965161, endtime: 40965169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9990259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965162, endtime: 40965169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9990315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965164, endtime: 40965169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:38,9990583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965166, endtime: 40965169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,0099023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965169, endtime: 40965170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,0162577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965170, endtime: 40965170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,0327830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965172, endtime: 40965172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,1353317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964986, endtime: 40965182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,7283089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964736, endtime: 40965241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,7283289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964737, endtime: 40965241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,7283369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964739, endtime: 40965241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,7283596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964741, endtime: 40965241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,7283676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964742, endtime: 40965241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,7283760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964744, endtime: 40965241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,7283829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964745, endtime: 40965241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,7283912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964748, endtime: 40965241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,7283981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964750, endtime: 40965241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,7284339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964753, endtime: 40965241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,7284405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964755, endtime: 40965241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,7284483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964756, endtime: 40965241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:39,7284546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40964759, endtime: 40965241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,0009016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,0972725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,0981028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965378, endtime: 40965378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,1270951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965381, endtime: 40965381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,1417973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965383, endtime: 40965383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,1576765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965384, endtime: 40965384, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,1730853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965386, endtime: 40965386, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,1897128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965387, endtime: 40965388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,2046428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965389, endtime: 40965389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,2198942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965391, endtime: 40965391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,2357274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965392, endtime: 40965392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,2510148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965394, endtime: 40965394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,2669862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965395, endtime: 40965395, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,2826692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965397, endtime: 40965397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,2980952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965398, endtime: 40965398, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,3136588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965400, endtime: 40965400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,3192814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965401, endtime: 40965401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,3453934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965403, endtime: 40965403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,3608176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965405, endtime: 40965405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,3765533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965406, endtime: 40965406, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4062387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965408, endtime: 40965409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4231824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965411, endtime: 40965411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4431698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965412, endtime: 40965413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4544714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965414, endtime: 40965414, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4596094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965167, endtime: 40965415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4596236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965169, endtime: 40965415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4596321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965170, endtime: 40965415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4596385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965172, endtime: 40965415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4596454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965173, endtime: 40965415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4596513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965175, endtime: 40965415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4596579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965178, endtime: 40965415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4596635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965180, endtime: 40965415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4596701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965181, endtime: 40965415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4597335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965184, endtime: 40965415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4597421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965189, endtime: 40965415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4597480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965191, endtime: 40965415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4699422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965416, endtime: 40965416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,4871189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965417, endtime: 40965417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,5030840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965419, endtime: 40965419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,6274744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,6274860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,6278556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40965431, endtime: 40965431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7553634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965420, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7553817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965422, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7553895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965423, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7553975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965425, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7554039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965426, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7554111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965428, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7554172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965430, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7554244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965431, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7554302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965433, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7554668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965434, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7554729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965436, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7554798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965438, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7554856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965439, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7554997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965067, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7555069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965069, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7555130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965070, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7555202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965072, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7555263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965073, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7556244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965075, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7556333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965076, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7556402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965078, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7556460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965080, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7556530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965081, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7556585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965083, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,7556654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965084, endtime: 40965444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:41,8275745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965086, endtime: 40965451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,6908551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965241, endtime: 40965538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,6908734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965242, endtime: 40965538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,6908809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965244, endtime: 40965538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,6908881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965247, endtime: 40965538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,6909069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965248, endtime: 40965538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,6909205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965250, endtime: 40965538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,6909280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965253, endtime: 40965538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,6909357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965255, endtime: 40965538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,6909415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965256, endtime: 40965538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,6909728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965258, endtime: 40965538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,6909789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965259, endtime: 40965538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,6909856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965261, endtime: 40965538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,6909911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965262, endtime: 40965538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,9310505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965192, endtime: 40965562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,9310688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965415, endtime: 40965562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,9310782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965416, endtime: 40965562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,9310848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965417, endtime: 40965562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,9310923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965419, endtime: 40965562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,9310984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965420, endtime: 40965562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,9311056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965422, endtime: 40965562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,9311114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965423, endtime: 40965562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,9311184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965425, endtime: 40965562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,9311242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965426, endtime: 40965562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,9311533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965428, endtime: 40965562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,9311597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965430, endtime: 40965562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:42,9311666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965431, endtime: 40965562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,0201800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965007, endtime: 40965571, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,0201966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965008, endtime: 40965571, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,0202038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965009, endtime: 40965571, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,0202110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965012, endtime: 40965571, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,0202165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965014, endtime: 40965571, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,0202229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965016, endtime: 40965571, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,0202285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965017, endtime: 40965571, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,0203977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965019, endtime: 40965571, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,0204102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965020, endtime: 40965571, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,0204182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965022, endtime: 40965571, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,0204246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965023, endtime: 40965571, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,0204318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965025, endtime: 40965571, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,0204379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965027, endtime: 40965571, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,9758837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965538, endtime: 40965666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,9759042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965539, endtime: 40965666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,9759120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965541, endtime: 40965666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,9759194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965542, endtime: 40965666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,9759253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965544, endtime: 40965666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,9759322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965547, endtime: 40965666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,9759377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965548, endtime: 40965666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,9759444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965550, endtime: 40965666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,9759499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965553, endtime: 40965666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,9759779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965555, endtime: 40965666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,9759840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965558, endtime: 40965666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,9759906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965559, endtime: 40965666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:43,9759962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965561, endtime: 40965666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,5139756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965444, endtime: 40965720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,5139936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965447, endtime: 40965720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,5140171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965448, endtime: 40965720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,5140304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965450, endtime: 40965720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,5140429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965452, endtime: 40965720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,5140512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965457, endtime: 40965720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,5140590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965458, endtime: 40965720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,5140653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965461, endtime: 40965720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,5140728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965462, endtime: 40965720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,5141654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965464, endtime: 40965720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,5141740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965466, endtime: 40965720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,5141798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965467, endtime: 40965720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,5142341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965470, endtime: 40965720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,6969498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965571, endtime: 40965738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,6969708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965572, endtime: 40965738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,6969791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965575, endtime: 40965738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,6969872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965576, endtime: 40965738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,6969935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965579, endtime: 40965738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,6970007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965581, endtime: 40965738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,6970066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965583, endtime: 40965738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,6970140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965587, endtime: 40965738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,6970348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965589, endtime: 40965738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,6970839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965592, endtime: 40965738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,6970908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965594, endtime: 40965738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,6970977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965595, endtime: 40965738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:44,6971038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965599, endtime: 40965738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:45,5488650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965562, endtime: 40965823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:45,5488833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965564, endtime: 40965823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:45,5488907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965566, endtime: 40965823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:45,5488979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965567, endtime: 40965823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:45,5489038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965569, endtime: 40965823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:45,5489104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965570, endtime: 40965823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:45,5489160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965572, endtime: 40965823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:45,5489232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965575, endtime: 40965823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:45,5489287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965576, endtime: 40965823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:45,5489592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965580, endtime: 40965824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:45,5489653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965581, endtime: 40965824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:45,5489719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965583, endtime: 40965824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:45,5489772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965587, endtime: 40965824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:46,1536113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965173, endtime: 40965884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:46,1536262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965175, endtime: 40965884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:46,1536348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965178, endtime: 40965884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:46,1536412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965180, endtime: 40965884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:46,1536481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965181, endtime: 40965884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:46,1536537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965184, endtime: 40965884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:46,1536603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965189, endtime: 40965884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:46,1536656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965191, endtime: 40965884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:46,1536722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965192, endtime: 40965884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:46,1537348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965194, endtime: 40965884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:46,1537429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965196, endtime: 40965884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:46,1537484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965197, endtime: 40965884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1882466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965666, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1882654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965667, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1882729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965669, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1882807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965670, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1882865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965672, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1882937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965673, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1882992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965676, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1883062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965678, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1883117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965680, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1883447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965681, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1883511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965684, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1883577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965686, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1883635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965688, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1883732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965200, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1883793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965884, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1883860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965886, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1883918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965887, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1883984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965893, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1884043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965894, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1884627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965897, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1884702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965899, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1884768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965900, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1884827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965903, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1884893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965906, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1884948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965907, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,1885015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965909, endtime: 40966087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,5410578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965738, endtime: 40966123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,5410822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965739, endtime: 40966123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,5410941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965741, endtime: 40966123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,5411032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965744, endtime: 40966123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,5411096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965745, endtime: 40966123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,5411168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965749, endtime: 40966123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,5411229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965750, endtime: 40966123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,5411298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965753, endtime: 40966123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,5411357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965755, endtime: 40966123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,5411656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965756, endtime: 40966123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,5411720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965758, endtime: 40966123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,5411792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965759, endtime: 40966123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:48,5411850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965761, endtime: 40966123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:49,1373619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965824, endtime: 40966182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:49,1373813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965825, endtime: 40966182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:49,1373894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965828, endtime: 40966182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:49,1373971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965830, endtime: 40966182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:49,1374035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965831, endtime: 40966182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:49,1374107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965833, endtime: 40966182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:49,1374165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965838, endtime: 40966182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:49,1374234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965841, endtime: 40966182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:49,1374293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965842, endtime: 40966182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:49,1374584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965846, endtime: 40966182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:49,1374647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965848, endtime: 40966182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:49,1374717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965850, endtime: 40966182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:49,1374775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965851, endtime: 40966182, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,1347443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965720, endtime: 40966282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,1347573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965722, endtime: 40966282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,1347648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965726, endtime: 40966282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,1347720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965728, endtime: 40966282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,1347776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965730, endtime: 40966282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,1347842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965730, endtime: 40966282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,1347895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965733, endtime: 40966282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,1349419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965736, endtime: 40966282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,1350865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965737, endtime: 40966282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,1350965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965739, endtime: 40966282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,1351028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965741, endtime: 40966282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,1351100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965744, endtime: 40966282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,1351158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965745, endtime: 40966282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,2664058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966087, endtime: 40966295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,2664249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966089, endtime: 40966295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,2664329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966092, endtime: 40966295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,2664407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966094, endtime: 40966295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,2664471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966097, endtime: 40966295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,2664543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966099, endtime: 40966295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,2664601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966101, endtime: 40966295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,2664673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966105, endtime: 40966295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,2664731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966108, endtime: 40966295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,2665055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966109, endtime: 40966295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,2665119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966111, endtime: 40966295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,2665188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966114, endtime: 40966295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,2665249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966116, endtime: 40966295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,5758882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966123, endtime: 40966326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,5759104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966123, endtime: 40966326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,5759195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966128, endtime: 40966326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,5759273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966131, endtime: 40966326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,5759339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966131, endtime: 40966326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,5759447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966133, endtime: 40966326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,5759511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966136, endtime: 40966326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,5759583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966139, endtime: 40966326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,5759638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966141, endtime: 40966326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,5759965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966142, endtime: 40966326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,5760026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966144, endtime: 40966326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,5760095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966145, endtime: 40966326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,5764972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966147, endtime: 40966326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,7733230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54996 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,8777114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,8782782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966356, endtime: 40966356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,8917426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966358, endtime: 40966358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,9229494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966361, endtime: 40966361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,9395977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966363, endtime: 40966363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,9784326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966366, endtime: 40966366, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:50,9850540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966367, endtime: 40966367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,0032704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966369, endtime: 40966369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,0317518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966372, endtime: 40966372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,0567915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966374, endtime: 40966374, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,1255926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966381, endtime: 40966381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,1429491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966383, endtime: 40966383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,1753463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966386, endtime: 40966386, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,2057266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966389, endtime: 40966389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,2204477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966391, endtime: 40966391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,2360147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966392, endtime: 40966392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,2722453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966395, endtime: 40966396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,2838163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966397, endtime: 40966397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3048919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966398, endtime: 40966399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3150233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966400, endtime: 40966400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3204287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966401, endtime: 40966401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3262291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966401, endtime: 40966401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3375618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965444, endtime: 40966402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3375782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965447, endtime: 40966402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3375870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965448, endtime: 40966402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3375937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965450, endtime: 40966402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3376009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965452, endtime: 40966402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3376067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965457, endtime: 40966402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3376139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965458, endtime: 40966402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3398478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965461, endtime: 40966403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3398630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965462, endtime: 40966403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3398702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965464, endtime: 40966403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3398774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965466, endtime: 40966403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3398833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965467, endtime: 40966403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3398896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40965470, endtime: 40966403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3449160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966403, endtime: 40966403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3612667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966405, endtime: 40966405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3763818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966406, endtime: 40966406, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,3957923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966408, endtime: 40966408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,4075991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966409, endtime: 40966409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,4381988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966412, endtime: 40966412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,4549233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966414, endtime: 40966414, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,4726219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966416, endtime: 40966416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,4882933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966417, endtime: 40966417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,5116126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966419, endtime: 40966420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,5345459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966422, endtime: 40966422, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,5483062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966423, endtime: 40966423, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,5658818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966425, endtime: 40966425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,5811952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966427, endtime: 40966427, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,6122690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966430, endtime: 40966430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7676270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7676390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7679349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40966445, endtime: 40966445, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7867935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966295, endtime: 40966447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7868207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966297, endtime: 40966447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7868323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966298, endtime: 40966447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7868448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966300, endtime: 40966447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7868547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966301, endtime: 40966447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7868664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966301, endtime: 40966447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7868761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966305, endtime: 40966447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7868877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966306, endtime: 40966447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7868980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966308, endtime: 40966447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7869586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966310, endtime: 40966447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7869705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966312, endtime: 40966447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7869825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966314, endtime: 40966447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:51,7869927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966316, endtime: 40966447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,2096400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966447, endtime: 40966490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,4048981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966282, endtime: 40966509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,4049191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966284, endtime: 40966509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,4049274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966286, endtime: 40966509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,4049352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966290, endtime: 40966509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,4049413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966292, endtime: 40966509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,4049485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966294, endtime: 40966509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,4049543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966297, endtime: 40966509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,4049612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966298, endtime: 40966509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,4049673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966300, endtime: 40966509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,4050443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966301, endtime: 40966509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,4050518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966301, endtime: 40966509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,4050588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966305, endtime: 40966509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:52,4052560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966306, endtime: 40966509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,2225777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966087, endtime: 40966591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,2225980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966089, endtime: 40966591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,2226057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966092, endtime: 40966591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,2226132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966094, endtime: 40966591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,2226190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966097, endtime: 40966591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,2226259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966099, endtime: 40966591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,2226318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966101, endtime: 40966591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,2226384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966105, endtime: 40966591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,2226442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966108, endtime: 40966591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,2226750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966109, endtime: 40966591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,2226813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966111, endtime: 40966591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,2226880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966114, endtime: 40966591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,2226941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966116, endtime: 40966591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,3761737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55005 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,5649730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966402, endtime: 40966625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,5649932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966403, endtime: 40966625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,5650013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966405, endtime: 40966625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,5650093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966406, endtime: 40966625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,5650154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966408, endtime: 40966625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,5650229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966409, endtime: 40966625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,5650287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966412, endtime: 40966625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,5650356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966414, endtime: 40966625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,5650414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966416, endtime: 40966625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,5651032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966417, endtime: 40966625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,5651124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966419, endtime: 40966625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,5651196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966420, endtime: 40966625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,5651257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966422, endtime: 40966625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,7875407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55007 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,8738913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,8742418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966656, endtime: 40966656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,9071292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966659, endtime: 40966659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,9230746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966661, endtime: 40966661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,9386645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966662, endtime: 40966662, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,9551563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966664, endtime: 40966664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,9797029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966667, endtime: 40966667, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:53,9852906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966667, endtime: 40966667, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,0011252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966669, endtime: 40966669, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,0173424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966670, endtime: 40966670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,0320008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966672, endtime: 40966672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,0495598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966673, endtime: 40966674, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,0633930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966675, endtime: 40966675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,0795351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966677, endtime: 40966677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,1108865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966680, endtime: 40966680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,1260871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966681, endtime: 40966681, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,1420644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966683, endtime: 40966683, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,1655782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966684, endtime: 40966685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,1828277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966686, endtime: 40966687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,1881848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966687, endtime: 40966687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,2042984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966689, endtime: 40966689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,2207785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966691, endtime: 40966691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,2409754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966692, endtime: 40966693, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,2679623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966695, endtime: 40966695, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,3035033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966698, endtime: 40966699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,3306850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966701, endtime: 40966702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,3607173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966705, endtime: 40966705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,3769794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966706, endtime: 40966706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,3828114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966707, endtime: 40966707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,4091287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966709, endtime: 40966710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,4229979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966711, endtime: 40966711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,4389480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966712, endtime: 40966713, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,4553949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966714, endtime: 40966714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,4711710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966716, endtime: 40966716, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,5121528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966431, endtime: 40966720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,5121703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966433, endtime: 40966720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,5151963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966720, endtime: 40966720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,5507573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966723, endtime: 40966724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,5884048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966727, endtime: 40966727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:54,6113040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966730, endtime: 40966730, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:55,3931725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966509, endtime: 40966808, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:55,3931938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966511, endtime: 40966808, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:55,3932021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966512, endtime: 40966808, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:55,3932102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966514, endtime: 40966808, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:55,3932165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966516, endtime: 40966808, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:55,3932238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966517, endtime: 40966808, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:55,3932298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966519, endtime: 40966808, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:55,3932368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966520, endtime: 40966808, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:55,3932429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966522, endtime: 40966808, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:55,3933171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966526, endtime: 40966808, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:55,3933249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966528, endtime: 40966808, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:55,3933321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966530, endtime: 40966808, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,3812031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:54950 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,3906416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,4696383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,4702855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966916, endtime: 40966916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,4864110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966917, endtime: 40966917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,5017893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966919, endtime: 40966919, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,5164868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966920, endtime: 40966920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,5322408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966922, endtime: 40966922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,5474553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966923, endtime: 40966923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,5642233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966925, endtime: 40966925, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,5797517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966927, endtime: 40966927, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,6101016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966930, endtime: 40966930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,6254120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966931, endtime: 40966931, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,6422176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966933, endtime: 40966933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,6573177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966934, endtime: 40966934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,6731700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966936, endtime: 40966936, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,6888137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966937, endtime: 40966937, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7041704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966939, endtime: 40966939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7200036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966941, endtime: 40966941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7329116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966591, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7329299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966592, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7329374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966594, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7329449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966596, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7329507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966600, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7329576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966600, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7329632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966601, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7329698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966601, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7329754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966602, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7330061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966605, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7330122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966606, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7330308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966608, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7330374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966611, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7354985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966942, endtime: 40966942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7507311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966944, endtime: 40966944, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7800164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966945, endtime: 40966947, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,7993444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966948, endtime: 40966949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,8162019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966950, endtime: 40966950, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,8327521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966951, endtime: 40966952, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,8468382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966953, endtime: 40966953, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,8603477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966955, endtime: 40966955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,8766976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966956, endtime: 40966956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:56,8928677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966958, endtime: 40966958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,5934840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966959, endtime: 40967028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,5935048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966961, endtime: 40967028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,5935137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966963, endtime: 40967028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,5935223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966966, endtime: 40967028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,5935289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966967, endtime: 40967028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,5935369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966969, endtime: 40967028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,5935433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966970, endtime: 40967028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,5935511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966972, endtime: 40967028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,5935572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966973, endtime: 40967028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,5935918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966975, endtime: 40967028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,5935982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966978, endtime: 40967028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,5936054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966980, endtime: 40967028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,5936115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966983, endtime: 40967028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6773580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966625, endtime: 40967036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6773760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966626, endtime: 40967036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6773835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966628, endtime: 40967036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6773913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966630, endtime: 40967036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6773974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966631, endtime: 40967036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6774154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966633, endtime: 40967036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6774223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966634, endtime: 40967036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6774298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966636, endtime: 40967036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6774356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966637, endtime: 40967036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6774669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966639, endtime: 40967036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6774727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966641, endtime: 40967036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6774797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966642, endtime: 40967036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6775672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966644, endtime: 40967036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6909947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966436, endtime: 40967038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6910152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966437, endtime: 40967038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6910235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966439, endtime: 40967038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6910316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966441, endtime: 40967038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6910382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966442, endtime: 40967038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6910454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966444, endtime: 40967038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6910512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966449, endtime: 40967038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6910584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966450, endtime: 40967038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6910751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966452, endtime: 40967038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6911114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966455, endtime: 40967038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6911177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966458, endtime: 40967038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6911249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966720, endtime: 40967038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,6911308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966723, endtime: 40967038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:57,7519523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966731, endtime: 40967044, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,3913811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,4088154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967036, endtime: 40967209, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,4088359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967037, endtime: 40967209, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,4088444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967039, endtime: 40967209, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,4088528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967041, endtime: 40967209, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,4088591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967042, endtime: 40967209, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,4088663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967044, endtime: 40967209, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,4088957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967045, endtime: 40967209, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,4089051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967047, endtime: 40967209, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,4089115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967048, endtime: 40967209, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,4089470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967050, endtime: 40967210, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,4089533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967052, endtime: 40967210, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,4089603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967053, endtime: 40967210, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,4089664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967055, endtime: 40967210, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,5007683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,5011426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967219, endtime: 40967219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,5169575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967220, endtime: 40967220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,5324004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967222, endtime: 40967222, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,5480848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967223, endtime: 40967223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,5638759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967225, endtime: 40967225, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,5791386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967226, endtime: 40967227, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,5950740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967228, endtime: 40967228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,6104875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967230, endtime: 40967230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,6271907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967231, endtime: 40967231, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,6418683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967233, endtime: 40967233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,6573773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967234, endtime: 40967234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,6730553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967236, endtime: 40967236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,7002257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967237, endtime: 40967239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,7196866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967241, endtime: 40967241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,7365123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967242, endtime: 40967242, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,7799181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967245, endtime: 40967247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,7998473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967249, endtime: 40967249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,8137685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967250, endtime: 40967250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,8303401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967251, endtime: 40967252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,8463703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967253, endtime: 40967253, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,8619430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967255, endtime: 40967255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,8774620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967256, endtime: 40967256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,8932407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967258, endtime: 40967258, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,9075398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967259, endtime: 40967259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,9246463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967261, endtime: 40967261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,9401382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967263, endtime: 40967263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,9718173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967266, endtime: 40967266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:56:59,9854225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967267, endtime: 40967267, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:00,0043817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967269, endtime: 40967269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:00,0177729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967270, endtime: 40967270, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:00,0326525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967272, endtime: 40967272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:00,0493401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967273, endtime: 40967274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:00,0680065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967275, endtime: 40967275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:00,1080164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967278, endtime: 40967279, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:00,1298886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967282, endtime: 40967282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:00,1431785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967283, endtime: 40967283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:00,1599331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967284, endtime: 40967285, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:00,1734623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967286, endtime: 40967286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,0090797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966733, endtime: 40967370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,0090983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966736, endtime: 40967370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,0091077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966738, endtime: 40967370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,0091149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966741, endtime: 40967370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,0091224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966742, endtime: 40967370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,0091285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966744, endtime: 40967370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,0091357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966745, endtime: 40967370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,0091418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966749, endtime: 40967370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,0091490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966750, endtime: 40967370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,0091781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966752, endtime: 40967370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,0091856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966753, endtime: 40967370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,0091914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966755, endtime: 40967370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,0091986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967044, endtime: 40967370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,7799976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,7800095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:01,7802702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40967447, endtime: 40967447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,5473509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966942, endtime: 40967523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,5473683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966944, endtime: 40967523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,5473775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966945, endtime: 40967523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,5473844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966948, endtime: 40967523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,5474018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966950, endtime: 40967523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,5474090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966951, endtime: 40967523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,5474165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966953, endtime: 40967523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,5474226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966955, endtime: 40967523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,5474298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966956, endtime: 40967523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,5474614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966958, endtime: 40967523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,5474686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966959, endtime: 40967523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,5474742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966961, endtime: 40967523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,5474814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40966963, endtime: 40967523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,9963581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967038, endtime: 40967568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,9963883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967039, endtime: 40967568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,9963983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967041, endtime: 40967568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,9964064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967042, endtime: 40967568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,9964127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967044, endtime: 40967568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,9964202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967045, endtime: 40967568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,9964260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967047, endtime: 40967568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,9964335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967048, endtime: 40967568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,9964396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967050, endtime: 40967568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,9964756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967052, endtime: 40967568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,9964812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967053, endtime: 40967568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,9964878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967055, endtime: 40967568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:02,9964933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967056, endtime: 40967568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9503530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967370, endtime: 40967664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9503715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967370, endtime: 40967664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9503796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967372, endtime: 40967664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9503876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967373, endtime: 40967664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9503940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967375, endtime: 40967664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9504012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967376, endtime: 40967664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9504073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967378, endtime: 40967664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9504145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967380, endtime: 40967664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9504209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967381, endtime: 40967664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9504522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967383, endtime: 40967664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9504588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967384, endtime: 40967664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9504657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967386, endtime: 40967664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9504718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967387, endtime: 40967664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9667544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967210, endtime: 40967665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9667708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967211, endtime: 40967665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9667777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967212, endtime: 40967665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9667849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967214, endtime: 40967665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9667904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967216, endtime: 40967665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9667968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967217, endtime: 40967665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9668021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967219, endtime: 40967665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9668087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967220, endtime: 40967665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9668137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967222, endtime: 40967665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9668686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967223, endtime: 40967665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9668752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967225, endtime: 40967665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9668819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967226, endtime: 40967665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:03,9668871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967228, endtime: 40967665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:04,5903392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967028, endtime: 40967728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:04,5903608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967030, endtime: 40967728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:04,5903752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967031, endtime: 40967728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:04,5903832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967033, endtime: 40967728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:04,5903910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967036, endtime: 40967728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:04,5903971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967037, endtime: 40967728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:04,5904048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967039, endtime: 40967728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:04,5904109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967041, endtime: 40967728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:04,5904181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967042, endtime: 40967728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:04,5904965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967044, endtime: 40967728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:04,5905048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967045, endtime: 40967728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:04,5905107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967047, endtime: 40967728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:04,5906852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967048, endtime: 40967728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,8261898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967568, endtime: 40967851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,8262069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967570, endtime: 40967851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,8262141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967574, endtime: 40967851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,8262211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967575, endtime: 40967851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,8262269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967577, endtime: 40967851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,8262335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967580, endtime: 40967851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,8262388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967581, endtime: 40967851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,8262455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967583, endtime: 40967851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,8262507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967584, endtime: 40967851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,8263358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967586, endtime: 40967851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,8263466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967588, endtime: 40967851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,8263582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967589, endtime: 40967851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,8273412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967591, endtime: 40967851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,9541107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967289, endtime: 40967864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,9541287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967291, endtime: 40967864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,9541365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967292, endtime: 40967864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,9541437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967294, endtime: 40967864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,9541492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967295, endtime: 40967864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,9541559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967297, endtime: 40967864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,9541614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967299, endtime: 40967864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,9541678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967300, endtime: 40967864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,9541733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967301, endtime: 40967864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,9542199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967303, endtime: 40967864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,9542268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967305, endtime: 40967864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,9542334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967306, endtime: 40967864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:05,9542390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967308, endtime: 40967864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,1493161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967523, endtime: 40967884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,1493338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967525, endtime: 40967884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,1493416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967527, endtime: 40967884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,1493493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967528, endtime: 40967884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,1493557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967530, endtime: 40967884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,1493626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967530, endtime: 40967884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,1493684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967531, endtime: 40967884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,1493754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967533, endtime: 40967884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,1493917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967534, endtime: 40967884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,1494255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967536, endtime: 40967884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,1494319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967537, endtime: 40967884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,1494388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967539, endtime: 40967884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,1494446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967541, endtime: 40967884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,3600003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967664, endtime: 40967905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,3600147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967666, endtime: 40967905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,3600216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967669, endtime: 40967905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,3600286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967670, endtime: 40967905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,3600341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967672, endtime: 40967905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,3600405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967673, endtime: 40967905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,3600457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967675, endtime: 40967905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,3600521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967676, endtime: 40967905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,3600574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967678, endtime: 40967905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,3600878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967681, endtime: 40967905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,3600934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967685, endtime: 40967905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,3600998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967686, endtime: 40967905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,3601050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967688, endtime: 40967905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,4440821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967665, endtime: 40967913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,4441023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967669, endtime: 40967913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,4441106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967670, endtime: 40967913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,4441187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967672, endtime: 40967913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,4441250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967673, endtime: 40967913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,4441464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967675, endtime: 40967913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,4441586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967676, endtime: 40967913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,4441713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967678, endtime: 40967913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,4441816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967681, endtime: 40967913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,4442159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967685, endtime: 40967913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,4442223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967686, endtime: 40967913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,4442295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967688, endtime: 40967913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,4442353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967691, endtime: 40967913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,5416299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967728, endtime: 40967923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,5416623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967730, endtime: 40967923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,5416718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967732, endtime: 40967923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,5416801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967733, endtime: 40967923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,5416867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967735, endtime: 40967923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,5416942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967737, endtime: 40967923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,5417006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967739, endtime: 40967923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,5417086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967741, endtime: 40967923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,5417147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967742, endtime: 40967923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,5418028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967744, endtime: 40967923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,5418106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967745, endtime: 40967923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,5418200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967747, endtime: 40967923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:06,6172028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967749, endtime: 40967930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,0144715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967884, endtime: 40968070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,0144915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967886, endtime: 40968070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,0144995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967889, endtime: 40968070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,0145073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967891, endtime: 40968070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,0145133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967895, endtime: 40968070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,0145206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967897, endtime: 40968070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,0145264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967899, endtime: 40968070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,0145330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967900, endtime: 40968070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,0145388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967900, endtime: 40968070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,0145707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967903, endtime: 40968070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,0145768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967906, endtime: 40968070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,0145837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967907, endtime: 40968070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,0145895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967909, endtime: 40968070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,1999905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967913, endtime: 40968089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,2000079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967915, endtime: 40968089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,2000151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967917, endtime: 40968089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,2000226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967919, endtime: 40968089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,2000281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967920, endtime: 40968089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,2000348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967925, endtime: 40968089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,2000401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967927, endtime: 40968089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,2000617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967928, endtime: 40968089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,2000694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967930, endtime: 40968089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,2001054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967932, endtime: 40968089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,2001113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967935, endtime: 40968089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,2001179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967936, endtime: 40968089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,2001234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967938, endtime: 40968089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,4679494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967851, endtime: 40968115, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,4679663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967853, endtime: 40968115, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,4679738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967855, endtime: 40968115, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,4679812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967858, endtime: 40968115, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,4679868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967859, endtime: 40968115, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,4679937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967861, endtime: 40968115, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,4679990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967862, endtime: 40968115, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,4680056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967864, endtime: 40968115, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,4680112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967866, endtime: 40968115, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,4680740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967869, endtime: 40968115, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,4680810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967870, endtime: 40968115, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,4680876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967872, endtime: 40968115, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5116633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967905, endtime: 40968120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5116810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967906, endtime: 40968120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5116879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967907, endtime: 40968120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5116954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967909, endtime: 40968120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5117012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967913, endtime: 40968120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5117079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967915, endtime: 40968120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5117134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967917, endtime: 40968120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5117203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967919, endtime: 40968120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5117259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967920, endtime: 40968120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5117580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967925, endtime: 40968120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5117636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967927, endtime: 40968120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5117702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967928, endtime: 40968120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5117758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967930, endtime: 40968120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,5399820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967875, endtime: 40968123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,9406322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967864, endtime: 40968163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,9406508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967866, endtime: 40968163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,9406582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967869, endtime: 40968163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,9406657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967870, endtime: 40968163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,9406718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967872, endtime: 40968163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,9406782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967875, endtime: 40968163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,9406837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967878, endtime: 40968163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,9406904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967880, endtime: 40968163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,9406956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967883, endtime: 40968163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,9407233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967888, endtime: 40968163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,9407292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967889, endtime: 40968163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,9407358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967891, endtime: 40968163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:08,9407414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967895, endtime: 40968163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,2425288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968089, endtime: 40968293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,2425460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968092, endtime: 40968293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,2425532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968094, endtime: 40968293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,2425604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968097, endtime: 40968293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,2425662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968099, endtime: 40968293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,2425731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968100, endtime: 40968293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,2425787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968101, endtime: 40968293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,2425851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968103, endtime: 40968293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,2425906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968105, endtime: 40968293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,2426211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968107, endtime: 40968293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,2426269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968109, endtime: 40968293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,2426333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968112, endtime: 40968293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,2426388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968116, endtime: 40968293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,7053762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968115, endtime: 40968339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,7054003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968119, endtime: 40968339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,7054113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968127, endtime: 40968339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,7054196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968128, endtime: 40968339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,7054285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968130, endtime: 40968339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,7054357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968131, endtime: 40968339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,7054440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968133, endtime: 40968339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,7054510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968135, endtime: 40968339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,7054598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968136, endtime: 40968339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,7055371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968138, endtime: 40968339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,7055560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968139, endtime: 40968339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:10,7055637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968141, endtime: 40968339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,3286955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968070, endtime: 40968401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,3287149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968072, endtime: 40968401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,3287232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968075, endtime: 40968401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,3287312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968077, endtime: 40968401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,3287381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968078, endtime: 40968401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,3287453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968081, endtime: 40968401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,3287511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968083, endtime: 40968401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,3287584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968084, endtime: 40968401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,3287642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968086, endtime: 40968401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,3287935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968088, endtime: 40968401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,3287999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968089, endtime: 40968401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,3288071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968092, endtime: 40968401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,3288129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968094, endtime: 40968401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,4734129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968120, endtime: 40968416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,4734320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968122, endtime: 40968416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,4734401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968127, endtime: 40968416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,4734484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968128, endtime: 40968416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,4734545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968130, endtime: 40968416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,4734617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968131, endtime: 40968416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,4734678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968133, endtime: 40968416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,4734747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968135, endtime: 40968416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,4734805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968136, endtime: 40968416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,4735573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968138, endtime: 40968416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,4735650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968139, endtime: 40968416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,4735722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968141, endtime: 40968416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,4736908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968142, endtime: 40968416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,9383121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,9383227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:11,9396331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40968462, endtime: 40968463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,1465790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968163, endtime: 40968483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,1465982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968164, endtime: 40968483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,1466059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968166, endtime: 40968483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,1466139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968167, endtime: 40968483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,1466203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968169, endtime: 40968483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,1466275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968170, endtime: 40968483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,1466333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968172, endtime: 40968483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,1466403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968173, endtime: 40968483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,1466461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968175, endtime: 40968483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,1466757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968178, endtime: 40968483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,1466821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968180, endtime: 40968483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,1466893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968181, endtime: 40968483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,1466951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968183, endtime: 40968483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,7704203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968293, endtime: 40968546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,7704419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968295, endtime: 40968546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,7704502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968297, endtime: 40968546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,7704580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968298, endtime: 40968546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,7704644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968300, endtime: 40968546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,7704713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968301, endtime: 40968546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,7704771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968301, endtime: 40968546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,7706381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968303, endtime: 40968546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,7706483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968305, endtime: 40968546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,7706561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968306, endtime: 40968546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,7706625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968308, endtime: 40968546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,7706697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968309, endtime: 40968546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:12,7706755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968311, endtime: 40968546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,1970974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967923, endtime: 40968588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,1971182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967925, endtime: 40968588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,1971434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967927, endtime: 40968588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,1971565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967928, endtime: 40968588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,1971667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967930, endtime: 40968588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,1971753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967932, endtime: 40968588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,1971842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967935, endtime: 40968588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,1971930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967936, endtime: 40968588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,1971994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967938, endtime: 40968588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,1972764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967939, endtime: 40968588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,1972850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967941, endtime: 40968588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,1972964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967942, endtime: 40968588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,1974537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40967944, endtime: 40968588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4302947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968142, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4303130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968339, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4303216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968342, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4303279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968344, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4303349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968345, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4303404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968347, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4303470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968350, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4303526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968351, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4303595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968353, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4303651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968355, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4304249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968356, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4304324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968358, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4304487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968359, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:13,4333520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968612, endtime: 40968612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9148834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968416, endtime: 40968760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9149012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968417, endtime: 40968760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9149089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968419, endtime: 40968760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9149167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968422, endtime: 40968760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9149228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968423, endtime: 40968760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9149300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968425, endtime: 40968760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9149361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968427, endtime: 40968760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9149430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968428, endtime: 40968760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9149491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968430, endtime: 40968760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9150300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968431, endtime: 40968760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9150375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968433, endtime: 40968760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9150450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968434, endtime: 40968760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9151721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968436, endtime: 40968760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9983948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968401, endtime: 40968768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9984142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968405, endtime: 40968768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9984219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968406, endtime: 40968768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9984402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968408, endtime: 40968768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9984635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968409, endtime: 40968768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9984715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968411, endtime: 40968768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9984782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968413, endtime: 40968768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9984942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968416, endtime: 40968768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9985020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968417, endtime: 40968768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9985389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968419, endtime: 40968768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9985449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968422, endtime: 40968768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9985519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968423, endtime: 40968768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:14,9985577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968425, endtime: 40968768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:15,9396667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968483, endtime: 40968863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:15,9396844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968484, endtime: 40968863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:15,9396921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968486, endtime: 40968863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:15,9396993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968488, endtime: 40968863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:15,9397049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968491, endtime: 40968863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:15,9397115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968492, endtime: 40968863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:15,9397171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968494, endtime: 40968863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:15,9397237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968495, endtime: 40968863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:15,9397290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968497, endtime: 40968863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:15,9397570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968498, endtime: 40968863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:15,9397631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968500, endtime: 40968863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:15,9397694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968501, endtime: 40968863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:15,9397747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968503, endtime: 40968863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0428271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968588, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0428448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968589, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0428526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968592, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0428603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968594, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0428662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968597, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0428731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968598, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0428786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968600, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0428855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968601, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0428911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968601, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0429260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968603, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0429318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968605, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0429387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968608, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0429443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968612, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0429554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968546, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0429620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968547, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0429676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968548, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0429742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968550, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0429797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968553, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0430479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968555, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0430637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968556, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0430709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968558, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0430767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968559, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0430836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968561, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0430892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968563, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0430961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968566, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,0431017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968569, endtime: 40968873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,1304328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968873, endtime: 40968882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,7458604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968616, endtime: 40968943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,7458776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968617, endtime: 40968943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,7458848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968619, endtime: 40968943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,7458923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968620, endtime: 40968943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,7458981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968622, endtime: 40968943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,7459047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968623, endtime: 40968943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,7459103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968625, endtime: 40968943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,7461605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968627, endtime: 40968943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,7461718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968628, endtime: 40968943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,7461801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968630, endtime: 40968943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,7461862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968631, endtime: 40968943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,7461932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968633, endtime: 40968943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,9749140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968768, endtime: 40968966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,9749331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968770, endtime: 40968966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,9749414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968772, endtime: 40968966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,9749495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968773, endtime: 40968966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,9749561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968775, endtime: 40968966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,9749633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968776, endtime: 40968966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,9749694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968778, endtime: 40968966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,9749766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968780, endtime: 40968966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,9749827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968781, endtime: 40968966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,9750126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968783, endtime: 40968966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,9750190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968784, endtime: 40968966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,9750262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968786, endtime: 40968966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:16,9750323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968787, endtime: 40968966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:17,2319298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968875, endtime: 40968992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:17,2319442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968878, endtime: 40968992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:17,2319525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968880, endtime: 40968992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:17,2319588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968881, endtime: 40968992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:17,2319658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968883, endtime: 40968992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:17,2319713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968885, endtime: 40968992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:17,2319780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968886, endtime: 40968992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:17,2319835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968887, endtime: 40968992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:17,2319899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968889, endtime: 40968992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:17,2320780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968891, endtime: 40968992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:17,2320860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968892, endtime: 40968992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:17,2320918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968894, endtime: 40968992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:17,2322891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968897, endtime: 40968992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,3202591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968760, endtime: 40969101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,3202813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968761, endtime: 40969101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,3202901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968764, endtime: 40969101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,3202987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968766, endtime: 40969101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,3203059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968767, endtime: 40969101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,3203134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968769, endtime: 40969101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,3203198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968770, endtime: 40969101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,3203270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968772, endtime: 40969101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,3203334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968773, endtime: 40969101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,3204312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968775, endtime: 40969101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,3204397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968776, endtime: 40969101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,3204481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968778, endtime: 40969101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,3910599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55037 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,4604273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,4609543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969115, endtime: 40969115, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,4694286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969116, endtime: 40969116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,5030743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969119, endtime: 40969119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,5164882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969120, endtime: 40969120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,5328863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969122, endtime: 40969122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,5740264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969126, endtime: 40969126, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,5948970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969128, endtime: 40969128, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,6115018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969130, endtime: 40969130, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,6565517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969133, endtime: 40969134, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,6749058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969136, endtime: 40969136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,6883541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969137, endtime: 40969137, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,7049910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969139, endtime: 40969139, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,7207857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969140, endtime: 40969141, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,7401032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969142, endtime: 40969143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,7529816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969144, endtime: 40969144, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,7828432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969147, endtime: 40969147, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,8009015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969148, endtime: 40969149, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,8292848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969151, endtime: 40969152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,8457316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969153, endtime: 40969153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,8782522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969156, endtime: 40969156, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,9092952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969159, endtime: 40969160, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,9408192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969162, endtime: 40969163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,9547873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969164, endtime: 40969164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,9712408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969166, endtime: 40969166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:18,9963138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969167, endtime: 40969168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,0167312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969170, endtime: 40969170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,0327375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969172, endtime: 40969172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2104934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968873, endtime: 40969190, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2105108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968875, endtime: 40969190, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2105180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968878, endtime: 40969190, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2105255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968880, endtime: 40969190, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2105319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968881, endtime: 40969190, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2128805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968883, endtime: 40969190, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2128907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968885, endtime: 40969190, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2128991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968886, endtime: 40969190, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2129049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968887, endtime: 40969190, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2129115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968889, endtime: 40969190, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2129171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968891, endtime: 40969190, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2129237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968892, endtime: 40969190, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2129293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968894, endtime: 40969190, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2547952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968634, endtime: 40969194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2548129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968943, endtime: 40969194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2548201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968945, endtime: 40969194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2548273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968949, endtime: 40969194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2548334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968952, endtime: 40969194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2548404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968955, endtime: 40969194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2548459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968956, endtime: 40969194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2548523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968960, endtime: 40969194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2548578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968963, endtime: 40969194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2548850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968964, endtime: 40969194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2548908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968966, endtime: 40969194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2548971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968967, endtime: 40969194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,2549024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968970, endtime: 40969194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,4737853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969173, endtime: 40969216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,4738049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969175, endtime: 40969216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,4738130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969176, endtime: 40969216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,4738207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969178, endtime: 40969216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,4738268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969180, endtime: 40969216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,4738338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969181, endtime: 40969216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,4738396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969184, endtime: 40969216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,4738468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969186, endtime: 40969216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,4738523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969187, endtime: 40969216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,4738809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969189, endtime: 40969216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,4738870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969191, endtime: 40969216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,4739953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969192, endtime: 40969216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,4740055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969195, endtime: 40969216, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,9717991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968863, endtime: 40969266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,9718223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968864, endtime: 40969266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,9718309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968866, endtime: 40969266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,9718395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968867, endtime: 40969266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,9718459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968870, endtime: 40969266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,9718536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968872, endtime: 40969266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,9718600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968873, endtime: 40969266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,9718678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968875, endtime: 40969266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,9718736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968878, endtime: 40969266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,9719789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968880, endtime: 40969266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,9719858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968881, endtime: 40969266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,9719924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968883, endtime: 40969266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:19,9719980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968885, endtime: 40969266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,3346657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968966, endtime: 40969302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,3346843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968967, endtime: 40969302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,3346921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968970, endtime: 40969302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,3346998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968972, endtime: 40969302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,3347059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968975, endtime: 40969302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,3347131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968978, endtime: 40969302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,3347289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968980, endtime: 40969302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,3347375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968981, endtime: 40969302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,3347671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968983, endtime: 40969302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,3348062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968984, endtime: 40969302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,3348123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968986, endtime: 40969302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,3348201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968987, endtime: 40969302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,3348259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968989, endtime: 40969302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,5403998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968992, endtime: 40969323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,5404186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968995, endtime: 40969323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,5404264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968997, endtime: 40969323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,5404342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40968998, endtime: 40969323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,5404400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969000, endtime: 40969323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,5404469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969003, endtime: 40969323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,5404524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969005, endtime: 40969323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,5404594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969008, endtime: 40969323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,5404649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969009, endtime: 40969323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,5405403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969011, endtime: 40969323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,5405480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969014, endtime: 40969323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,5405547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969016, endtime: 40969323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:20,5407977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969017, endtime: 40969323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:21,5078416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969190, endtime: 40969419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:21,5078668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969191, endtime: 40969419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:21,5078762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969192, endtime: 40969419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:21,5078853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969194, endtime: 40969419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:21,5078920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969197, endtime: 40969419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:21,5079000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969198, endtime: 40969419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:21,5079067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969201, endtime: 40969419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:21,5079142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969205, endtime: 40969419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:21,5079208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969205, endtime: 40969419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:21,5079543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969207, endtime: 40969419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:21,5079607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969208, endtime: 40969419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:21,5079682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969209, endtime: 40969419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:21,5079745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969211, endtime: 40969419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,1249196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,1249335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,1252698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40969481, endtime: 40969481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,9879922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969194, endtime: 40969567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,9880118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969197, endtime: 40969567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,9880196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969198, endtime: 40969567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,9880268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969201, endtime: 40969567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,9880326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969205, endtime: 40969567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,9880398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969205, endtime: 40969567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,9880454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969207, endtime: 40969567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,9880520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969208, endtime: 40969567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,9880578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969209, endtime: 40969567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,9880889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969211, endtime: 40969567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,9880947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969212, endtime: 40969567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,9881016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969214, endtime: 40969567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:22,9881069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969216, endtime: 40969567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,0107080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969323, endtime: 40969670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,0107249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969325, endtime: 40969670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,0107324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969326, endtime: 40969670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,0107396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969328, endtime: 40969670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,0107454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969330, endtime: 40969670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,0107518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969331, endtime: 40969670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,0107573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969333, endtime: 40969670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,0107637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969334, endtime: 40969670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,0107692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969338, endtime: 40969670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,0108548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969339, endtime: 40969670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,0108620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969341, endtime: 40969670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,0108687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969342, endtime: 40969670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,0109582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969344, endtime: 40969670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,4621243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969216, endtime: 40969715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,4621431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969217, endtime: 40969715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,4621511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969221, endtime: 40969715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,4621586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969222, endtime: 40969715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,4621647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969225, endtime: 40969715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,4621716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969228, endtime: 40969715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,4621772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969230, endtime: 40969715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,4623833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969231, endtime: 40969715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,4629072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969236, endtime: 40969715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,4629194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969239, endtime: 40969715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,4629269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969241, endtime: 40969715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,4629344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969242, endtime: 40969715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:24,4629408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969246, endtime: 40969715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:25,2599468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55036 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:26,2360188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969567, endtime: 40969892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:26,2360388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969569, endtime: 40969892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:26,2360465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969570, endtime: 40969892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:26,2360537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969572, endtime: 40969892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:26,2360596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969573, endtime: 40969892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:26,2360662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969575, endtime: 40969892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:26,2360717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969576, endtime: 40969892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:26,2360781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969578, endtime: 40969892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:26,2360839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969580, endtime: 40969892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:26,2361374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969581, endtime: 40969892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:26,2361452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969583, endtime: 40969892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:26,2361521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969583, endtime: 40969892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:26,2361576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969584, endtime: 40969892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,0568528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969266, endtime: 40969974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,0568727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969267, endtime: 40969974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,0568821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969269, endtime: 40969974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,0568891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969272, endtime: 40969974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,0568966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969275, endtime: 40969974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,0569026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969277, endtime: 40969974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,0569096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969278, endtime: 40969974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,0569281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969280, endtime: 40969974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,0569389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969281, endtime: 40969974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,0569484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969283, endtime: 40969974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,0569924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969284, endtime: 40969974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,0570016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969286, endtime: 40969974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,0570124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969289, endtime: 40969974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:27,1401887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969974, endtime: 40969983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,1533126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969670, endtime: 40970084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,1533467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969670, endtime: 40970084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,1533558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969673, endtime: 40970084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,1533647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969675, endtime: 40970084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,1533716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969677, endtime: 40970084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,1533799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969678, endtime: 40970084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,1533866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969680, endtime: 40970084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,1533949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969681, endtime: 40970084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,1534018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969683, endtime: 40970084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,1534384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969684, endtime: 40970084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,1534448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969686, endtime: 40970084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,1534522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969689, endtime: 40970084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,1538119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969691, endtime: 40970084, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,2656893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,3405609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,3409075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970103, endtime: 40970103, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,3637791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970105, endtime: 40970105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,3911855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970108, endtime: 40970108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,4067216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970109, endtime: 40970109, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,4221958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970111, endtime: 40970111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,4389934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970112, endtime: 40970113, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,4752008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970116, endtime: 40970116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,5023146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970119, endtime: 40970119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,5171742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970120, endtime: 40970120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,5486854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970123, endtime: 40970123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,5903829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970127, endtime: 40970128, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6119409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970130, endtime: 40970130, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6265116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970131, endtime: 40970131, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6576086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970134, endtime: 40970134, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6655854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969892, endtime: 40970135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6656017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969894, endtime: 40970135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6656089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969895, endtime: 40970135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6656161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969898, endtime: 40970135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6656217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969901, endtime: 40970135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6656283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969902, endtime: 40970135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6656336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969903, endtime: 40970135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6656399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969905, endtime: 40970135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6656452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969906, endtime: 40970135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6656732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969909, endtime: 40970135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6656787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969911, endtime: 40970135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6656851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969913, endtime: 40970135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6656906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969914, endtime: 40970135, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,6870154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970136, endtime: 40970137, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,7058657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970139, endtime: 40970139, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,7290841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970141, endtime: 40970142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,7364272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970142, endtime: 40970142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,7514531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970144, endtime: 40970144, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,7693503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970145, endtime: 40970146, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,8006325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970148, endtime: 40970149, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,8310992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970151, endtime: 40970152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,8453191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970153, endtime: 40970153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,8790077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970156, endtime: 40970157, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,8938083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970158, endtime: 40970158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,9076296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970159, endtime: 40970159, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,9247203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970161, endtime: 40970161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,9389676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970162, endtime: 40970163, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,9549460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970164, endtime: 40970164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,9714444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970166, endtime: 40970166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:28,9916767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970167, endtime: 40970168, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,0012050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970169, endtime: 40970169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,0168356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970170, endtime: 40970170, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,0340114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970172, endtime: 40970172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,0481405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970173, endtime: 40970173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,0655025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970175, endtime: 40970175, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,0795306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970176, endtime: 40970177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,0952635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970178, endtime: 40970178, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,2532284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969715, endtime: 40970194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,2532459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969717, endtime: 40970194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,2532534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969719, endtime: 40970194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,2532611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969720, endtime: 40970194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,2532670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969723, endtime: 40970194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,2532883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969726, endtime: 40970194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,2532985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969728, endtime: 40970194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,2533099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969731, endtime: 40970194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,2533199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969733, endtime: 40970194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,2533534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969736, endtime: 40970194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,2533592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969739, endtime: 40970194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,2533659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969741, endtime: 40970194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,2533714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969742, endtime: 40970194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,3911483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969975, endtime: 40970208, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,3911658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969976, endtime: 40970208, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,3911752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969978, endtime: 40970208, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,3911818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969980, endtime: 40970208, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,3911893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969981, endtime: 40970208, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,3911954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969983, endtime: 40970208, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,3912024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969984, endtime: 40970208, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,3912084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969986, endtime: 40970208, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,3912154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969989, endtime: 40970208, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,3912927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969994, endtime: 40970208, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,3913018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969995, endtime: 40970208, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,3913079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969998, endtime: 40970208, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:29,3918105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40969999, endtime: 40970208, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,6947209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,6951060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970338, endtime: 40970338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,7043150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970339, endtime: 40970339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,7195883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970341, endtime: 40970341, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,7353974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970342, endtime: 40970342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,7507083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970344, endtime: 40970344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,7659738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970345, endtime: 40970345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,7816259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970347, endtime: 40970347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,7976422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970348, endtime: 40970348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,8133086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970350, endtime: 40970350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,8299893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970352, endtime: 40970352, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,8611088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970355, endtime: 40970355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,8943389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970358, endtime: 40970358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,9098150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970359, endtime: 40970360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,9400836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970362, endtime: 40970363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,9552037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970364, endtime: 40970364, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:30,9869344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970367, endtime: 40970367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0118154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970369, endtime: 40970370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0304125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970135, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0304302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970136, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0304374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970139, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0304449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970141, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0304507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970142, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0304576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970144, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0304632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970145, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0304698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970148, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0304751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970151, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0305070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970153, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0305128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970156, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0305192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970158, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0305247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970159, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0320729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970372, endtime: 40970372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0493501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970373, endtime: 40970374, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0657119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970375, endtime: 40970375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,0802080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970376, endtime: 40970377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,1022362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970378, endtime: 40970379, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,1246719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970380, endtime: 40970381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,1431674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970383, endtime: 40970383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,1679559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970384, endtime: 40970385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,1902907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970388, endtime: 40970388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,2058258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970389, endtime: 40970389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,2221234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970391, endtime: 40970391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,2373235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970392, endtime: 40970392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,2515323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970394, endtime: 40970394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,2686028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970395, endtime: 40970395, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,2821977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970397, endtime: 40970397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,2998102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970398, endtime: 40970399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3136314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970400, endtime: 40970400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3192963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970401, endtime: 40970401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3295250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970402, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3344106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970208, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3344283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970209, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3344361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970211, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3344438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970214, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3344610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970216, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3344696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970217, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3344757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970219, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3344832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970222, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3344890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970223, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3345666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970225, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3345740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970226, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3345812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970228, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3347885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970230, endtime: 40970402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3457732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970403, endtime: 40970403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,3774113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970406, endtime: 40970406, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,8459256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970084, endtime: 40970453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,8459475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970086, endtime: 40970453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,8459558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970087, endtime: 40970453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,8459641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970089, endtime: 40970453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,8459702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970091, endtime: 40970453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,8459771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970094, endtime: 40970453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,8459829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970095, endtime: 40970453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,8459899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970098, endtime: 40970453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,8459954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970101, endtime: 40970453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,8460267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970102, endtime: 40970453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,8460328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970103, endtime: 40970453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,8460397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970105, endtime: 40970453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:31,8460453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970108, endtime: 40970453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:32,2629265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:32,2629381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:32,2632058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40970495, endtime: 40970495, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,2564520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970194, endtime: 40970594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,2564728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970195, endtime: 40970594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,2564814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970198, endtime: 40970594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,2564897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970200, endtime: 40970594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,2564960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970201, endtime: 40970594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,2565035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970203, endtime: 40970594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,2565215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970205, endtime: 40970594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,2565365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970207, endtime: 40970594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,2565473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970209, endtime: 40970594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,2565902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970211, endtime: 40970594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,2565972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970214, endtime: 40970594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,2566044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970216, endtime: 40970594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,2566105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970217, endtime: 40970594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,8052654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970453, endtime: 40970649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,8052826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970456, endtime: 40970649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,8052900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970458, endtime: 40970649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,8052972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970459, endtime: 40970649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,8053031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970461, endtime: 40970649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,8053100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970464, endtime: 40970649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,8053155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970466, endtime: 40970649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,8053219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970467, endtime: 40970649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,8053274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970469, endtime: 40970649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,8055399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970472, endtime: 40970649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,8055477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970473, endtime: 40970649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,8055546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970475, endtime: 40970649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,8055602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970478, endtime: 40970649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,9701220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970402, endtime: 40970666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,9701412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970403, endtime: 40970666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,9701489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970406, endtime: 40970666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,9701669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970408, endtime: 40970666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,9701747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970409, endtime: 40970666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,9701822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970412, endtime: 40970666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,9701885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970414, endtime: 40970666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,9701957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970417, endtime: 40970666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,9702018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970420, endtime: 40970666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,9702772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970422, endtime: 40970666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,9702847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970424, endtime: 40970666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,9702919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970425, endtime: 40970666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:33,9704986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970427, endtime: 40970666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,0613616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970408, endtime: 40970675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,3030137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970372, endtime: 40970699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,3030323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970373, endtime: 40970699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,3030395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970375, endtime: 40970699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,3030470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970376, endtime: 40970699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,3030528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970378, endtime: 40970699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,3030595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970380, endtime: 40970699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,3030650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970383, endtime: 40970699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,3030714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970384, endtime: 40970699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,3030769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970388, endtime: 40970699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,3031068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970389, endtime: 40970699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,3031127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970391, endtime: 40970699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,3031190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970392, endtime: 40970699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:34,3031243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970394, endtime: 40970699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7102906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970594, endtime: 40970840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7103072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970595, endtime: 40970840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7103241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970597, endtime: 40970840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7103346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970598, endtime: 40970840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7103413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970600, endtime: 40970840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7103488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970601, endtime: 40970840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7103551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970603, endtime: 40970840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7103629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970609, endtime: 40970840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7103690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970612, endtime: 40970840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7104019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970614, endtime: 40970840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7104080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970616, endtime: 40970840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7104150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970617, endtime: 40970840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7104208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970619, endtime: 40970840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7699396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970180, endtime: 40970846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7699587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970181, endtime: 40970846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7699662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970183, endtime: 40970846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7699737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970185, endtime: 40970846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7699792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970186, endtime: 40970846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7699859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970187, endtime: 40970846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7699912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970189, endtime: 40970846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7699975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970191, endtime: 40970846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7700031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970192, endtime: 40970846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7700305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970194, endtime: 40970846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7700360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970195, endtime: 40970846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7700427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970198, endtime: 40970846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:35,7706553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970200, endtime: 40970846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,0471503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970666, endtime: 40970873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,0471675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970667, endtime: 40970873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,0471752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970669, endtime: 40970873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,0471830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970670, endtime: 40970873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,0471891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970672, endtime: 40970873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,0471963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970673, endtime: 40970873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,0472018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970675, endtime: 40970873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,0472090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970676, endtime: 40970873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,0472146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970678, endtime: 40970873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,0472777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970680, endtime: 40970873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,0472852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970681, endtime: 40970873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,0472924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970683, endtime: 40970873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1642990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970409, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1643228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970412, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1643375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970414, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1643491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970417, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1643616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970420, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1643719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970422, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1643840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970424, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1643940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970425, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1644062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970427, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1644450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970428, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1644575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970430, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1644680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970433, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1644802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970675, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,1651637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970686, endtime: 40970885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,3421936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970649, endtime: 40970903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,3422116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970650, endtime: 40970903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,3422188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970651, endtime: 40970903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,3422263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970653, endtime: 40970903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,3422321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970655, endtime: 40970903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,3422388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970656, endtime: 40970903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,3422443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970658, endtime: 40970903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,3422510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970659, endtime: 40970903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,3422562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970661, endtime: 40970903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,3423202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970662, endtime: 40970903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,3423274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970664, endtime: 40970903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:36,3423344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970666, endtime: 40970903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:37,6551769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970699, endtime: 40971034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:37,6551980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970700, endtime: 40971034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:37,6552060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970701, endtime: 40971034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:37,6552143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970701, endtime: 40971034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:37,6552204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970703, endtime: 40971034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:37,6552279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970705, endtime: 40971034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:37,6552337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970709, endtime: 40971034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:37,6552406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970711, endtime: 40971034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:37,6552467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970713, endtime: 40971034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:37,6552792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970714, endtime: 40971034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:37,6552852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970717, endtime: 40971034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:37,6552925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970719, endtime: 40971034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:37,6552983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970721, endtime: 40971034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,0991645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970873, endtime: 40971079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,0991817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970876, endtime: 40971079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,0992044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970878, endtime: 40971079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,0992130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970880, endtime: 40971079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,0992207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970881, endtime: 40971079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,0992268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970884, endtime: 40971079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,0992343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970886, endtime: 40971079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,0992404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970889, endtime: 40971079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,0992476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970892, endtime: 40971079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,0993100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970894, endtime: 40971079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,0993185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970895, endtime: 40971079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,0993244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970897, endtime: 40971079, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,8544556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970846, endtime: 40971154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,8544764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970848, endtime: 40971154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,8544841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970850, endtime: 40971154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,8544919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970851, endtime: 40971154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,8544980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970853, endtime: 40971154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,8545046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970857, endtime: 40971154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,8545102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970858, endtime: 40971154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,8545171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970861, endtime: 40971154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,8545223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970862, endtime: 40971154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,8545550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970864, endtime: 40971154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,8545611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970866, endtime: 40971154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,8545681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970869, endtime: 40971154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,8545736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970870, endtime: 40971154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,9566588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970840, endtime: 40971164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,9566760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970841, endtime: 40971164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,9566834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970842, endtime: 40971164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,9566906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970845, endtime: 40971164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,9566965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970847, endtime: 40971164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,9567031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970848, endtime: 40971164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,9567087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970850, endtime: 40971164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,9567153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970851, endtime: 40971164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,9567206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970853, endtime: 40971164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,9567488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970857, endtime: 40971164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,9567546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970858, endtime: 40971164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,9567610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970861, endtime: 40971164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:38,9567666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970862, endtime: 40971164, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,0303244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970885, endtime: 40971172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,0303427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970886, endtime: 40971172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,0303504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970889, endtime: 40971172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,0303579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970892, endtime: 40971172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,0303637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970894, endtime: 40971172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,0303704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970895, endtime: 40971172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,0303759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970897, endtime: 40971172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,0303826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970898, endtime: 40971172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,0303878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970900, endtime: 40971172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,0304183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970901, endtime: 40971172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,0304241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970903, endtime: 40971172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,0304305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970905, endtime: 40971172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,0304360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970906, endtime: 40971172, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8234084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970898, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8234264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971079, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8234353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971080, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8234416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971081, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8234486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971083, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8234541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971084, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8234608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971086, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8234663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971087, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8234727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971089, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8234782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971091, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8235120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971092, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8235178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971094, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8235245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971095, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8235339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970667, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8235408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970903, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8235461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970905, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8235527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970906, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8235583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970908, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8235652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970911, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8236145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970915, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8236228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970916, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8236281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970917, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8236348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970920, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8236400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970923, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8236467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970926, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8236519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40970928, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,8238974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971251, endtime: 40971251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:39,9025805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55034 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,0150337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,0155678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971270, endtime: 40971270, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,0318734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971272, endtime: 40971272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,0484893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971273, endtime: 40971273, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,0794201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971277, endtime: 40971277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,0947829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971278, endtime: 40971278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,1123299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971280, endtime: 40971280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,1270496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971281, endtime: 40971281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,1413723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971283, endtime: 40971283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,1582248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971284, endtime: 40971284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,1891930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971288, endtime: 40971288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,2097475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971289, endtime: 40971290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,2296609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971291, endtime: 40971292, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,2518224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971294, endtime: 40971294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,2665274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971295, endtime: 40971295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,2840598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971297, endtime: 40971297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,2997212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971299, endtime: 40971299, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,3290687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971301, endtime: 40971302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,3351243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971302, endtime: 40971302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,3409164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971303, endtime: 40971303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,3608381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971305, endtime: 40971305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,3930306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971308, endtime: 40971308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,4259385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971311, endtime: 40971311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,4398348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971312, endtime: 40971313, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,4558498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971314, endtime: 40971314, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,4703362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971316, endtime: 40971316, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,5751047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971317, endtime: 40971326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,5751238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971319, endtime: 40971326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,5751343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971322, endtime: 40971326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,5751454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971323, endtime: 40971326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,5969486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971328, endtime: 40971328, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,6108748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971330, endtime: 40971330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,6277337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971331, endtime: 40971331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,6430582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971333, endtime: 40971333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,6763770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971336, endtime: 40971336, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,6897095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971337, endtime: 40971338, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,7227284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971341, endtime: 40971341, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,7525718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971344, endtime: 40971344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:40,7690303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971345, endtime: 40971346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6553033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971251, endtime: 40971434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6553249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971252, endtime: 40971434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6553335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971255, endtime: 40971434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6553418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971258, endtime: 40971434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6553481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971259, endtime: 40971434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6553553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971261, endtime: 40971434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6553614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971262, endtime: 40971434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6554238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971264, endtime: 40971434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6555919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971266, endtime: 40971434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6556083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971267, endtime: 40971434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6556174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971270, endtime: 40971434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6556258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971272, endtime: 40971434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6556321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971273, endtime: 40971434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6896759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971164, endtime: 40971438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6896995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971167, endtime: 40971438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6897103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971169, endtime: 40971438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6897219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971170, endtime: 40971438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6897311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971173, endtime: 40971438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6897419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971175, endtime: 40971438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6897510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971178, endtime: 40971438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6897618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971180, endtime: 40971438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6897710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971181, endtime: 40971438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6898150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971183, endtime: 40971438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6898247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971186, endtime: 40971438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6898355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971188, endtime: 40971438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,6898447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971189, endtime: 40971438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,7757198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971434, endtime: 40971446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,8975868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971252, endtime: 40971458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,8976037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971255, endtime: 40971458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,8976115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971258, endtime: 40971458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,8976192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971259, endtime: 40971458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,8976253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971261, endtime: 40971458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,8976325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971262, endtime: 40971458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,8976381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971264, endtime: 40971458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,8976453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971266, endtime: 40971458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,8976511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971267, endtime: 40971458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,8977270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971270, endtime: 40971458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,8977348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971272, endtime: 40971458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,8977420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971273, endtime: 40971458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:41,8979118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971277, endtime: 40971458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:42,4103572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:42,4103685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:42,4106592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40971510, endtime: 40971510, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,5907509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971172, endtime: 40971628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,5907697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971173, endtime: 40971628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,5907777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971175, endtime: 40971628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,5907852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971178, endtime: 40971628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,5907910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971180, endtime: 40971628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,5907977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971181, endtime: 40971628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,5908032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971183, endtime: 40971628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,5908102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971186, endtime: 40971628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,5908154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971188, endtime: 40971628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,5908473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971189, endtime: 40971628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,5908534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971191, endtime: 40971628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,5908597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971193, endtime: 40971628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,5908653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971194, endtime: 40971628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,8799295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971154, endtime: 40971657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,8799494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971156, endtime: 40971657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,8799578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971158, endtime: 40971657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,8799655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971159, endtime: 40971657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,8799719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971161, endtime: 40971657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,8799791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971162, endtime: 40971657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,8799852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971164, endtime: 40971657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,8799921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971167, endtime: 40971657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,8799982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971169, endtime: 40971657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,8800270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971170, endtime: 40971657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,8800337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971173, endtime: 40971657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,8800406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971175, endtime: 40971657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,8800464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971178, endtime: 40971657, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,9692601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971350, endtime: 40971666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,9692776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971352, endtime: 40971666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,9692851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971353, endtime: 40971666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,9692925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971355, endtime: 40971666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,9692984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971356, endtime: 40971666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,9693053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971358, endtime: 40971666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,9693108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971359, endtime: 40971666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,9693177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971361, endtime: 40971666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,9693233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971362, endtime: 40971666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,9693504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971364, endtime: 40971666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,9693563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971366, endtime: 40971666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,9693629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971367, endtime: 40971666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:43,9693687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971369, endtime: 40971666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,0953536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971458, endtime: 40971678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,0953705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971459, endtime: 40971678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,0953788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971461, endtime: 40971678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,0953871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971462, endtime: 40971678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,0953938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971464, endtime: 40971678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,0954010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971465, endtime: 40971678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,0954071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971467, endtime: 40971678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,0954143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971469, endtime: 40971678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,0954204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971471, endtime: 40971678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,0954952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971474, endtime: 40971678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,0955032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971476, endtime: 40971678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,0955107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971478, endtime: 40971678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,0956517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971480, endtime: 40971678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,2595697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55064 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,3784506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,3788850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971706, endtime: 40971706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,3915586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971708, endtime: 40971708, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,4069718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971709, endtime: 40971709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,4226175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971711, endtime: 40971711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,4380464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971712, endtime: 40971712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,4549746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971714, endtime: 40971714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,4692377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971716, endtime: 40971716, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,4850601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971717, endtime: 40971717, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,5008066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971719, endtime: 40971719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,5162787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971720, endtime: 40971720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,5320998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971722, endtime: 40971722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,5485743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971723, endtime: 40971723, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,5642499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971725, endtime: 40971725, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,5945393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971728, endtime: 40971728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,6098979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971730, endtime: 40971730, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,6259073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971731, endtime: 40971731, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,6411507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971733, endtime: 40971733, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,6579275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971734, endtime: 40971734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,6955772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971737, endtime: 40971738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,7056299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971739, endtime: 40971739, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,7359083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971742, endtime: 40971742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,7508765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971744, endtime: 40971744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,7688982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971745, endtime: 40971745, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,7875457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971747, endtime: 40971747, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8134743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971750, endtime: 40971750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8903379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971628, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8903579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971630, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8903662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971631, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8903742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971633, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8903798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971634, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8903870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971636, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8903928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971640, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8903994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971642, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8904050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971644, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8904366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971646, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8904427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971648, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8904493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971650, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8904551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971652, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8904690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971436, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8904748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971437, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8904815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971439, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8904873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971441, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8905255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971442, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8906258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971444, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8906341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971445, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8906397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971447, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8906466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971448, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8906521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971450, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8906593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971452, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:44,8906649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971453, endtime: 40971758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:45,1275392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971751, endtime: 40971781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:45,1275578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971753, endtime: 40971781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:45,1275661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971755, endtime: 40971781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:45,1275744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971756, endtime: 40971781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:45,1275810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971759, endtime: 40971781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:45,1275888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971761, endtime: 40971781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:45,1275952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971762, endtime: 40971781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:45,1276024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971764, endtime: 40971781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:45,1276087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971765, endtime: 40971781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:45,1276389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971767, endtime: 40971781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:45,1276456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971769, endtime: 40971781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:45,1276528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971772, endtime: 40971781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:45,1276589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971773, endtime: 40971781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:46,8677315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971657, endtime: 40971955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:46,8677692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971658, endtime: 40971955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:46,8677842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971659, endtime: 40971955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:46,8677980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971661, endtime: 40971955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:46,8678094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971662, endtime: 40971955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:46,8678180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971664, endtime: 40971955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:46,8678249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971666, endtime: 40971955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:46,8678330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971667, endtime: 40971955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:46,8678396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971669, endtime: 40971955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:46,8680042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971670, endtime: 40971955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:46,8680144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971672, endtime: 40971955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:46,8680222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971673, endtime: 40971955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:46,8680286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971675, endtime: 40971955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:47,9164970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971666, endtime: 40972060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:47,9165134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971667, endtime: 40972060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:47,9165206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971669, endtime: 40972060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:47,9165278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971670, endtime: 40972060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:47,9165333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971672, endtime: 40972060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:47,9165400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971673, endtime: 40972060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:47,9165455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971675, endtime: 40972060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:47,9165524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971676, endtime: 40972060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:47,9165580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971678, endtime: 40972060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:47,9165879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971680, endtime: 40972060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:47,9165937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971685, endtime: 40972060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:47,9166004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971686, endtime: 40972060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:47,9166059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971688, endtime: 40972060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,1807583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971758, endtime: 40972087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,1807763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971759, endtime: 40972087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,1807841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971761, endtime: 40972087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,1807919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971762, endtime: 40972087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,1807977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971764, endtime: 40972087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,1808046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971765, endtime: 40972087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,1808101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971767, endtime: 40972087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,1808171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971769, endtime: 40972087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,1808223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971772, endtime: 40972087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,1808542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971773, endtime: 40972087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,1808603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971777, endtime: 40972087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,1808669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971778, endtime: 40972087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,1808725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971780, endtime: 40972087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,3965332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971678, endtime: 40972108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,3965479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971680, endtime: 40972108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,3965556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971685, endtime: 40972108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,3965628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971686, endtime: 40972108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,3965686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971688, endtime: 40972108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,3965753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971689, endtime: 40972108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,3965808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971691, endtime: 40972108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,3965872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971692, endtime: 40972108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,3965928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971694, endtime: 40972108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,3966210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971695, endtime: 40972108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,3966266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971697, endtime: 40972108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,3966329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971698, endtime: 40972108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:48,3966385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971700, endtime: 40972108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:49,0040090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971955, endtime: 40972169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:49,0040331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971956, endtime: 40972169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:49,0040409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971959, endtime: 40972169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:49,0040484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971961, endtime: 40972169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:49,0040542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971962, endtime: 40972169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:49,0040611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971964, endtime: 40972169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:49,0040664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971966, endtime: 40972169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:49,0040733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971967, endtime: 40972169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:49,0040789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971969, endtime: 40972169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:49,0041082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971970, endtime: 40972169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:49,0041146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971972, endtime: 40972169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:49,0041213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971973, endtime: 40972169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:49,0041271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971975, endtime: 40972169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,3569884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972087, endtime: 40972404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,3570064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972087, endtime: 40972404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,3570147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972091, endtime: 40972404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,3570228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972094, endtime: 40972404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,3570292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972097, endtime: 40972404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,3570366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972099, endtime: 40972404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,3570430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972101, endtime: 40972404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,3570505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972105, endtime: 40972404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,3570566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972106, endtime: 40972404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,3570887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972108, endtime: 40972404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,3570954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972109, endtime: 40972404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,3571026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972113, endtime: 40972404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,3571087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972116, endtime: 40972404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6582896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972108, endtime: 40972434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6583074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972109, endtime: 40972434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6583151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972113, endtime: 40972434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6583223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972116, endtime: 40972434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6583279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972117, endtime: 40972434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6583348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972119, endtime: 40972434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6583403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972121, endtime: 40972434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6583470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972122, endtime: 40972434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6585066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972123, endtime: 40972434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6585215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972126, endtime: 40972434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6585279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972126, endtime: 40972434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6585354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972128, endtime: 40972434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6585415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972130, endtime: 40972434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6722114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972060, endtime: 40972436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6722319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972061, endtime: 40972436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6722405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972062, endtime: 40972436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6722486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972064, endtime: 40972436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6722552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972066, endtime: 40972436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6722627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972067, endtime: 40972436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6722688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972069, endtime: 40972436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6722760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972072, endtime: 40972436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6722821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972076, endtime: 40972436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6723148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972079, endtime: 40972436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6723214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972080, endtime: 40972436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6723286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972083, endtime: 40972436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:51,6723350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972084, endtime: 40972436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5202628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971455, endtime: 40972521, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5202808</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971758, endtime: 40972521, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5202902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971759, endtime: 40972521, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5202972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971761, endtime: 40972521, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5203044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971762, endtime: 40972521, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5203102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971764, endtime: 40972521, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5203174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971765, endtime: 40972521, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5203235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971767, endtime: 40972521, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5203307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971769, endtime: 40972521, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5203365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971772, endtime: 40972521, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5203689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971773, endtime: 40972521, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5203747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971777, endtime: 40972521, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5203817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971778, endtime: 40972521, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5651597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5651778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:52,5758871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40972525, endtime: 40972526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:53,0982447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971781, endtime: 40972578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:53,0982616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971783, endtime: 40972578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:53,0982707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971784, endtime: 40972578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:53,0982776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971786, endtime: 40972578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:53,0982848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971787, endtime: 40972578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:53,0982907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971789, endtime: 40972578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:53,0982979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971791, endtime: 40972578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:53,0983037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971794, endtime: 40972578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:53,0983109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971795, endtime: 40972578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:53,0983400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971799, endtime: 40972578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:53,0983475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971803, endtime: 40972578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:53,0983536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971803, endtime: 40972578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:53,0983608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40971804, endtime: 40972578, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,0624690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972169, endtime: 40972675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,0624903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972170, endtime: 40972675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,0624997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972172, endtime: 40972675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,0625067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972173, endtime: 40972675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,0625144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972175, endtime: 40972675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,0625202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972178, endtime: 40972675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,0625274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972181, endtime: 40972675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,0625330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972183, endtime: 40972675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,0625399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972184, endtime: 40972675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,0625457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972186, endtime: 40972675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,0625751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972187, endtime: 40972675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,0625812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972191, endtime: 40972675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,0625884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972192, endtime: 40972675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1407739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972675, endtime: 40972683, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1707441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972436, endtime: 40972686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1707605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972437, endtime: 40972686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1707674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972439, endtime: 40972686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1707746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972441, endtime: 40972686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1707802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972444, endtime: 40972686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1707871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972445, endtime: 40972686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1707924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972447, endtime: 40972686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1707987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972448, endtime: 40972686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1708040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972450, endtime: 40972686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1708347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972454, endtime: 40972686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1708406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972455, endtime: 40972686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1708469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972456, endtime: 40972686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,1709514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972458, endtime: 40972686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,2576176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972404, endtime: 40972694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,2576358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972406, endtime: 40972694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,2576433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972408, endtime: 40972694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,2576511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972409, endtime: 40972694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,2576569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972411, endtime: 40972694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,2576638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972412, endtime: 40972694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,2576694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972414, endtime: 40972694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,2576760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972416, endtime: 40972694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,2576818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972417, endtime: 40972694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,2577090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972419, endtime: 40972694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,2577151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972420, endtime: 40972694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,2577217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972423, endtime: 40972694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:54,2577273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972425, endtime: 40972694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2722697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972434, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2722882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972437, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2722960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972439, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2723037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972441, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2723098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972444, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2723170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972445, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2723226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972447, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2723292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972450, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2723351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972454, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2724085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972455, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2724162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972456, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2724234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972458, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2724345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972521, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2724417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972522, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2724475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972523, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2724545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972525, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2724600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972528, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2724672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972530, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2725232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972531, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2725312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972534, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2725370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972536, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2725437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972538, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2725495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972539, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2725561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972541, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,2725620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972544, endtime: 40972796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,3549313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972459, endtime: 40972804, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,8649701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972677, endtime: 40972855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,8649870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972680, endtime: 40972855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,8649962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972681, endtime: 40972855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,8650028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972683, endtime: 40972855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,8650103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972684, endtime: 40972855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,8650161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972686, endtime: 40972855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,8650233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972687, endtime: 40972855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,8650291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972691, endtime: 40972855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,8650361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972692, endtime: 40972855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,8651186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972694, endtime: 40972855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,8651275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972695, endtime: 40972855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,8651336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972697, endtime: 40972855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:55,8653231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972698, endtime: 40972855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:56,1249734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972578, endtime: 40972881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:56,1249894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972580, endtime: 40972881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:56,1249969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972581, endtime: 40972881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:56,1250044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972583, endtime: 40972881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:56,1250099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972584, endtime: 40972881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:56,1250172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972587, endtime: 40972881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:56,1250227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972588, endtime: 40972881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:56,1250299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972588, endtime: 40972881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:56,1250354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972589, endtime: 40972881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:56,1250662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972590, endtime: 40972881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:56,1250720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972590, endtime: 40972881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:56,1250787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972592, endtime: 40972881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:56,1250845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972594, endtime: 40972881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,1329193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972694, endtime: 40972982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,1329335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972695, endtime: 40972982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,1329407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972696, endtime: 40972982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,1329482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972697, endtime: 40972982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,1329540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972698, endtime: 40972982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,1329606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972698, endtime: 40972982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,1329662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972699, endtime: 40972982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,1329725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972699, endtime: 40972982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,1329781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972700, endtime: 40972982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,1330598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972701, endtime: 40972982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,1330667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972703, endtime: 40972982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,1330737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972705, endtime: 40972982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,1332399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972706, endtime: 40972982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,6003101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972686, endtime: 40973029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,6003256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972687, endtime: 40973029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,6003328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972691, endtime: 40973029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,6003398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972692, endtime: 40973029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,6003456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972694, endtime: 40973029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,6003522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972695, endtime: 40973029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,6003578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972697, endtime: 40973029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,6003644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972698, endtime: 40973029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,6003700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972698, endtime: 40973029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,6003988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972699, endtime: 40973029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,6004046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972699, endtime: 40973029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,6004110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972700, endtime: 40973029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,6004165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972701, endtime: 40973029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,8244900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972796, endtime: 40973051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,8245064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972797, endtime: 40973051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,8245150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972798, endtime: 40973051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,8245213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972800, endtime: 40973051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,8245285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972801, endtime: 40973051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,8245341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972801, endtime: 40973051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,8245407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972803, endtime: 40973051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,8245463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972805, endtime: 40973051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,8245529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972806, endtime: 40973051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,8246338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972811, endtime: 40973051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,8246471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972812, endtime: 40973051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:57,8246568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972814, endtime: 40973051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:58,4277192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972855, endtime: 40973111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:58,4277366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972856, endtime: 40973111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:58,4277438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972859, endtime: 40973111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:58,4277510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972861, endtime: 40973111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:58,4277566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972863, endtime: 40973111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:58,4277629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972864, endtime: 40973111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:58,4277685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972866, endtime: 40973111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:58,4277749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972867, endtime: 40973111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:58,4277804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972869, endtime: 40973111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:58,4278519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972872, endtime: 40973111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:58,4278588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972873, endtime: 40973111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:58,4279189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972877, endtime: 40973111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:58,4279259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972878, endtime: 40973111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,1591837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972881, endtime: 40973185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,1592017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972883, endtime: 40973185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,1592092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972884, endtime: 40973185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,1592167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972887, endtime: 40973185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,1592225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972889, endtime: 40973185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,1592291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972892, endtime: 40973185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,1592347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972894, endtime: 40973185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,1592413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972897, endtime: 40973185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,1592469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972898, endtime: 40973185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,1592762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972900, endtime: 40973185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,1592821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972901, endtime: 40973185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,1592890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972903, endtime: 40973185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,1592945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972905, endtime: 40973185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,8542816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972796, endtime: 40973254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,8543013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972797, endtime: 40973254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,8543087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972798, endtime: 40973254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,8543162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972800, endtime: 40973254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,8543220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972801, endtime: 40973254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,8543290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972801, endtime: 40973254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,8543345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972803, endtime: 40973254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,8544301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972805, endtime: 40973254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,8544373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972806, endtime: 40973254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,8544439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972811, endtime: 40973254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,8544495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972812, endtime: 40973254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,8544559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972814, endtime: 40973254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:57:59,8544611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972816, endtime: 40973254, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1948383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972816, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1948644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973051, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1948782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973053, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1948857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973055, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1948937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973056, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1948998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973058, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1949073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973059, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1949137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973061, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1949212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973062, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1949275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973064, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1949627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973066, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1949688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973067, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1949760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973069, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,1978316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973288, endtime: 40973288, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,3986385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973029, endtime: 40973308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,3986565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973030, endtime: 40973308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,3986640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973031, endtime: 40973308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,3986712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973033, endtime: 40973308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,3986768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973034, endtime: 40973308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,3986834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973037, endtime: 40973308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,3986890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973042, endtime: 40973308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,3986953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973044, endtime: 40973308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,3987009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973047, endtime: 40973308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,3988311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973049, endtime: 40973308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,3988430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973050, endtime: 40973308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,3988513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973052, endtime: 40973308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:00,3988574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973053, endtime: 40973308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,3359086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973111, endtime: 40973402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,3359277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973114, endtime: 40973402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,3359358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973119, endtime: 40973402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,3359435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973120, endtime: 40973402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,3359493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973123, endtime: 40973402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,3359563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973125, endtime: 40973402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,3359618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973127, endtime: 40973402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,3359687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973130, endtime: 40973402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,3359743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973131, endtime: 40973402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,3360410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973134, endtime: 40973402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,3360482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973136, endtime: 40973402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,3360552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973139, endtime: 40973402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,4811123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973141, endtime: 40973417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,7260551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973185, endtime: 40973441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,7260733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973186, endtime: 40973441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,7260817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973189, endtime: 40973441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,7260894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973191, endtime: 40973441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,7260961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973194, endtime: 40973441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,7261035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973195, endtime: 40973441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,7261096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973199, endtime: 40973441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,7261168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973200, endtime: 40973441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,7261232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973201, endtime: 40973441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,7261565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973203, endtime: 40973441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,7261631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973206, endtime: 40973441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,7261700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973208, endtime: 40973441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,7261761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973211, endtime: 40973441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,9053056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973254, endtime: 40973459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,9053253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973255, endtime: 40973459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,9053328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973256, endtime: 40973459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,9053405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973258, endtime: 40973459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,9053461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973259, endtime: 40973459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,9053527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973261, endtime: 40973459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,9053583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973262, endtime: 40973459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,9053649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973264, endtime: 40973459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,9053704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973266, endtime: 40973459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,9054026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973267, endtime: 40973459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,9054084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973269, endtime: 40973459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,9054328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973272, endtime: 40973459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:01,9054411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973273, endtime: 40973459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,3603267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973289, endtime: 40973505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,3603447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973291, endtime: 40973505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,3603527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973292, endtime: 40973505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,3603610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973294, endtime: 40973505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,3603674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973295, endtime: 40973505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,3603746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973297, endtime: 40973505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,3603804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973298, endtime: 40973505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,3603876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973300, endtime: 40973505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,3603934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973300, endtime: 40973505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,3604699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973304, endtime: 40973505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,3604774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973306, endtime: 40973505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,3604846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973308, endtime: 40973505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,3605766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973309, endtime: 40973505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,6178070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973402, endtime: 40973530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,6178234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973403, endtime: 40973530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,6178320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973405, endtime: 40973530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,6178384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973406, endtime: 40973530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,6178453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973408, endtime: 40973530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,6178508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973409, endtime: 40973530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,6178575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973411, endtime: 40973530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,6178630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973412, endtime: 40973530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,6178697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973414, endtime: 40973530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,6179591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973416, endtime: 40973530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,6179675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973417, endtime: 40973530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,6179730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973419, endtime: 40973530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,6180908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973420, endtime: 40973530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,8571197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972982, endtime: 40973554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,8571347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972983, endtime: 40973554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,8571427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972984, endtime: 40973554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,8571491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972986, endtime: 40973554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,8571558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972987, endtime: 40973554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,8571613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972990, endtime: 40973554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,8571680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972992, endtime: 40973554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,8571732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972994, endtime: 40973554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,8571799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972995, endtime: 40973554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,8572464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972997, endtime: 40973554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,8572547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40972998, endtime: 40973554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,8572602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973002, endtime: 40973554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,9375655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,9375868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:02,9386033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40973562, endtime: 40973562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,1123471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973459, endtime: 40973580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,1123698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973461, endtime: 40973580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,1123803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973462, endtime: 40973580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,1123903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973464, endtime: 40973580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,1123972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973466, endtime: 40973580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,1124042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973467, endtime: 40973580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,1124100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973469, endtime: 40973580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,1124172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973470, endtime: 40973580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,1124227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973472, endtime: 40973580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,1124787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973473, endtime: 40973580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,1124862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973475, endtime: 40973580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,1124928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973479, endtime: 40973580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,1124987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973480, endtime: 40973580, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5189460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973441, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5189945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973442, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5190036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973446, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5190122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973450, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5190194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973452, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5190274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973453, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5190341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973455, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5190421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973456, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5190485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973458, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5190889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973459, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5190956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973461, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5191028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973462, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5191089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973464, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5191216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973308, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5191288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973309, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5191349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973311, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5191418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973312, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5191479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973314, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5192125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973316, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5192205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973317, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5192277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973319, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5192336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973320, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5192405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973322, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5192463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973323, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5192532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973325, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:03,5192590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973326, endtime: 40973621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,1793911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973580, endtime: 40973687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,1794135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973581, endtime: 40973687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,1794221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973583, endtime: 40973687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,1794304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973584, endtime: 40973687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,1794371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973586, endtime: 40973687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,1794445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973587, endtime: 40973687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,1794506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973589, endtime: 40973687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,1794578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973591, endtime: 40973687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,1794639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973592, endtime: 40973687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,1794980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973594, endtime: 40973687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,1795047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973595, endtime: 40973687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,1795116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973597, endtime: 40973687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,1795180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973600, endtime: 40973687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,7693877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973530, endtime: 40973746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,7694091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973531, endtime: 40973746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,7694177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973534, endtime: 40973746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,7694265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973536, endtime: 40973746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,7694332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973537, endtime: 40973746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,7694409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973541, endtime: 40973746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,7694470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973542, endtime: 40973746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,7694545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973545, endtime: 40973746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,7694606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973549, endtime: 40973746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,7695445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973550, endtime: 40973746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,7695531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973553, endtime: 40973746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:04,7695609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973555, endtime: 40973746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3695693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973005, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3695881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973554, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3696089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973556, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3696164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973559, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3696244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973561, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3696313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973562, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3696399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973564, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3696496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973566, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3696576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973567, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3696643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973572, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3696964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973573, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3697028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973575, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3697100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973578, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,3699787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973806, endtime: 40973806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,5072099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973621, endtime: 40973819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,5072343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973622, endtime: 40973819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,5072459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973623, endtime: 40973819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,5072536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973625, endtime: 40973819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,5072592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973626, endtime: 40973819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,5072664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973628, endtime: 40973819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,5072719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973630, endtime: 40973819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,5072789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973631, endtime: 40973819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,5072844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973633, endtime: 40973819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,5073149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973634, endtime: 40973819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,5073207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973636, endtime: 40973819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,5073273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973637, endtime: 40973819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:05,5073329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973639, endtime: 40973819, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:06,9240787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973806, endtime: 40973961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:06,9240975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973808, endtime: 40973961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:06,9241058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973809, endtime: 40973961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:06,9241133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973811, endtime: 40973961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:06,9241194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973812, endtime: 40973961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:06,9241260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973814, endtime: 40973961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:06,9241316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973816, endtime: 40973961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:06,9241385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973818, endtime: 40973961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:06,9241440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973820, endtime: 40973961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:06,9242172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973822, endtime: 40973961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:06,9242244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973824, endtime: 40973961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:06,9242313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973825, endtime: 40973961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,7872886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973819, endtime: 40974047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,7873152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973820, endtime: 40974047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,7873263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973822, endtime: 40974047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,7873385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973824, endtime: 40974047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,7873479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973825, endtime: 40974047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,7873593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973827, endtime: 40974047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,7873684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973828, endtime: 40974047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,7873800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973830, endtime: 40974047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,7873895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973831, endtime: 40974047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,7874404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973833, endtime: 40974047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,7874501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973836, endtime: 40974047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,7874609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973839, endtime: 40974047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,7874701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973841, endtime: 40974047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,8610343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973621, endtime: 40974055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,8610559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973622, endtime: 40974055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,8610650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973623, endtime: 40974055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,8610736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973625, endtime: 40974055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,8610805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973626, endtime: 40974055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,8610880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973628, endtime: 40974055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,8610947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973630, endtime: 40974055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,8611022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973631, endtime: 40974055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,8611088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973633, endtime: 40974055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,8611401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973634, endtime: 40974055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,8611465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973636, endtime: 40974055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,8611537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973637, endtime: 40974055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:07,8611598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973639, endtime: 40974055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:08,2986291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55006 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:09,2589436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973505, endtime: 40974195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:09,2589599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973506, endtime: 40974195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:09,2589685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973509, endtime: 40974195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:09,2589749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973513, endtime: 40974195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:09,2589818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973514, endtime: 40974195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:09,2589873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973516, endtime: 40974195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:09,2589937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973519, endtime: 40974195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:09,2589995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973521, endtime: 40974195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:09,2590059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973523, endtime: 40974195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:09,2590693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973526, endtime: 40974195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:09,2590774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973527, endtime: 40974195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:09,2590829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973530, endtime: 40974195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,0505783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973556, endtime: 40974274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,0505993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973746, endtime: 40974274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,0506079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973748, endtime: 40974274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,0506160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973750, endtime: 40974274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,0506226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973752, endtime: 40974274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,0506301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973755, endtime: 40974274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,0506362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973757, endtime: 40974274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,0506434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973759, endtime: 40974274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,0506495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973761, endtime: 40974274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,0506778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973764, endtime: 40974274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,0506847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973767, endtime: 40974274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,0506922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973769, endtime: 40974274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,0506983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973772, endtime: 40974274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7293138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973827, endtime: 40974342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7293371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973961, endtime: 40974342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7293457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973962, endtime: 40974342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7293545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973964, endtime: 40974342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7293612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973966, endtime: 40974342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7293689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973967, endtime: 40974342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7293750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973970, endtime: 40974342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7293828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973972, endtime: 40974342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7293892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973973, endtime: 40974342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7294224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973977, endtime: 40974342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7294288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973980, endtime: 40974342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7294360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973981, endtime: 40974342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7294418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973983, endtime: 40974342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7963960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974055, endtime: 40974348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7964137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974056, endtime: 40974348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7964209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974058, endtime: 40974348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7964284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974059, endtime: 40974348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7964342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974061, endtime: 40974348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7964409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974064, endtime: 40974348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7964467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974066, endtime: 40974348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7964533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974067, endtime: 40974348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7964592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974069, endtime: 40974348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7964921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974070, endtime: 40974348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7964982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974072, endtime: 40974348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7965049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974073, endtime: 40974348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,7965104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974075, endtime: 40974348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,8461508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973687, endtime: 40974353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,8461713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973689, endtime: 40974353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,8461810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973691, endtime: 40974353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,8461877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973693, endtime: 40974353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,8461952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973695, endtime: 40974353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,8462015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973697, endtime: 40974353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,8462090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973698, endtime: 40974353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,8462154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973700, endtime: 40974353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,8462229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973701, endtime: 40974353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,8462497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973701, endtime: 40974353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,8462572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973705, endtime: 40974353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,8462636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973708, endtime: 40974353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:10,8462708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973711, endtime: 40974353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:11,2415212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974047, endtime: 40974393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:11,2415389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974050, endtime: 40974393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:11,2415461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974052, endtime: 40974393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:11,2415533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974053, endtime: 40974393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:11,2415588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974056, endtime: 40974393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:11,2415652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974058, endtime: 40974393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:11,2415708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974059, endtime: 40974393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:11,2415771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974061, endtime: 40974393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:11,2415824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974064, endtime: 40974393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:11,2416123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974066, endtime: 40974393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:11,2416179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974067, endtime: 40974393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:11,2416245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974069, endtime: 40974393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:11,2416298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974070, endtime: 40974393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5148314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974395, endtime: 40974520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5148486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974398, endtime: 40974520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5148563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974398, endtime: 40974520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5148638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974400, endtime: 40974520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5148699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974401, endtime: 40974520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5148768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974403, endtime: 40974520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5148827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974405, endtime: 40974520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5148893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974406, endtime: 40974520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5148949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974408, endtime: 40974520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5149237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974409, endtime: 40974520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5149298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974411, endtime: 40974520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5149364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974414, endtime: 40974520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5149422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974416, endtime: 40974520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5743702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974342, endtime: 40974526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5743960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974344, endtime: 40974526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5744068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974345, endtime: 40974526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5744179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974347, endtime: 40974526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5744270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974348, endtime: 40974526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5744378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974350, endtime: 40974526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5744467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974352, endtime: 40974526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5744575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974353, endtime: 40974526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5744666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974355, endtime: 40974526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5745087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974356, endtime: 40974526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5745181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974359, endtime: 40974526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5745290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974361, endtime: 40974526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,5745381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974364, endtime: 40974526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,7466104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974526, endtime: 40974543, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,9769332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,9769451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:12,9773180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40974566, endtime: 40974566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6022692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974353, endtime: 40974629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6022908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974355, endtime: 40974629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6023013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974356, endtime: 40974629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6023124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974359, endtime: 40974629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6023210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974361, endtime: 40974629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6023315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974364, endtime: 40974629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6023404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974366, endtime: 40974629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6023509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974368, endtime: 40974629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6023595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974370, endtime: 40974629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6024011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974372, endtime: 40974629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6024099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974375, endtime: 40974629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6024202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974376, endtime: 40974629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6024293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974378, endtime: 40974629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6567176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974274, endtime: 40974634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6567379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974275, endtime: 40974634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6567462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974277, endtime: 40974634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6567542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974278, endtime: 40974634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6567606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974280, endtime: 40974634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6567863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974281, endtime: 40974634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6567944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974283, endtime: 40974634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6568021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974284, endtime: 40974634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6568085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974286, endtime: 40974634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6568420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974289, endtime: 40974634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6568487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974292, endtime: 40974634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6568559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974294, endtime: 40974634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,6568617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974296, endtime: 40974634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9480047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40973531, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9480227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974195, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9480315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974197, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9480379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974200, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9480451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974201, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9480509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974203, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9480579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974205, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9480634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974208, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9480703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974210, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9480759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974213, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9481052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974214, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9481110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974217, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9481180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974219, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9484039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974663, endtime: 40974663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9587328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974520, endtime: 40974664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9587494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974523, endtime: 40974664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9587569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974525, endtime: 40974664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9587641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974526, endtime: 40974664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9587699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974528, endtime: 40974664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9587769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974530, endtime: 40974664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9587824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974531, endtime: 40974664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9587891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974533, endtime: 40974664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9587946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974534, endtime: 40974664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9588243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974536, endtime: 40974664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9588301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974537, endtime: 40974664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9588367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974537, endtime: 40974664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:13,9588423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974538, endtime: 40974664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:14,6913532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974528, endtime: 40974738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:14,6913707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974530, endtime: 40974738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:14,6913793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974531, endtime: 40974738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:14,6913854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974533, endtime: 40974738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:14,6913923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974534, endtime: 40974738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:14,6913978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974536, endtime: 40974738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:14,6914048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974537, endtime: 40974738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:14,6914100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974537, endtime: 40974738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:14,6914167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974538, endtime: 40974738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:14,6914937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974538, endtime: 40974738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:14,6915020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974539, endtime: 40974738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:14,6915076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974541, endtime: 40974738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:14,6916494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974543, endtime: 40974738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,2779900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974664, endtime: 40974896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,2780222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974666, endtime: 40974896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,2780349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974669, endtime: 40974896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,2780449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974670, endtime: 40974896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,2780521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974674, endtime: 40974896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,2780599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974675, endtime: 40974896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,2780668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974678, endtime: 40974896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,2780745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974680, endtime: 40974896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,2780812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974684, endtime: 40974896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,2781172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974686, endtime: 40974896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,2781236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974689, endtime: 40974896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,2781308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974690, endtime: 40974896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,2781372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974692, endtime: 40974896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7007291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974348, endtime: 40974939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7007463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974350, endtime: 40974939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7007554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974352, endtime: 40974939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7007784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974353, endtime: 40974939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7007920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974355, endtime: 40974939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7008031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974356, endtime: 40974939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7008117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974359, endtime: 40974939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7008180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974361, endtime: 40974939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7008258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974364, endtime: 40974939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7008588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974366, endtime: 40974939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7008665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974368, endtime: 40974939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7008726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974370, endtime: 40974939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7008798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974372, endtime: 40974939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7899675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974664, endtime: 40974948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7899938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974666, endtime: 40974948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7900054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974669, endtime: 40974948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7900184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974670, endtime: 40974948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7900287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974674, endtime: 40974948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7900406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974675, endtime: 40974948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7900503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974678, endtime: 40974948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7900622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974680, endtime: 40974948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7900722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974684, endtime: 40974948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7902052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974686, endtime: 40974948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7902185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974689, endtime: 40974948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7902307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974690, endtime: 40974948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,7903066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974692, endtime: 40974948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,9819357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974629, endtime: 40974967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,9819551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974631, endtime: 40974967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,9819629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974633, endtime: 40974967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,9819709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974636, endtime: 40974967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,9819767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974637, endtime: 40974967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,9819839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974639, endtime: 40974967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,9819895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974641, endtime: 40974967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,9819964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974642, endtime: 40974967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,9820022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974645, endtime: 40974967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,9820313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974647, endtime: 40974967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,9820374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974648, endtime: 40974967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,9820443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974650, endtime: 40974967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:16,9820501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974652, endtime: 40974967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,3259249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974634, endtime: 40975101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,3259424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974636, endtime: 40975101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,3259496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974637, endtime: 40975101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,3259570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974639, endtime: 40975101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,3259631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974641, endtime: 40975101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,3259698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974642, endtime: 40975101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,3259756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974645, endtime: 40975101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,3259825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974647, endtime: 40975101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,3259883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974648, endtime: 40975101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,3260177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974650, endtime: 40975101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,3260235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974652, endtime: 40975101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,3260302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974653, endtime: 40975101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,3260357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974655, endtime: 40975101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,7386545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974948, endtime: 40975142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,7386863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974948, endtime: 40975142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,7386993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974950, endtime: 40975142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,7387115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974954, endtime: 40975142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,7387223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974955, endtime: 40975142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,7387345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974956, endtime: 40975142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,7387434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974958, endtime: 40975142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,7387542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974959, endtime: 40975142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,7387631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974961, endtime: 40975142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,7388656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974962, endtime: 40975142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,7388731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974964, endtime: 40975142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,7388800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974966, endtime: 40975142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:18,7419758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974967, endtime: 40975143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,5014263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975142, endtime: 40975219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,5014471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975144, endtime: 40975219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,5014551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975145, endtime: 40975219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,5014635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975147, endtime: 40975219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,5014695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975148, endtime: 40975219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,5014768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975150, endtime: 40975219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,5014826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975152, endtime: 40975219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,5014895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975153, endtime: 40975219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,5014953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975155, endtime: 40975219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,5015250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975156, endtime: 40975219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,5015311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975158, endtime: 40975219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,5015383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975161, endtime: 40975219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,5015438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975164, endtime: 40975219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,6809179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974896, endtime: 40975237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,6809370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974898, endtime: 40975237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,6809448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974900, endtime: 40975237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,6809523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974900, endtime: 40975237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,6809581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974901, endtime: 40975237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,6809647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974903, endtime: 40975237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,6809703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974905, endtime: 40975237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,6809769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974908, endtime: 40975237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,6809825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974911, endtime: 40975237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,6810118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974912, endtime: 40975237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,6810177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974914, endtime: 40975237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,6810243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974916, endtime: 40975237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,6810299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974917, endtime: 40975237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:19,7609101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975237, endtime: 40975245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,2749588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55067 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,4252553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974939, endtime: 40975311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,4252755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974941, endtime: 40975311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,4252838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974942, endtime: 40975311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,4252922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974944, endtime: 40975311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,4252985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974945, endtime: 40975311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,4253057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974947, endtime: 40975311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,4253121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974948, endtime: 40975311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,4253193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974950, endtime: 40975311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,4253254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974954, endtime: 40975311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,4253559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974955, endtime: 40975311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,4253625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974956, endtime: 40975311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,4253697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974958, endtime: 40975311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,4253756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974959, endtime: 40975311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7722015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975219, endtime: 40975346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7722206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975220, endtime: 40975346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7722284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975222, endtime: 40975346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7722361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975224, endtime: 40975346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7722425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975227, endtime: 40975346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7722494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975228, endtime: 40975346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7722550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975230, endtime: 40975346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7722619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975231, endtime: 40975346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7722677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975233, endtime: 40975346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7722996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975234, endtime: 40975346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7723057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975236, endtime: 40975346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7723123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975237, endtime: 40975346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7723182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975239, endtime: 40975346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,7837631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55076 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,8887726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,8891801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975357, endtime: 40975358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,9070843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975359, endtime: 40975359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,9237359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975361, endtime: 40975361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,9562482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975364, endtime: 40975364, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,9707690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975366, endtime: 40975366, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:20,9912767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975368, endtime: 40975368, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,0003804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975369, endtime: 40975369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,0169462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975370, endtime: 40975370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,0333911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975372, endtime: 40975372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,0516738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975374, endtime: 40975374, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,0654130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975375, endtime: 40975375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,0793650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975376, endtime: 40975377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,0955633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975378, endtime: 40975378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,1260963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975381, endtime: 40975381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,1451386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975383, endtime: 40975383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,1765258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975386, endtime: 40975386, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,1884272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975387, endtime: 40975387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,2068180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975389, endtime: 40975389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,2372459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975392, endtime: 40975392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,2514650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975394, endtime: 40975394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,2675600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975395, endtime: 40975395, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,2839038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975397, endtime: 40975397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,2998697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975398, endtime: 40975399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,3140134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975400, endtime: 40975400, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,3192830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975401, endtime: 40975401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,8737811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974738, endtime: 40975456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,8737985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974739, endtime: 40975456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,8738057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974741, endtime: 40975456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,8738135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974742, endtime: 40975456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,8738196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974745, endtime: 40975456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,8738268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974746, endtime: 40975456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,8738326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974747, endtime: 40975456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,8738398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974747, endtime: 40975456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,8738453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974748, endtime: 40975456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,8739271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974750, endtime: 40975456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,8739346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974752, endtime: 40975456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,8739418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974753, endtime: 40975456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:21,8740357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974755, endtime: 40975456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:22,1343988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975403, endtime: 40975482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:22,1344174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975406, endtime: 40975482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:22,1344254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975410, endtime: 40975482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:22,1344332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975411, endtime: 40975482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:22,1344393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975414, endtime: 40975482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:22,1344468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975416, endtime: 40975482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:22,1344529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975417, endtime: 40975482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:22,1344601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975419, endtime: 40975482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:22,1344659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975420, endtime: 40975482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:22,1344947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975424, endtime: 40975482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:22,1345011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975427, endtime: 40975482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:22,1345080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975430, endtime: 40975482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:22,1345141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975433, endtime: 40975482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,1549007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,1549129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,1553830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40975584, endtime: 40975584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2317813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975311, endtime: 40975592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2318018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975312, endtime: 40975592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2318098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975314, endtime: 40975592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2318178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975316, endtime: 40975592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2318239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975317, endtime: 40975592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2318311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975319, endtime: 40975592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2318369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975320, endtime: 40975592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2318558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975322, endtime: 40975592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2318638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975323, endtime: 40975592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2318976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975325, endtime: 40975592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2319040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975328, endtime: 40975592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2319109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975330, endtime: 40975592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2319170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975331, endtime: 40975592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,2817566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,3609498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,3620106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975605, endtime: 40975605, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,3759166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975606, endtime: 40975606, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,3926342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975608, endtime: 40975608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,4229618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975611, endtime: 40975611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,4382562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975612, endtime: 40975612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,4543046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975614, endtime: 40975614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,4694729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975616, endtime: 40975616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,4870557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975617, endtime: 40975617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,5037187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975619, endtime: 40975619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,5166253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975620, endtime: 40975620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,5330922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975622, endtime: 40975622, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,5639886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975625, endtime: 40975625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,5790358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975626, endtime: 40975627, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,5948989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975628, endtime: 40975628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,6104753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975630, endtime: 40975630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,6405927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975631, endtime: 40975633, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,6571426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975634, endtime: 40975634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,6762977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975636, endtime: 40975636, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7216887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975639, endtime: 40975641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7252067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975641, endtime: 40975641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7325523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975642, endtime: 40975642, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7379701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975642, endtime: 40975642, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7521573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974967, endtime: 40975644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7521745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974969, endtime: 40975644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7521839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974970, endtime: 40975644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7521909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974974, endtime: 40975644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7521986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974975, endtime: 40975644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7522047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974977, endtime: 40975644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7522119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974978, endtime: 40975644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7522180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974980, endtime: 40975644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7522255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974981, endtime: 40975644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7522538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974983, endtime: 40975644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7522615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974985, endtime: 40975644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7522676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974987, endtime: 40975644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7522745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40974987, endtime: 40975644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7788836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975645, endtime: 40975646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,7981988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975648, endtime: 40975648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,8149377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975650, endtime: 40975650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,8317378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975652, endtime: 40975652, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,8607641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975655, endtime: 40975655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,9117909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975656, endtime: 40975660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,9118092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975658, endtime: 40975660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,9118175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975659, endtime: 40975660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,9242255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975661, endtime: 40975661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,9387554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975662, endtime: 40975662, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,9549981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975664, endtime: 40975664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:23,9713452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975666, endtime: 40975666, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,0046008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975669, endtime: 40975669, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,0506293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975674, endtime: 40975674, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,0669390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975675, endtime: 40975675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,0790106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975676, endtime: 40975677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,0955974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975678, endtime: 40975678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,1010194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975679, endtime: 40975679, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,5174194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55008 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,6400286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,6405356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975733, endtime: 40975733, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,6569138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975734, endtime: 40975734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,6844038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975736, endtime: 40975737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,7140901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975740, endtime: 40975740, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,7376003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975742, endtime: 40975742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,7539945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975744, endtime: 40975744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,7868309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975747, endtime: 40975747, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,7926458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975748, endtime: 40975748, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,7984545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975748, endtime: 40975748, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,8042145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975749, endtime: 40975749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,8303140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975752, endtime: 40975752, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,8447268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975753, endtime: 40975753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,8613928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975755, endtime: 40975755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,8760316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975756, endtime: 40975756, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,8928384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975758, endtime: 40975758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,9071486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975759, endtime: 40975759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,9250187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975761, endtime: 40975761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,9563427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975764, endtime: 40975764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,9704999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975765, endtime: 40975766, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:24,9963969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975767, endtime: 40975768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,0167525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975770, endtime: 40975770, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,0336601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975772, endtime: 40975772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,0496546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975773, endtime: 40975774, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,0815022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975776, endtime: 40975777, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,0953796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975778, endtime: 40975778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,1111854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975780, endtime: 40975780, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,1455118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975783, endtime: 40975783, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,1744888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975786, endtime: 40975786, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,4485072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975592, endtime: 40975813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,4485244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975594, endtime: 40975813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,4485319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975595, endtime: 40975813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,4485394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975597, endtime: 40975813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,4485449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975598, endtime: 40975813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,4485516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975600, endtime: 40975813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,4485568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975601, endtime: 40975813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,4485635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975603, endtime: 40975813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,4485687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975605, endtime: 40975813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,4485984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975606, endtime: 40975813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,4486039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975608, endtime: 40975813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,4486103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975611, endtime: 40975813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,4486158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975612, endtime: 40975813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,9140185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975787, endtime: 40975860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,9140345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975789, endtime: 40975860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,9140431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975791, endtime: 40975860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,9140514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975794, endtime: 40975860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,9140581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975796, endtime: 40975860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,9140656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975800, endtime: 40975860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,9140717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975801, endtime: 40975860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,9143263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975802, endtime: 40975860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,9143346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975803, endtime: 40975860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,9143418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975805, endtime: 40975860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,9143476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975806, endtime: 40975860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:25,9143545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975811, endtime: 40975860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:26,4707856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975456, endtime: 40975916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:26,4708019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975458, endtime: 40975916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:26,4708091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975459, endtime: 40975916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:26,4708163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975463, endtime: 40975916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:26,4708219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975465, endtime: 40975916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:26,4708285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975467, endtime: 40975916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:26,4708338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975469, endtime: 40975916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:26,4708404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975471, endtime: 40975916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:26,4708457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975473, endtime: 40975916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:26,4709335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975477, endtime: 40975916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:26,4709405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975478, endtime: 40975916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:26,4709468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975481, endtime: 40975916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:26,4716583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975483, endtime: 40975916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:27,3496958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975813, endtime: 40976004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:27,3497138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975816, endtime: 40976004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:27,3497218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975817, endtime: 40976004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:27,3497296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975820, endtime: 40976004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:27,3497359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975822, endtime: 40976004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:27,3497429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975825, endtime: 40976004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:27,3497489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975828, endtime: 40976004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:27,3497562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975830, endtime: 40976004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:27,3497620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975833, endtime: 40976004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:27,3497930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975834, endtime: 40976004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:27,3497994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975836, endtime: 40976004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:27,3498066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975838, endtime: 40976004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:27,3498124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975840, endtime: 40976004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,3643074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975346, endtime: 40976105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,3643287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975347, endtime: 40976105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,3643426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975348, endtime: 40976105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,3643534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975350, endtime: 40976105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,3643614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975351, endtime: 40976105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,3643678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975353, endtime: 40976105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,3643747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975355, endtime: 40976105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,3643806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975358, endtime: 40976105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,3643878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975359, endtime: 40976105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,3644180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975361, endtime: 40976105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,3644252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975364, endtime: 40976105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,3644307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975366, endtime: 40976105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,3644376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975368, endtime: 40976105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,4197452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975916, endtime: 40976111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,4197652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975917, endtime: 40976111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,4197726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975919, endtime: 40976111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,4197804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975920, endtime: 40976111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,4198015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975923, endtime: 40976111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,4198139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975926, endtime: 40976111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,4198239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975928, endtime: 40976111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,4198325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975930, endtime: 40976111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,4198389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975932, endtime: 40976111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,4199214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975933, endtime: 40976111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,4199289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975934, endtime: 40976111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,4199358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975936, endtime: 40976111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:28,4201650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975938, endtime: 40976111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:29,1423268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975679, endtime: 40976183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:29,1423376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975680, endtime: 40976183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:29,1423451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975680, endtime: 40976183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:29,1423509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975683, endtime: 40976183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:29,1423578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975684, endtime: 40976183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:29,1423631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975686, endtime: 40976183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:29,1423694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975687, endtime: 40976183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:29,1423750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975691, endtime: 40976183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:29,1423816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975694, endtime: 40976183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:29,1424556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975696, endtime: 40976183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:29,1424634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975698, endtime: 40976183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:29,1424689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975700, endtime: 40976183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:29,1425756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975701, endtime: 40976183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:30,7082825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976004, endtime: 40976339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:30,7082960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976005, endtime: 40976339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:30,7083035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976006, endtime: 40976339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:30,7083110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976008, endtime: 40976339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:30,7083168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976011, endtime: 40976339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:30,7083238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976014, endtime: 40976339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:30,7083293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976016, endtime: 40976339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:30,7083362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976019, endtime: 40976339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:30,7083418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976020, endtime: 40976339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:30,7083722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976023, endtime: 40976339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:30,7083781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976025, endtime: 40976339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:30,7083847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976027, endtime: 40976339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:30,7083902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976028, endtime: 40976339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,0848446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976105, endtime: 40976377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,0848626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976108, endtime: 40976377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,0848703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976109, endtime: 40976377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,0848778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976111, endtime: 40976377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,0848836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976114, endtime: 40976377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,0848908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976115, endtime: 40976377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,0848964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976117, endtime: 40976377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,0849030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976119, endtime: 40976377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,0849086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976122, endtime: 40976377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,0849366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976123, endtime: 40976377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,0849424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976126, endtime: 40976377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,0849493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976128, endtime: 40976377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,0856253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976130, endtime: 40976377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,7267302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976111, endtime: 40976441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,7267480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976112, endtime: 40976441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,7267563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976114, endtime: 40976441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,7267640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976115, endtime: 40976441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,7267704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976117, endtime: 40976441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,7267776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976119, endtime: 40976441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,7267834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976122, endtime: 40976441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,7267904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976123, endtime: 40976441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,7267965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976126, endtime: 40976441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,7268261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976128, endtime: 40976441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,7268325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976130, endtime: 40976441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,7268397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976131, endtime: 40976441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:31,7268455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976134, endtime: 40976441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,4909711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976339, endtime: 40976518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,4909880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976341, endtime: 40976518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,4909954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976344, endtime: 40976518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,4910029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976347, endtime: 40976518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,4910087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976349, endtime: 40976518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,4910157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976350, endtime: 40976518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,4910215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976354, endtime: 40976518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,4910284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976356, endtime: 40976518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,4910340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976358, endtime: 40976518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,4910639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976361, endtime: 40976518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,4910697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976362, endtime: 40976518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,4910763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976364, endtime: 40976518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,4910822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976366, endtime: 40976518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5635215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976183, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5635404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976184, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5635484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976186, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5635564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976187, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5635628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976191, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5635700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976194, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5635758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976195, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5635830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976197, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5635888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976198, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5636769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976200, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5636891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976200, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5637010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976204, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5637185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976518, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,5646527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976207, endtime: 40976525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,9556148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 7688, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:32,9558243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 11876, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:33,4345569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:33,4345677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:33,4356408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40976612, endtime: 40976612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:33,7057053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 8664, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0102960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976441, endtime: 40976670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0103129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976442, endtime: 40976670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0103201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976444, endtime: 40976670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0103276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976445, endtime: 40976670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0103334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976450, endtime: 40976670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0103403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976452, endtime: 40976670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0103456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976453, endtime: 40976670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0103522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976455, endtime: 40976670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0103575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976458, endtime: 40976670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0103869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976460, endtime: 40976670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0103927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976463, endtime: 40976670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0103993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976464, endtime: 40976670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0104049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976466, endtime: 40976670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,0813830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55083 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,1717313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,1721699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976686, endtime: 40976686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,1988113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976688, endtime: 40976688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,2191719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976690, endtime: 40976691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,2353761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976692, endtime: 40976692, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,2509225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976694, endtime: 40976694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,2668446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976695, endtime: 40976695, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,2832580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976697, endtime: 40976697, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,3002967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976698, endtime: 40976699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,3290745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976701, endtime: 40976702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,3343687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976702, endtime: 40976702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,3400201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976703, endtime: 40976703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,3598850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976705, endtime: 40976705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,3768589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976706, endtime: 40976706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,4094922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976709, endtime: 40976710, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,4548842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976714, endtime: 40976714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,4802426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976716, endtime: 40976717, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,4854759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976717, endtime: 40976717, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5177557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976720, endtime: 40976720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5350659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976722, endtime: 40976722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5507803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975812, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5507994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975860, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5508069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975862, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5508141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975864, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5508199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975866, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5508265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975867, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5508318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975869, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5508384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975870, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5508437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975872, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5508722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975873, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5508783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975878, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5509775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975881, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5509842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975884, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5517297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976724, endtime: 40976724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5690324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976725, endtime: 40976726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5792364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976726, endtime: 40976727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,5953134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976728, endtime: 40976728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6105787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976730, endtime: 40976730, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6276146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976731, endtime: 40976731, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6369045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976377, endtime: 40976732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6369220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976379, endtime: 40976732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6369300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976381, endtime: 40976732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6369375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976384, endtime: 40976732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6369433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976388, endtime: 40976732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6369502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976391, endtime: 40976732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6369561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976394, endtime: 40976732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6369630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976395, endtime: 40976732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6369685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976397, endtime: 40976732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6369971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976398, endtime: 40976732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6370034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976400, endtime: 40976732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6370101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976401, endtime: 40976732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6370159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976401, endtime: 40976732, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6429953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976733, endtime: 40976733, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,6759401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976736, endtime: 40976736, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,7070684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976739, endtime: 40976739, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,7197905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976741, endtime: 40976741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,7358587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976742, endtime: 40976742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,7522078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976744, endtime: 40976744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,7669726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976745, endtime: 40976745, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,7872800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976747, endtime: 40976747, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,7978685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976748, endtime: 40976748, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,8147612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976750, endtime: 40976750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,8451656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976753, endtime: 40976753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,8615482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976755, endtime: 40976755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:34,8773171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976756, endtime: 40976756, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,3604544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,8224401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976525, endtime: 40976851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,8224573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976526, endtime: 40976851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,8224647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976528, endtime: 40976851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,8224722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976530, endtime: 40976851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,8224778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976531, endtime: 40976851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,8224847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976533, endtime: 40976851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,8224902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976536, endtime: 40976851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,8224969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976537, endtime: 40976851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,8225027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976539, endtime: 40976851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,8225323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976542, endtime: 40976851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,8225384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976544, endtime: 40976851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,8225451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976545, endtime: 40976851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:35,8225506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976547, endtime: 40976851, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2055485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976759, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2055748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976670, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2055845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976672, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2055917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976675, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2055989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976677, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2056047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976678, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2056119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976680, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2056177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976683, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2056247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976688, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2056527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976690, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2056599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976692, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2056657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976694, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2056723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976695, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,2056781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976697, endtime: 40976989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,7630986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976851, endtime: 40977045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,7631174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976851, endtime: 40977045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,7631254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976853, endtime: 40977045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,7631335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976855, endtime: 40977045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,7631398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976856, endtime: 40977045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,7631470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976858, endtime: 40977045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,7631531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976859, endtime: 40977045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,7631603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976861, endtime: 40977045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,7631664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976862, endtime: 40977045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,7631966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976864, endtime: 40977045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,7632027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976866, endtime: 40977045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,7632099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976867, endtime: 40977045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:37,7632160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976869, endtime: 40977045, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,6964106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976732, endtime: 40977238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,6964270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976736, endtime: 40977238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,6964356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976739, endtime: 40977238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,6964414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976741, endtime: 40977238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,6964483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976742, endtime: 40977238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,6964536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976744, endtime: 40977238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,6964602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976745, endtime: 40977238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,6965505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976747, endtime: 40977238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,6966262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976748, endtime: 40977238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,6966334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976750, endtime: 40977238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,6966397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976753, endtime: 40977238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,6966453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976755, endtime: 40977238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,6966517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976756, endtime: 40977238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,9095953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976989, endtime: 40977260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,9096180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976991, endtime: 40977260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,9096293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976992, endtime: 40977260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,9096407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976994, endtime: 40977260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,9096501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976998, endtime: 40977260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,9096609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977000, endtime: 40977260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,9096698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977001, endtime: 40977260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,9096803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977001, endtime: 40977260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,9096895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977002, endtime: 40977260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,9097252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977003, endtime: 40977260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,9097346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977005, endtime: 40977260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,9097449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977006, endtime: 40977260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:39,9097543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977010, endtime: 40977260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,0370206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977045, endtime: 40977272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,0370375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977047, endtime: 40977272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,0370447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977048, endtime: 40977272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,0370521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977050, endtime: 40977272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,0370580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977051, endtime: 40977272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,0370646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977053, endtime: 40977272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,0370704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977055, endtime: 40977272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,0370771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977056, endtime: 40977272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,0370823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977060, endtime: 40977272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,0371111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977063, endtime: 40977272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,0371170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977066, endtime: 40977272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,0371236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977067, endtime: 40977272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,0371292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977070, endtime: 40977272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,2041876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975482, endtime: 40977289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,2042036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975483, endtime: 40977289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,2042122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975486, endtime: 40977289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,2042186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975487, endtime: 40977289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,2042258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975489, endtime: 40977289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,2042316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975491, endtime: 40977289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,2042386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975492, endtime: 40977289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,2042441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975494, endtime: 40977289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,2042510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975495, endtime: 40977289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,2042760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975497, endtime: 40977289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,2042832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975498, endtime: 40977289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,2042887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975500, endtime: 40977289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,2042956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40975501, endtime: 40977289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,4338396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976724, endtime: 40977312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,4338568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976725, endtime: 40977312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,4338648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976726, endtime: 40977312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,4338709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976728, endtime: 40977312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,4338776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976730, endtime: 40977312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,4338831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976731, endtime: 40977312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,4338898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976733, endtime: 40977312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,4338950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976736, endtime: 40977312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,4339017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976739, endtime: 40977312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,4339069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976741, endtime: 40977312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,4339377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976742, endtime: 40977312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,4339435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976744, endtime: 40977312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:40,4339502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976745, endtime: 40977312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,3605586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,4381899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,4390945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977412, endtime: 40977413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,4528700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55040 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,4533549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977414, endtime: 40977414, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,4696092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977416, endtime: 40977416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,4852149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977417, endtime: 40977417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,5006395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977419, endtime: 40977419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,5178372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977420, endtime: 40977420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,5318626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977422, endtime: 40977422, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,5486913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977423, endtime: 40977423, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,5557781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,5561355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977424, endtime: 40977424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,5794384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977426, endtime: 40977427, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,5794605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977426, endtime: 40977427, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6125236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977430, endtime: 40977430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6125480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977430, endtime: 40977430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6266709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977431, endtime: 40977431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6266953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977431, endtime: 40977431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6579516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977434, endtime: 40977434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6579724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977434, endtime: 40977434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6634166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976761, endtime: 40977435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6634340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976762, endtime: 40977435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6634432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976764, endtime: 40977435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6634495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976768, endtime: 40977435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6634567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976770, endtime: 40977435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6634623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976770, endtime: 40977435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6634689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976772, endtime: 40977435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6634745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976775, endtime: 40977435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6634811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976777, endtime: 40977435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6635133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976778, endtime: 40977435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6635205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976781, endtime: 40977435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6635263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976784, endtime: 40977435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6635329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40976989, endtime: 40977435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6863191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977436, endtime: 40977437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,6863405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977436, endtime: 40977437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,7056762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977439, endtime: 40977439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,7056989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977439, endtime: 40977439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,7256796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977441, endtime: 40977441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,7256999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977441, endtime: 40977441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,7368622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977442, endtime: 40977442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,7368821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977442, endtime: 40977442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,7515935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977444, endtime: 40977444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,7516129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977444, endtime: 40977444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,7702352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977445, endtime: 40977446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,7702582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977445, endtime: 40977446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,7826806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977447, endtime: 40977447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,7827235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977447, endtime: 40977447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,8007713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977448, endtime: 40977449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,8007940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977448, endtime: 40977449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,8136250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977450, endtime: 40977450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,8136474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977450, endtime: 40977450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,8311793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977451, endtime: 40977452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,8312003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977451, endtime: 40977452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,8448589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977453, endtime: 40977453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,8448800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977453, endtime: 40977453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,8782857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977456, endtime: 40977456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,8783076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977456, endtime: 40977456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,9070832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977459, endtime: 40977459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,9071045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977459, endtime: 40977459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,9225704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977461, endtime: 40977461, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,9382423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977462, endtime: 40977462, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,9553433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977464, endtime: 40977464, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:41,9867922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977467, endtime: 40977467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,0028008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977469, endtime: 40977469, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,0343348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977472, endtime: 40977472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,0485519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977473, endtime: 40977473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,0977136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977478, endtime: 40977478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1113705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977480, endtime: 40977480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1232811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977461, endtime: 40977481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1233027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977462, endtime: 40977481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1233113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977464, endtime: 40977481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1233196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977467, endtime: 40977481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1233257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977469, endtime: 40977481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1236452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977472, endtime: 40977481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1236543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977473, endtime: 40977481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1236618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977478, endtime: 40977481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1236676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977480, endtime: 40977481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1293076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977481, endtime: 40977482, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1435508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977483, endtime: 40977483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1773068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977486, endtime: 40977486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,1889187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977487, endtime: 40977488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4217287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977272, endtime: 40977511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4217445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977275, endtime: 40977511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4217517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977276, endtime: 40977511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4217591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977278, endtime: 40977511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4217650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977280, endtime: 40977511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4217719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977281, endtime: 40977511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4217774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977283, endtime: 40977511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4217844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977284, endtime: 40977511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4217896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977286, endtime: 40977511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4218179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977289, endtime: 40977511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4218234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977290, endtime: 40977511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4218303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977292, endtime: 40977511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4218359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977294, endtime: 40977511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4866709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977481, endtime: 40977517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4866911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977483, endtime: 40977517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4866994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977486, endtime: 40977517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4867080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977487, endtime: 40977517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4867147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977491, endtime: 40977517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4867221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977492, endtime: 40977517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4867282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977494, endtime: 40977517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4867357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977497, endtime: 40977517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4867418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977498, endtime: 40977517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4867745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977500, endtime: 40977517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4867806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977503, endtime: 40977517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4867875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977505, endtime: 40977517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:42,4867933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977505, endtime: 40977517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,3393945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977312, endtime: 40977603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,3394186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977314, endtime: 40977603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,3394272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977316, endtime: 40977603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,3394358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977319, endtime: 40977603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,3394425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977322, endtime: 40977603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,3394499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977326, endtime: 40977603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,3394563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977330, endtime: 40977603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,3394638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977333, endtime: 40977603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,3394702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977336, endtime: 40977603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,3395115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977338, endtime: 40977603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,3395203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977341, endtime: 40977603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,3395303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977342, endtime: 40977603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,3396699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977345, endtime: 40977603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,5191637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,5191734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:43,5195560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40977621, endtime: 40977621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,5691915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977511, endtime: 40977726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,5692092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977512, endtime: 40977726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,5692170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977514, endtime: 40977726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,5692244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977516, endtime: 40977726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,5692305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977517, endtime: 40977726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,5692377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977519, endtime: 40977726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,5692436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977520, endtime: 40977726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,5692508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977522, endtime: 40977726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,5692566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977523, endtime: 40977726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,5692871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977525, endtime: 40977726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,5692934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977526, endtime: 40977726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,5693004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977528, endtime: 40977726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,5693064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977530, endtime: 40977726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,6683800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977435, endtime: 40977735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,6683961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977436, endtime: 40977735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,6684030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977439, endtime: 40977735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,6684102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977441, endtime: 40977735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,6684158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977442, endtime: 40977735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,6684224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977444, endtime: 40977735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,6684277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977445, endtime: 40977735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,6684343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977447, endtime: 40977735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,6684399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977448, endtime: 40977735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,6684679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977450, endtime: 40977735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,6684737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977451, endtime: 40977735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,6684800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977453, endtime: 40977735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:44,6684856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977456, endtime: 40977735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,4923309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977735, endtime: 40977918, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,4923483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977739, endtime: 40977918, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,4923555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977741, endtime: 40977918, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,4923633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977742, endtime: 40977918, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,4923688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977744, endtime: 40977918, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,4923757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977747, endtime: 40977918, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,4923813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977749, endtime: 40977918, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,4923879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977750, endtime: 40977918, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,4923937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977753, endtime: 40977918, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,4924234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977755, endtime: 40977918, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,4924292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977756, endtime: 40977918, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,4924361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977758, endtime: 40977918, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,4924417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977759, endtime: 40977918, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,7206727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977260, endtime: 40977941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,7206888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977261, endtime: 40977941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,7206979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977262, endtime: 40977941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,7207046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977264, endtime: 40977941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,7207118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977266, endtime: 40977941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,7207176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977267, endtime: 40977941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,7207245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977269, endtime: 40977941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,7207303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977270, endtime: 40977941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,7207372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977272, endtime: 40977941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,7208165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977275, endtime: 40977941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,7208254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977276, endtime: 40977941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,7208314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977278, endtime: 40977941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:46,7212819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977280, endtime: 40977941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,3386038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55100 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6009235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977517, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6009390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977519, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6009476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977520, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6009537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977522, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6009607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977523, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6009659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977525, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6009726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977526, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6009781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977528, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6009845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977530, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6010826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977531, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6010923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977533, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6010978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977534, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6011094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977603, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6011166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977604, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6011222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977604, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6011294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977607, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6011355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977608, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6011427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977609, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6012058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977611, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6012139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977613, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6012191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977614, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6012258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977617, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6012313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977619, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6012380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977620, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6012435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977622, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,6012579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977536, endtime: 40978029, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,8181247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977726, endtime: 40978050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,8181413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977726, endtime: 40978050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,8181485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977728, endtime: 40978050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,8181557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977730, endtime: 40978050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,8181612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977731, endtime: 40978050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,8181682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977734, endtime: 40978050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,8181734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977736, endtime: 40978050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,8181801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977739, endtime: 40978050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,8181856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977741, endtime: 40978050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,8182144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977742, endtime: 40978050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,8182200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977744, endtime: 40978050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,8182266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977747, endtime: 40978050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:47,8182322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977749, endtime: 40978050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:48,5061601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977491, endtime: 40978119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:48,5061759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977492, endtime: 40978119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:48,5061850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977494, endtime: 40978119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:48,5061917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977497, endtime: 40978119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:48,5061992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977498, endtime: 40978119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:48,5062050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977500, endtime: 40978119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:48,5062119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977503, endtime: 40978119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:48,5062175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977505, endtime: 40978119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:48,5062244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977505, endtime: 40978119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:48,5062526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977508, endtime: 40978119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:48,5062596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977509, endtime: 40978119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:48,5062654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977511, endtime: 40978119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:48,5062820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977512, endtime: 40978119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,7503623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977941, endtime: 40978244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,7503803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977942, endtime: 40978244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,7503883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977945, endtime: 40978244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,7503961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977947, endtime: 40978244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,7504022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977950, endtime: 40978244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,7504091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977951, endtime: 40978244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,7504149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977953, endtime: 40978244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,7504221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977956, endtime: 40978244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,7504277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977958, endtime: 40978244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,7505047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977959, endtime: 40978244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,7505122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977962, endtime: 40978244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,7505194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977964, endtime: 40978244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,7506025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977967, endtime: 40978244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,8288448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978029, endtime: 40978251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,8288631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978030, endtime: 40978251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,8288703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978031, endtime: 40978251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,8288772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978033, endtime: 40978251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,8288827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978036, endtime: 40978251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,8288891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978037, endtime: 40978251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,8288947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978039, endtime: 40978251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,8289010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978041, endtime: 40978251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,8289063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978042, endtime: 40978251, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,8289382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978044, endtime: 40978252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,8289443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978045, endtime: 40978252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,8289504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978047, endtime: 40978252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,8289559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978048, endtime: 40978252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,9133261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978029, endtime: 40978260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,9133444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978030, endtime: 40978260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,9133516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978031, endtime: 40978260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,9133591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978033, endtime: 40978260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,9133649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978036, endtime: 40978260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,9133718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978037, endtime: 40978260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,9133771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978039, endtime: 40978260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,9133840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978041, endtime: 40978260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,9133896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978042, endtime: 40978260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,9134669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978044, endtime: 40978260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,9134738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978045, endtime: 40978260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,9134804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978047, endtime: 40978260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:49,9142545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978048, endtime: 40978260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,1585055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977918, endtime: 40978284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,1585215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977919, endtime: 40978284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,1585299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977920, endtime: 40978284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,1585376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977922, endtime: 40978284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,1585443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977923, endtime: 40978284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,1585515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977925, endtime: 40978284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,1585573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977929, endtime: 40978284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,1585642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977931, endtime: 40978284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,1585700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977933, endtime: 40978284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,1585991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977935, endtime: 40978284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,1586052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977937, endtime: 40978284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,1586121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977939, endtime: 40978284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,1586180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40977942, endtime: 40978284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,8183009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978260, endtime: 40978350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,8183156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978262, endtime: 40978350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,8183222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978264, endtime: 40978350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,8183291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978266, endtime: 40978350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,8183344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978269, endtime: 40978350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,8183410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978272, endtime: 40978350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,8183463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978274, endtime: 40978350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,8183527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978275, endtime: 40978350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,8183579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978277, endtime: 40978350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,8183879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978278, endtime: 40978350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,8183934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978280, endtime: 40978350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,8183998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978281, endtime: 40978350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:50,8184048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978283, endtime: 40978350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,3193481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978050, endtime: 40978401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,3193650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978051, endtime: 40978401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,3193728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978052, endtime: 40978401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,3193806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978056, endtime: 40978401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,3193867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978058, endtime: 40978401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,3193936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978060, endtime: 40978401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,3193994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978064, endtime: 40978401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,3194060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978066, endtime: 40978401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,3194119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978067, endtime: 40978401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,3194412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978069, endtime: 40978401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,3194473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978071, endtime: 40978401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,3194540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978073, endtime: 40978401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,3194598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978075, endtime: 40978401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,7104479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978244, endtime: 40978440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,7104646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978245, endtime: 40978440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,7104723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978247, endtime: 40978440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,7104801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978248, endtime: 40978440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,7104859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978252, endtime: 40978440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,7104928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978253, endtime: 40978440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,7104986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978256, endtime: 40978440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,7105056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978260, endtime: 40978440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,7105114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978262, endtime: 40978440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,7105806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978264, endtime: 40978440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,7105879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978266, endtime: 40978440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,7105951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978269, endtime: 40978440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:51,7790977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978272, endtime: 40978447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,7367788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978252, endtime: 40978542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,7367996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978253, endtime: 40978542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,7368073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978256, endtime: 40978542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,7368148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978261, endtime: 40978542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,7368209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978262, endtime: 40978542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,7368278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978264, endtime: 40978542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,7368336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978266, endtime: 40978542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,7369281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978269, endtime: 40978542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,7369353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978272, endtime: 40978542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,7369420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978274, endtime: 40978542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,7369472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978275, endtime: 40978542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,7369539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978277, endtime: 40978542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,7369592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978278, endtime: 40978542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:52,8105106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978542, endtime: 40978550, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,6897139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,6897272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,6901533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40978638, endtime: 40978638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,7407379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978119, endtime: 40978643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,7407568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978120, endtime: 40978643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,7407648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978122, endtime: 40978643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,7407723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978124, endtime: 40978643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,7407784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978125, endtime: 40978643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,7407853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978127, endtime: 40978643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,7407908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978128, endtime: 40978643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,7407975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978130, endtime: 40978643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,7408030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978131, endtime: 40978643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,7408310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978133, endtime: 40978643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,7408368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978134, endtime: 40978643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,7408438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978136, endtime: 40978643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:53,7408493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978137, endtime: 40978643, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,0459756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978401, endtime: 40978673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,0459925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978401, endtime: 40978673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,0459999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978403, endtime: 40978673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,0460074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978405, endtime: 40978673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,0460135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978406, endtime: 40978673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,0460204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978408, endtime: 40978673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,0460263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978409, endtime: 40978673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,0460332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978411, endtime: 40978673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,0460387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978414, endtime: 40978673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,0461157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978416, endtime: 40978673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,0461235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978417, endtime: 40978673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,0461307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978419, endtime: 40978673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,0464582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978420, endtime: 40978673, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2207181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978350, endtime: 40978691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2207364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978351, endtime: 40978691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2207439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978353, endtime: 40978691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2207511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978355, endtime: 40978691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2207566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978358, endtime: 40978691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2209063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978359, endtime: 40978691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2209137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978361, endtime: 40978691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2209204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978362, endtime: 40978691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2209256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978364, endtime: 40978691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2209323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978366, endtime: 40978691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2209376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978367, endtime: 40978691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2209439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978369, endtime: 40978691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2209492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978370, endtime: 40978691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2952207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978544, endtime: 40978698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2952384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978547, endtime: 40978698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2952479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978548, endtime: 40978698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2952545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978550, endtime: 40978698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2952617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978551, endtime: 40978698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2952678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978555, endtime: 40978698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2952747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978556, endtime: 40978698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2952806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978558, endtime: 40978698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2952872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978559, endtime: 40978698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2953487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978561, endtime: 40978698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2953573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978562, endtime: 40978698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,2953631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978564, endtime: 40978698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,4925517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978284, endtime: 40978718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,4925702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978287, endtime: 40978718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,4925783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978289, endtime: 40978718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,4925863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978291, endtime: 40978718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,4925924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978294, endtime: 40978718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,4925993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978295, endtime: 40978718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,4926051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978297, endtime: 40978718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,4927498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978299, endtime: 40978718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,4927608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978300, endtime: 40978718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,4927686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978300, endtime: 40978718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,4927753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978304, endtime: 40978718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,4927825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978305, endtime: 40978718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:54,4927886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978306, endtime: 40978718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:55,0300060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978440, endtime: 40978772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:55,0300213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978441, endtime: 40978772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:55,0300301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978442, endtime: 40978772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:55,0300368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978444, endtime: 40978772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:55,0300440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978449, endtime: 40978772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:55,0300501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978450, endtime: 40978772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:55,0300570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978452, endtime: 40978772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:55,0300631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978453, endtime: 40978772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:55,0300703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978455, endtime: 40978772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:55,0301509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978456, endtime: 40978772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:55,0301601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978458, endtime: 40978772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:55,0301659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978459, endtime: 40978772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:55,0305845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978461, endtime: 40978772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,4666242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978692, endtime: 40978915, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,4666406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978694, endtime: 40978915, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,4666478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978695, endtime: 40978915, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,4666550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978696, endtime: 40978915, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,4666605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978697, endtime: 40978915, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,4666669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978697, endtime: 40978915, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,4666724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978698, endtime: 40978915, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,4666788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978698, endtime: 40978915, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,4666843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978699, endtime: 40978915, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,4667154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978700, endtime: 40978915, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,4667212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978700, endtime: 40978915, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,4667276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978701, endtime: 40978915, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,4667331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978703, endtime: 40978915, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,5085129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978673, endtime: 40978919, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,5085317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978675, endtime: 40978919, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,5085397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978677, endtime: 40978919, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,5085478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978678, endtime: 40978919, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,5085539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978680, endtime: 40978919, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,5085614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978681, endtime: 40978919, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,5085672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978683, endtime: 40978919, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,5085744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978684, endtime: 40978919, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,5085805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978686, endtime: 40978919, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,5086447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978692, endtime: 40978919, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,5086525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978694, endtime: 40978919, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:56,5086597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978695, endtime: 40978919, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,1367278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978643, endtime: 40978982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,1367460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978644, endtime: 40978982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,1367541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978645, endtime: 40978982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,1367621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978647, endtime: 40978982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,1367685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978648, endtime: 40978982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,1367757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978650, endtime: 40978982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,1367818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978653, endtime: 40978982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,1367890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978656, endtime: 40978982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,1367948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978658, endtime: 40978982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,1368242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978659, endtime: 40978982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,1368305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978663, endtime: 40978982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,1369452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978666, endtime: 40978982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,1369555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978667, endtime: 40978982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5382327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978566, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5382490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978698, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5382573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978699, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5382634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978699, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5382704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978700, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5382759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978700, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5382825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978703, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5382881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978705, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5382947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978706, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5383003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978709, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5383313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978711, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5383371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978714, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5383438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978717, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:57,5386355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979022, endtime: 40979022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,2027907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978772, endtime: 40979089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,2028087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978773, endtime: 40979089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,2028164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978775, endtime: 40979089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,2028245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978776, endtime: 40979089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,2028308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978778, endtime: 40979089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,2028383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978780, endtime: 40979089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,2028441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978782, endtime: 40979089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,2028513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978783, endtime: 40979089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,2028574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978784, endtime: 40979089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,2029502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978786, endtime: 40979089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,2029583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978787, endtime: 40979089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,2029655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978789, endtime: 40979089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,2031636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978791, endtime: 40979089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,3648679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978718, endtime: 40979105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,3648865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978720, endtime: 40979105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,3648942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978722, endtime: 40979105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,3649014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978723, endtime: 40979105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,3649075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978725, endtime: 40979105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,3649142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978727, endtime: 40979105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,3649197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978728, endtime: 40979105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,3649264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978731, endtime: 40979105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,3649319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978732, endtime: 40979105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,3649610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978735, endtime: 40979105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,3649671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978736, endtime: 40979105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,3649737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978738, endtime: 40979105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:58,3649793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978739, endtime: 40979105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,5148949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979023, endtime: 40979220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,5149264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979025, endtime: 40979220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,5149353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979028, endtime: 40979220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,5149442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979030, endtime: 40979220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,5149511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979033, endtime: 40979220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,5149589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979036, endtime: 40979220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,5149652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979037, endtime: 40979220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,5149730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979039, endtime: 40979220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,5149796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979042, endtime: 40979220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,5150586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979045, endtime: 40979220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,5150669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979047, endtime: 40979220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,5150741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979050, endtime: 40979220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,5154817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979052, endtime: 40979220, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,9874272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978696, endtime: 40979267, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,9874430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978919, endtime: 40979267, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,9874500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978922, endtime: 40979267, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,9874572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978924, endtime: 40979267, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,9874627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978925, endtime: 40979267, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,9874694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978928, endtime: 40979267, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,9874746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978931, endtime: 40979267, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,9889087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978934, endtime: 40979268, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,9889172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978936, endtime: 40979268, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,9889239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978938, endtime: 40979268, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,9889294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978941, endtime: 40979268, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,9889361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978942, endtime: 40979268, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:58:59,9889414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978944, endtime: 40979268, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,1360016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978915, endtime: 40979282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,1360213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978917, endtime: 40979282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,1360293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978919, endtime: 40979282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,1360371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978922, endtime: 40979282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,1360434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978925, endtime: 40979282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,1360506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978928, endtime: 40979282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,1360565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978931, endtime: 40979282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,1360634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978934, endtime: 40979282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,1360692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978936, endtime: 40979282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,1360994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978938, endtime: 40979282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,1361055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978941, endtime: 40979282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,1362146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978942, endtime: 40979282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,1362260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978944, endtime: 40979282, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,6469348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979220, endtime: 40979333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,6469517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979222, endtime: 40979333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,6469589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979223, endtime: 40979333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,6469661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979225, endtime: 40979333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,6469716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979228, endtime: 40979333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,6469783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979230, endtime: 40979333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,6469835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979231, endtime: 40979333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,6469902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979233, endtime: 40979333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,6469955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979236, endtime: 40979333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,6470589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979237, endtime: 40979333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,6470658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979239, endtime: 40979333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,6470725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979241, endtime: 40979333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,7344643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978982, endtime: 40979342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,7344853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978984, endtime: 40979342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,7344931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978986, endtime: 40979342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,7345008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978989, endtime: 40979342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,7345069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978991, endtime: 40979342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,7345136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978992, endtime: 40979342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,7345197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978994, endtime: 40979342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,7345263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978995, endtime: 40979342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,7345321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978997, endtime: 40979342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,7345621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40978998, endtime: 40979342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,7345682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979000, endtime: 40979342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,7345748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979001, endtime: 40979342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,7345806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979003, endtime: 40979342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:00,8071261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979242, endtime: 40979349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:01,0672019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979089, endtime: 40979375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:01,0672194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979091, endtime: 40979375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:01,0672277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979092, endtime: 40979375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:01,0672360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979095, endtime: 40979375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:01,0672424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979099, endtime: 40979375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:01,0672504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979102, endtime: 40979375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:01,0672568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979102, endtime: 40979375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:01,0672643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979103, endtime: 40979375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:01,0672712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979105, endtime: 40979375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:01,0673499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979106, endtime: 40979375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:01,0673576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979108, endtime: 40979375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:01,0673646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979109, endtime: 40979375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:01,0677486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979111, endtime: 40979375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,1456024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979333, endtime: 40979483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,1456165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979334, endtime: 40979483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,1456246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979336, endtime: 40979483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,1456307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979337, endtime: 40979483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,1456373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979339, endtime: 40979483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,1456429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979342, endtime: 40979483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,1456495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979344, endtime: 40979483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,1456548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979345, endtime: 40979483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,1456614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979350, endtime: 40979483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,1457534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979351, endtime: 40979483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,1457620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979354, endtime: 40979483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,1457678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979356, endtime: 40979483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,1458518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979359, endtime: 40979483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,4278499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979267, endtime: 40979511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,4278660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979269, endtime: 40979511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,4278738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979270, endtime: 40979511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,4278812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979272, endtime: 40979511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,4278873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979273, endtime: 40979511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,4278945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979275, endtime: 40979511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,4279001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979276, endtime: 40979511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,4279070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979278, endtime: 40979511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,4279128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979280, endtime: 40979511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,4279403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979281, endtime: 40979511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,4279464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979283, endtime: 40979511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,4279533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979284, endtime: 40979511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,4279591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979286, endtime: 40979511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,5003987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979511, endtime: 40979519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,7801874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979105, endtime: 40979547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,7802079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979106, endtime: 40979547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,7802162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979108, endtime: 40979547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,7802242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979109, endtime: 40979547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,7802303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979111, endtime: 40979547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,7802375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979113, endtime: 40979547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,7802433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979116, endtime: 40979547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,7802503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979117, endtime: 40979547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,7802558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979119, endtime: 40979547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,7802846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979120, endtime: 40979547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,7803966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979123, endtime: 40979547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,7804082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979125, endtime: 40979547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,7804148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979127, endtime: 40979547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,8693978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979282, endtime: 40979556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,8694174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979284, endtime: 40979556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,8694260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979286, endtime: 40979556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,8694341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979289, endtime: 40979556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,8694407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979291, endtime: 40979556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,8694485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979292, endtime: 40979556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,8694546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979294, endtime: 40979556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,8694620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979296, endtime: 40979556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,8694681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979299, endtime: 40979556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,8694961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979302, endtime: 40979556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,8695030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979305, endtime: 40979556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,8695102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979308, endtime: 40979556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:02,8695166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979309, endtime: 40979556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:03,8682120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979342, endtime: 40979655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:03,8682308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979344, endtime: 40979655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:03,8682386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979345, endtime: 40979655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:03,8682466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979350, endtime: 40979655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:03,8682524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979351, endtime: 40979655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:03,8682596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979354, endtime: 40979655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:03,8682652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979355, endtime: 40979655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:03,8682721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979356, endtime: 40979655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:03,8682785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979359, endtime: 40979655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:03,8683297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979361, endtime: 40979655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:03,8683372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979362, endtime: 40979655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:03,8683438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979364, endtime: 40979655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:03,8683494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979367, endtime: 40979655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,0225009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,0225172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,0229489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40979671, endtime: 40979671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,5086991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979512, endtime: 40979719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,5087193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979516, endtime: 40979719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,5087298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979517, endtime: 40979719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,5087376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979521, endtime: 40979719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,5087459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979523, endtime: 40979719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,5087522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979527, endtime: 40979719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,5087594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979528, endtime: 40979719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,5087655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979530, endtime: 40979719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,5087725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979533, endtime: 40979719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,5088597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979534, endtime: 40979719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,5088692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979536, endtime: 40979719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:04,5088755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979537, endtime: 40979719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2483279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979375, endtime: 40979793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2483459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979376, endtime: 40979793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2483539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979378, endtime: 40979793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2483617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979380, endtime: 40979793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2483678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979381, endtime: 40979793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2483747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979383, endtime: 40979793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2483805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979384, endtime: 40979793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2483874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979387, endtime: 40979793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2483933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979389, endtime: 40979793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2484223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979391, endtime: 40979793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2484284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979392, endtime: 40979793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2484354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979395, endtime: 40979793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2484412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979397, endtime: 40979793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2928943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979483, endtime: 40979798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2929137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979484, endtime: 40979798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2929217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979486, endtime: 40979798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2929297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979489, endtime: 40979798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2929358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979491, endtime: 40979798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2929430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979492, endtime: 40979798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2929489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979494, endtime: 40979798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2929558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979495, endtime: 40979798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2929619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979497, endtime: 40979798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2930406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979498, endtime: 40979798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2930483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979500, endtime: 40979798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2930555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979501, endtime: 40979798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,2935440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979503, endtime: 40979798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,5954863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979547, endtime: 40979828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,5955040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979548, endtime: 40979828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,5955112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979550, endtime: 40979828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,5955187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979552, endtime: 40979828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,5955245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979555, endtime: 40979828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,5955309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979556, endtime: 40979828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,5955364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979558, endtime: 40979828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,5955428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979561, endtime: 40979828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,5955484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979562, endtime: 40979828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,5955797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979564, endtime: 40979828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,5955855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979566, endtime: 40979828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,5955919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979567, endtime: 40979828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:05,5955971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979569, endtime: 40979828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,0287676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979793, endtime: 40979971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,0287895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979795, endtime: 40979971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,0287986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979798, endtime: 40979971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,0288072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979800, endtime: 40979971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,0288142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979801, endtime: 40979971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,0288216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979803, endtime: 40979971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,0288280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979805, endtime: 40979971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,0288355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979806, endtime: 40979971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,0288419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979808, endtime: 40979971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,0288745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979809, endtime: 40979971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,0288812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979813, endtime: 40979971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,0288884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979816, endtime: 40979971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,0288948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979819, endtime: 40979971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,5168248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979655, endtime: 40980020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,5168431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979658, endtime: 40980020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,5168503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979659, endtime: 40980020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,5168575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979661, endtime: 40980020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,5168633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979664, endtime: 40980020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,5168700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979666, endtime: 40980020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,5168755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979667, endtime: 40980020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,5168822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979669, endtime: 40980020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,5168877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979672, endtime: 40980020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,5169190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979673, endtime: 40980020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,5169246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979675, endtime: 40980020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,5169312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979676, endtime: 40980020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,5169365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979678, endtime: 40980020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,7376507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979556, endtime: 40980042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,7376687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979556, endtime: 40980042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,7376759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979558, endtime: 40980042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,7376837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979561, endtime: 40980042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,7376892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979562, endtime: 40980042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,7376958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979564, endtime: 40980042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,7377011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979566, endtime: 40980042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,7377080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979567, endtime: 40980042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,7377133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979569, endtime: 40980042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,7377418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979570, endtime: 40980042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,7377474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979572, endtime: 40980042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,7377538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979573, endtime: 40980042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:07,7377590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979575, endtime: 40980042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,0078308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979971, endtime: 40980169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,0078521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979973, endtime: 40980169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,0078598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979975, endtime: 40980169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,0078679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979976, endtime: 40980169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,0078740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979978, endtime: 40980169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,0082483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979980, endtime: 40980169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,0082707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979981, endtime: 40980169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,0082790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979983, endtime: 40980169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,0082854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979984, endtime: 40980169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,0082929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979986, endtime: 40980169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,0082993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979987, endtime: 40980169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,0083065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979989, endtime: 40980169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,0083128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979991, endtime: 40980169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,4328187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55069 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,5209106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,5213178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980221, endtime: 40980221, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,5335288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980222, endtime: 40980222, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,5495202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980223, endtime: 40980224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,5806167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980227, endtime: 40980227, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,6128405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980230, endtime: 40980230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,6429133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980233, endtime: 40980233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,6568761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980234, endtime: 40980234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,6731986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980236, endtime: 40980236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,6897940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980238, endtime: 40980238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7050024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980239, endtime: 40980239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7213775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980241, endtime: 40980241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7371947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980242, endtime: 40980242, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7530348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980244, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7530544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980042, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7530630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980044, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7530691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980045, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7530758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980048, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7530813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980050, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7530877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980051, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7530932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980053, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7530996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980056, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7531254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980058, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7531323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980059, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7531376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980061, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7531439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980062, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7531495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980064, endtime: 40980244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7728640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980245, endtime: 40980246, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,7822938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980247, endtime: 40980247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,8000811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980248, endtime: 40980249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,8136219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980250, endtime: 40980250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,8297510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980251, endtime: 40980252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,8452038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980253, endtime: 40980253, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,8619425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980255, endtime: 40980255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,8894336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980256, endtime: 40980258, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,9089993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980259, endtime: 40980260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,9496897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980262, endtime: 40980264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,9702952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980266, endtime: 40980266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:09,9891500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980267, endtime: 40980268, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,0037514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980269, endtime: 40980269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,0191028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980270, endtime: 40980271, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,0505786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980273, endtime: 40980274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,0652689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980275, endtime: 40980275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,0794148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980276, endtime: 40980277, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,0952328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980278, endtime: 40980278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,1105407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980280, endtime: 40980280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,1275977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980281, endtime: 40980281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,1421780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980283, endtime: 40980283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,1575837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980284, endtime: 40980284, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,1743423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980286, endtime: 40980286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,2142009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980289, endtime: 40980290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,5137661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979828, endtime: 40980320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,5137816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979830, endtime: 40980320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,5137997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979831, endtime: 40980320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,5138080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979834, endtime: 40980320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,5138143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979836, endtime: 40980320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,5138218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979838, endtime: 40980320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,5138279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979841, endtime: 40980320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,5138351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979842, endtime: 40980320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,5138412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979845, endtime: 40980320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,5138739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979847, endtime: 40980320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,5138797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979849, endtime: 40980320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,5138864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979850, endtime: 40980320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:10,5138919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979852, endtime: 40980320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,3779314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55127 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,4729868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,4735188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980416, endtime: 40980416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,4858810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980417, endtime: 40980417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,5176039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980420, endtime: 40980420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,5317332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980422, endtime: 40980422, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,5487120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980423, endtime: 40980423, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,5637723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980425, endtime: 40980425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,5957481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980428, endtime: 40980428, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,6111527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980430, endtime: 40980430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,6427302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980433, endtime: 40980433, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,6570307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980434, endtime: 40980434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,6726284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980436, endtime: 40980436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,6893701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980437, endtime: 40980438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,7040732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980439, endtime: 40980439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,7214540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980441, endtime: 40980441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,7522579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980444, endtime: 40980444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,7697554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980445, endtime: 40980446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,8088416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980449, endtime: 40980449, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,8393513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980452, endtime: 40980453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,8621467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980455, endtime: 40980455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,8989355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980458, endtime: 40980459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,9069544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980459, endtime: 40980459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,9265907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980461, endtime: 40980461, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,9390303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980462, endtime: 40980463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,9563172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980464, endtime: 40980464, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,9707097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980466, endtime: 40980466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:11,9853964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980467, endtime: 40980467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,0028961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980469, endtime: 40980469, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,0355253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980472, endtime: 40980472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,0481596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980473, endtime: 40980473, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,0653922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980475, endtime: 40980475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,0806419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980476, endtime: 40980477, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,0967998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980478, endtime: 40980478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,1109754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980480, endtime: 40980480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,1264714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980481, endtime: 40980481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,1420686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980483, endtime: 40980483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,1590845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980484, endtime: 40980485, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,1733213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980486, endtime: 40980486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,2633645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55099 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,3551862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,3555364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980504, endtime: 40980504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,3764865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980506, endtime: 40980506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,4185605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980510, endtime: 40980510, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,4391765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980512, endtime: 40980513, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,4568070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980514, endtime: 40980514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,4700098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980516, endtime: 40980516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,4860062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980517, endtime: 40980517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,5027152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980519, endtime: 40980519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,5394163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980522, endtime: 40980523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,5472337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980523, endtime: 40980523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,5645164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980525, endtime: 40980525, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,5705310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980526, endtime: 40980526, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,6020547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980528, endtime: 40980529, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,6105224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980530, endtime: 40980530, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,6276134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980531, endtime: 40980531, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,6421520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980533, endtime: 40980533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,6589460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980534, endtime: 40980535, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,6730398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980536, endtime: 40980536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,6901597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980537, endtime: 40980538, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,7048317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980539, endtime: 40980539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,7206212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980541, endtime: 40980541, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,7524325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980544, endtime: 40980544, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,7793163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980545, endtime: 40980547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,7975707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980548, endtime: 40980548, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:12,8172650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980550, endtime: 40980550, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,1511153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980552, endtime: 40980584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,1511341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980555, endtime: 40980584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,1511416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980556, endtime: 40980584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,1511491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980560, endtime: 40980584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,1511552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980561, endtime: 40980584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,1511618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980563, endtime: 40980584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,1511676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980566, endtime: 40980584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,1511746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980567, endtime: 40980584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,1511798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980569, endtime: 40980584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,1512103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980570, endtime: 40980584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,1512161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980572, endtime: 40980584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,1512228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980573, endtime: 40980584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,1512283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980575, endtime: 40980584, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:13,4030008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980487, endtime: 40980609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,0526446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,0526573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,0529660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40980674, endtime: 40980674, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,1838378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979798, endtime: 40980687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,1838550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979800, endtime: 40980687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,1838627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979801, endtime: 40980687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,1838708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979803, endtime: 40980687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,1838769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979805, endtime: 40980687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,1838841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979806, endtime: 40980687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,1838899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979808, endtime: 40980687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,1838971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979809, endtime: 40980687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,1839029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979813, endtime: 40980687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,1839331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979816, endtime: 40980687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,1839392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979819, endtime: 40980687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,1839464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979820, endtime: 40980687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,1839525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40979823, endtime: 40980687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,2776318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980687, endtime: 40980696, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,2776498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980689, endtime: 40980696, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,2776581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980691, endtime: 40980696, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,2776659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980692, endtime: 40980696, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,2776723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980694, endtime: 40980696, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,2833336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980697, endtime: 40980697, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3009375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980698, endtime: 40980699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3290193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980701, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3347289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980244, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3347480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980245, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3347566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980247, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3347649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980248, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3347713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980250, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3347785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980251, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3347846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980253, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3347918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980255, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3347976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980256, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3348262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980259, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3348325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980262, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3348397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980266, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3348458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980267, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3349525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980702, endtime: 40980702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3409028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980703, endtime: 40980703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3608946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980705, endtime: 40980705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,3915340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980708, endtime: 40980708, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,4081543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980709, endtime: 40980709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,5834909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980320, endtime: 40980727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,5835078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980322, endtime: 40980727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,5835153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980323, endtime: 40980727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,5835225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980327, endtime: 40980727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,5835280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980328, endtime: 40980727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,5835347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980330, endtime: 40980727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,5835402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980331, endtime: 40980727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,5835468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980333, endtime: 40980727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,5835521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980336, endtime: 40980727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,5835801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980338, endtime: 40980727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,5835859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980341, endtime: 40980727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,5835923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980344, endtime: 40980727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:14,5835976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980347, endtime: 40980727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:15,0760544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980291, endtime: 40980776, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,4365052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980702, endtime: 40980912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,4365210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980703, endtime: 40980912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,4365282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980705, endtime: 40980912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,4367318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980708, endtime: 40980912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,4369030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980709, endtime: 40980912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,4371532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980711, endtime: 40980912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,4371618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980712, endtime: 40980912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,4371687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980714, endtime: 40980912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,4371743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980716, endtime: 40980912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,4371806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980719, endtime: 40980912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,4371859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980720, endtime: 40980912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,4371923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980722, endtime: 40980912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,4371975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980726, endtime: 40980912, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,8567241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980292, endtime: 40980954, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,8567407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980294, endtime: 40980954, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,8567490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980295, endtime: 40980954, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,8567551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980297, endtime: 40980954, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,8567621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980298, endtime: 40980954, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,8567676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980300, endtime: 40980954, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,8567743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980300, endtime: 40980954, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,8567795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980303, endtime: 40980954, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,8567864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980305, endtime: 40980954, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,8568150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980306, endtime: 40980954, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,8568222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980308, endtime: 40980954, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,8568275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980309, endtime: 40980954, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:16,8568341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980776, endtime: 40980954, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:17,2632875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980489, endtime: 40980995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:17,2633083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980491, endtime: 40980995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:17,2633177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980492, endtime: 40980995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:17,2633249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980494, endtime: 40980995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:17,2633324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980495, endtime: 40980995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:17,2633388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980497, endtime: 40980995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:17,2633457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980498, endtime: 40980995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:17,2633668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980500, endtime: 40980995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:17,2633770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980503, endtime: 40980995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:17,2634152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980506, endtime: 40980995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:17,2634230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980510, endtime: 40980995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:17,2634291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980512, endtime: 40980995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:17,2634366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980609, endtime: 40980995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,0923603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980711, endtime: 40981078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,0923949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980712, endtime: 40981078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,0924052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980714, endtime: 40981078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,0924138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980716, endtime: 40981078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,0924201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980719, endtime: 40981078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,0924282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980720, endtime: 40981078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,0924343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980722, endtime: 40981078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,0924420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980726, endtime: 40981078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,0924484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980726, endtime: 40981078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,0925348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980728, endtime: 40981078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,0925420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980731, endtime: 40981078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,0925492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980733, endtime: 40981078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,0927313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980736, endtime: 40981078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,3134784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980727, endtime: 40981100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,3134989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980728, endtime: 40981100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,3135075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980731, endtime: 40981100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,3135158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980733, endtime: 40981100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,3135222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980736, endtime: 40981100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,3135297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980738, endtime: 40981100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,3135355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980740, endtime: 40981100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,3135427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980742, endtime: 40981100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,3135488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980744, endtime: 40981100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,3137001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980747, endtime: 40981100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,3137103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980748, endtime: 40981100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,3137184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980750, endtime: 40981100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:18,3137245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980752, endtime: 40981100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:19,5945897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980912, endtime: 40981228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:19,5946119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980914, endtime: 40981228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:19,5946230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980916, endtime: 40981228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:19,5946346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980917, endtime: 40981228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:19,5946418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980919, endtime: 40981228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:19,5946490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980920, endtime: 40981228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:19,5946551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980922, endtime: 40981228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:19,5946621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980923, endtime: 40981228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:19,5946682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980925, endtime: 40981228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:19,5947006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980928, endtime: 40981228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:19,5947064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980930, endtime: 40981228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:19,5947130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980931, endtime: 40981228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:19,5947186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980933, endtime: 40981228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:20,6672261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980995, endtime: 40981335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:20,6672408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980998, endtime: 40981335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:20,6672474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981000, endtime: 40981335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:20,6672543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981001, endtime: 40981335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:20,6672596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981003, endtime: 40981335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:20,6672660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981005, endtime: 40981335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:20,6672715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981006, endtime: 40981335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:20,6672776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981010, endtime: 40981335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:20,6672829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981011, endtime: 40981335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:20,6673120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981013, endtime: 40981335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:20,6673175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981017, endtime: 40981335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:20,6673236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981019, endtime: 40981335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:20,6673289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981021, endtime: 40981335, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,1242079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980584, endtime: 40981381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,1242248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980584, endtime: 40981381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,1242342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980587, endtime: 40981381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,1242411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980589, endtime: 40981381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,1242483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980592, endtime: 40981381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,1242544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980594, endtime: 40981381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,1242613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980595, endtime: 40981381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,1242672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980597, endtime: 40981381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,1242741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980599, endtime: 40981381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,1243256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980600, endtime: 40981381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,1243395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980601, endtime: 40981381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,1243489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980603, endtime: 40981381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,1243600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980605, endtime: 40981381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,2032991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981100, endtime: 40981389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,2033185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981101, endtime: 40981389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,2033265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981105, endtime: 40981389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,2033340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981106, endtime: 40981389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,2033398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981109, endtime: 40981389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,2033589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981111, endtime: 40981389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,2033700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981113, endtime: 40981389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,2033783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981116, endtime: 40981389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,2033844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981117, endtime: 40981389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,2034182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981121, endtime: 40981389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,2034243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981122, endtime: 40981389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,2034309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981126, endtime: 40981389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,2034368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981129, endtime: 40981389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4714090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981389, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4714372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981078, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4714461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981080, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4714635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981081, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4714716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981082, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4714777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981084, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4714971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981086, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4715179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981088, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4715417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981089, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4716386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981091, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4716470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981092, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4716525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981094, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4716680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981095, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:21,4717697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981099, endtime: 40981416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,3370836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981335, endtime: 40981602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,3371024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981336, endtime: 40981602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,3371099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981337, endtime: 40981602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,3371174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981339, endtime: 40981602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,3371235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981341, endtime: 40981602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,3371302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981342, endtime: 40981602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,3371357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981344, endtime: 40981602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,3371423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981346, endtime: 40981602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,3371482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981348, endtime: 40981602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,3372449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981350, endtime: 40981602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,3372559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981352, endtime: 40981602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,3372665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981353, endtime: 40981602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,3376161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981355, endtime: 40981602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7030259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981416, endtime: 40981639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7030420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981419, endtime: 40981639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7030594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981422, endtime: 40981639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7030735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981423, endtime: 40981639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7030821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981425, endtime: 40981639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7030896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981427, endtime: 40981639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7030954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981434, endtime: 40981639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7031026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981436, endtime: 40981639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7031082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981438, endtime: 40981639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7031755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981439, endtime: 40981639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7031819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981441, endtime: 40981639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7031885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981444, endtime: 40981639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7191417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981391, endtime: 40981641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7191564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981392, endtime: 40981641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7193268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981394, endtime: 40981641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7193423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981397, endtime: 40981641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7195603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981398, endtime: 40981641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7197434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981400, endtime: 40981641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7197526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981400, endtime: 40981641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7197587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981403, endtime: 40981641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7197653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981405, endtime: 40981641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7197709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981408, endtime: 40981641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7197772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981410, endtime: 40981641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7197825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981411, endtime: 40981641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7746551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981445, endtime: 40981646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7905318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981416, endtime: 40981648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7905592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981641, endtime: 40981648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7905725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981642, endtime: 40981648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7905825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981644, endtime: 40981648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7905930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981647, endtime: 40981648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,7985149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981648, endtime: 40981648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,8303423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981651, endtime: 40981652, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,8469607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981653, endtime: 40981653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,8779790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981656, endtime: 40981656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,8913439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981658, endtime: 40981658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,9072417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981659, endtime: 40981659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,9250542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981661, endtime: 40981661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:23,9567103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981664, endtime: 40981664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,1880768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,1880876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,1961613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40981687, endtime: 40981688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2504723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981381, endtime: 40981694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2504928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981383, endtime: 40981694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2505011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981384, endtime: 40981694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2505094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981386, endtime: 40981694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2505158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981387, endtime: 40981694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2505230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981391, endtime: 40981694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2505288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981392, endtime: 40981694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2505360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981394, endtime: 40981694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2505421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981397, endtime: 40981694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2505726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981398, endtime: 40981694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2505787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981400, endtime: 40981694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2506014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981400, endtime: 40981694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2506094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981403, endtime: 40981694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2945885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980954, endtime: 40981698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2946059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980955, endtime: 40981698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2946129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980958, endtime: 40981698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2946203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980960, endtime: 40981698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2946259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980962, endtime: 40981698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2946325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980962, endtime: 40981698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2946381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980967, endtime: 40981698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2946444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980968, endtime: 40981698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2946500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980970, endtime: 40981698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2946791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980972, endtime: 40981698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2946849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980974, endtime: 40981698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2946915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980976, endtime: 40981698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,2946971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40980978, endtime: 40981698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,7230374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981228, endtime: 40981741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,7230579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981230, endtime: 40981741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,7230665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981233, endtime: 40981741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,7230750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981234, endtime: 40981741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,7230814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981236, endtime: 40981741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,7230886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981238, endtime: 40981741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,7230944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981241, endtime: 40981741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,7231016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981244, endtime: 40981741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,7231075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981247, endtime: 40981741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,7231371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981249, endtime: 40981741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,7231438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981250, endtime: 40981741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,7231510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981252, endtime: 40981741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:24,7231568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981255, endtime: 40981741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:25,9129388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981639, endtime: 40981860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:25,9129540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981641, endtime: 40981860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:25,9129626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981642, endtime: 40981860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:25,9129690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981644, endtime: 40981860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:25,9129759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981647, endtime: 40981860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:25,9129815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981648, endtime: 40981860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:25,9129884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981651, endtime: 40981860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:25,9129936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981653, endtime: 40981860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:25,9130003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981656, endtime: 40981860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:25,9130632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981658, endtime: 40981860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:25,9130715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981659, endtime: 40981860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:25,9130773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981661, endtime: 40981860, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,0774815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981666, endtime: 40981876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,0775037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981669, endtime: 40981876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,0775123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981673, endtime: 40981876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,0775203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981673, endtime: 40981876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,0775267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981677, endtime: 40981876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,0775453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981678, endtime: 40981876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,0775586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981680, endtime: 40981876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,0775705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981681, endtime: 40981876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,0775807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981683, endtime: 40981876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,0776170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981687, endtime: 40981876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,0776234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981689, endtime: 40981876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,0776309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981692, endtime: 40981876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,0776370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981694, endtime: 40981876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,1635277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981602, endtime: 40981885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,1635462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981603, endtime: 40981885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,1635537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981605, endtime: 40981885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,1635609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981606, endtime: 40981885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,1635667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981608, endtime: 40981885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,1635734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981611, endtime: 40981885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,1635786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981612, endtime: 40981885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,1635853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981614, endtime: 40981885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,1635908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981617, endtime: 40981885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,1636709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981619, endtime: 40981885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,1636781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981623, endtime: 40981885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,1636850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981628, endtime: 40981885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,1638441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981630, endtime: 40981885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,2482101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981741, endtime: 40981893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,2482270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981742, endtime: 40981893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,2482345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981744, endtime: 40981893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,2482420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981745, endtime: 40981893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,2482478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981747, endtime: 40981893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,2482545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981748, endtime: 40981893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,2482600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981750, endtime: 40981893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,2482669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981751, endtime: 40981893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,2482722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981753, endtime: 40981893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,2483027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981754, endtime: 40981893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,2483085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981754, endtime: 40981893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,2483149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981755, endtime: 40981893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:26,2483204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981755, endtime: 40981893, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:27,8172705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981694, endtime: 40982050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:27,8172888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981695, endtime: 40982050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:27,8172968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981698, endtime: 40982050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:27,8173049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981700, endtime: 40982050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:27,8173112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981701, endtime: 40982050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:27,8173184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981703, endtime: 40982050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:27,8173245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981705, endtime: 40982050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:27,8173315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981706, endtime: 40982050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:27,8173378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981708, endtime: 40982050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:27,8173694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981709, endtime: 40982050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:27,8173758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981711, endtime: 40982050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:27,8173830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981714, endtime: 40982050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:27,8173891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981716, endtime: 40982050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1256724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981664, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1256890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981860, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1256976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981860, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1257037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981861, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1257103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981862, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1257156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981862, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1257220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981864, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1257272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981866, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1257336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981867, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1257389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981869, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1257840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981872, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1257907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981873, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1257976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981875, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1262431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982181, endtime: 40982181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1990643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981885, endtime: 40982189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1990814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981886, endtime: 40982189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1990892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981887, endtime: 40982189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1990972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981889, endtime: 40982189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1991030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981891, endtime: 40982189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1991100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981892, endtime: 40982189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1991155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981894, endtime: 40982189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1991224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981895, endtime: 40982189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1991280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981897, endtime: 40982189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1992100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981900, endtime: 40982189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1993449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981900, endtime: 40982189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1993552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981903, endtime: 40982189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,1993615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981905, endtime: 40982189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,2643184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981698, endtime: 40982195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,2643367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981700, endtime: 40982195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,2643445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981701, endtime: 40982195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,2643525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981703, endtime: 40982195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,2643694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981705, endtime: 40982195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,2643772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981706, endtime: 40982195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,2643835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981708, endtime: 40982195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,2643910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981709, endtime: 40982195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,2643971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981711, endtime: 40982195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,2644284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981714, endtime: 40982195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,2644348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981716, endtime: 40982195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,2644420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981717, endtime: 40982195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,2644478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981719, endtime: 40982195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,3178833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981893, endtime: 40982200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,3178994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981895, endtime: 40982200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,3179066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981897, endtime: 40982200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,3179144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981900, endtime: 40982200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,3179202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981903, endtime: 40982200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,3179274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981905, endtime: 40982200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,3179329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981906, endtime: 40982200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,3179399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981908, endtime: 40982200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,3179457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981909, endtime: 40982200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,3179726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981911, endtime: 40982200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,3179784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981913, endtime: 40982200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,3179850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981914, endtime: 40982200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:29,3179908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981916, endtime: 40982200, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:31,7073214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982200, endtime: 40982439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:31,7073385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982203, endtime: 40982439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:31,7073457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982208, endtime: 40982439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:31,7073529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982218, endtime: 40982439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:31,7073588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982222, endtime: 40982439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:31,7073651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982227, endtime: 40982439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:31,7075799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982235, endtime: 40982439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:31,7076624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982240, endtime: 40982439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:31,7079655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982242, endtime: 40982439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:31,7079774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982246, endtime: 40982439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:31,7079844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982252, endtime: 40982439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:31,7079918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982257, endtime: 40982439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:31,7079982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982261, endtime: 40982439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,6568656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981876, endtime: 40982534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,6568822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981878, endtime: 40982534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,6568897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981880, endtime: 40982534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,6568972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981881, endtime: 40982534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,6569027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981883, endtime: 40982534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,6569096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981884, endtime: 40982534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,6569149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981886, endtime: 40982534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,6569221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981887, endtime: 40982534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,6569274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981889, endtime: 40982534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,6569578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981891, endtime: 40982534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,6569637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981892, endtime: 40982534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,6569700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981894, endtime: 40982534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,6569756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40981895, endtime: 40982534, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,8538477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982195, endtime: 40982554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,8538704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982197, endtime: 40982554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,8538934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982198, endtime: 40982554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,8539056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982200, endtime: 40982554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,8539131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982203, endtime: 40982554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,8539217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982208, endtime: 40982554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,8539286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982217, endtime: 40982554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,8539372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982222, endtime: 40982554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,8539444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982227, endtime: 40982554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,8539799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982235, endtime: 40982554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,8539868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982240, endtime: 40982554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,8539943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982242, endtime: 40982554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:32,8540007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982246, endtime: 40982554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,1861667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982183, endtime: 40982587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,1861856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982187, endtime: 40982587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,1861933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982188, endtime: 40982587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,1862011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982192, endtime: 40982587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,1862072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982197, endtime: 40982587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,1862141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982202, endtime: 40982587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,1862197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982203, endtime: 40982587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,1862266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982208, endtime: 40982587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,1862324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982217, endtime: 40982587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,1863155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982222, endtime: 40982587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,1863233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982227, endtime: 40982587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,1863302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982235, endtime: 40982587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,1868034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982240, endtime: 40982587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,2292343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982050, endtime: 40982592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,2292517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982053, endtime: 40982592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,2292617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982055, endtime: 40982592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,2292697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982056, endtime: 40982592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,2292775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982060, endtime: 40982592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,2292841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982061, endtime: 40982592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,2292922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982063, endtime: 40982592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,2292986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982066, endtime: 40982592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,2293063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982067, endtime: 40982592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,2293396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982069, endtime: 40982592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,2293473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982070, endtime: 40982592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,2293534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982072, endtime: 40982592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,2293609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982073, endtime: 40982592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,9050840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982439, endtime: 40982659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,9051014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982440, endtime: 40982659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,9051097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982442, endtime: 40982659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,9051197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982444, endtime: 40982659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,9051261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982446, endtime: 40982659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,9051333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982447, endtime: 40982659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,9051538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982448, endtime: 40982659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,9051671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982450, endtime: 40982659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,9051737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982452, endtime: 40982659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,9052067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982453, endtime: 40982659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,9052131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982455, endtime: 40982659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,9052203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982456, endtime: 40982659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:33,9052267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982459, endtime: 40982659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,2073989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982587, endtime: 40982689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,2074167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982589, endtime: 40982689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,2074241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982590, endtime: 40982689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,2074319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982592, endtime: 40982689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,2074380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982594, endtime: 40982689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,2074449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982597, endtime: 40982689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,2074507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982599, endtime: 40982689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,2074579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982600, endtime: 40982689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,2074632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982601, endtime: 40982689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,2075449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982603, endtime: 40982689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,2075521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982605, endtime: 40982689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,2075588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982608, endtime: 40982689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,2077128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982609, endtime: 40982689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,4541946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,4542066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:34,4545811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40982714, endtime: 40982714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,0899745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982592, endtime: 40982778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,0899951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982594, endtime: 40982778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,0900031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982597, endtime: 40982778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,0900114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982599, endtime: 40982778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,0900180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982600, endtime: 40982778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,0900253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982601, endtime: 40982778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,0900313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982603, endtime: 40982778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,0900385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982605, endtime: 40982778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,0900444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982608, endtime: 40982778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,0900762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982609, endtime: 40982778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,0900826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982610, endtime: 40982778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,0900898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982612, endtime: 40982778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,0900959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982614, endtime: 40982778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,2811704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982534, endtime: 40982797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,2812039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982536, endtime: 40982797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,2812122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982539, endtime: 40982797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,2812200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982541, endtime: 40982797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,2812263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982542, endtime: 40982797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,2812338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982546, endtime: 40982797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,2812396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982547, endtime: 40982797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,2812466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982548, endtime: 40982797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,2812524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982551, endtime: 40982797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,2812837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982553, endtime: 40982797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,2812898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982555, endtime: 40982797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,2812964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982556, endtime: 40982797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,2813020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982558, endtime: 40982797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,3655076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55178 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,3658985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55177 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,4098615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55128 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,5321070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982554, endtime: 40982822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,5321247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982555, endtime: 40982822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,5321322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982556, endtime: 40982822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,5321397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982558, endtime: 40982822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,5321455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982559, endtime: 40982822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,5321521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982562, endtime: 40982822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,5321577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982564, endtime: 40982822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,5321646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982566, endtime: 40982822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,5321701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982571, endtime: 40982822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,5322017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982573, endtime: 40982822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,5322075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982575, endtime: 40982822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,5322142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982576, endtime: 40982822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:35,5322197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982578, endtime: 40982822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:36,9946429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982659, endtime: 40982968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:36,9946617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982661, endtime: 40982968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:36,9946695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982664, endtime: 40982968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:36,9946770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982666, endtime: 40982968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:36,9946828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982667, endtime: 40982968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:36,9946897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982669, endtime: 40982968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:36,9946953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982670, endtime: 40982968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:36,9947911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982672, endtime: 40982968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:36,9947997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982674, endtime: 40982968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:36,9948069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982675, endtime: 40982968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:36,9948127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982678, endtime: 40982968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:36,9948197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982680, endtime: 40982968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:36,9948257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982681, endtime: 40982968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,1567736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55190 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,1567822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55189 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,1881338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55191 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,6711775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982689, endtime: 40983036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,6711941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982691, endtime: 40983036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,6712013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982693, endtime: 40983036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,6712088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982694, endtime: 40983036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,6712146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982695, endtime: 40983036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,6712215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982697, endtime: 40983036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,6712273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982699, endtime: 40983036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,6712337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982701, endtime: 40983036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,6712392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982701, endtime: 40983036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,6713168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982702, endtime: 40983036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,6713243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982702, endtime: 40983036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,6713309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982705, endtime: 40983036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:37,6715088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982706, endtime: 40983036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,5861454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982822, endtime: 40983127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,5861628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982823, endtime: 40983127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,5861703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982825, endtime: 40983127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,5861783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982826, endtime: 40983127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,5861844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982828, endtime: 40983127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,5861916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982830, endtime: 40983127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,5861974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982831, endtime: 40983127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,5862044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982834, endtime: 40983127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,5862102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982836, endtime: 40983127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,5862429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982837, endtime: 40983127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,5862490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982841, endtime: 40983127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,5862556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982843, endtime: 40983127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,5862612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982846, endtime: 40983127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,7036797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983127, endtime: 40983139, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,9384182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55191 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,9384254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55189 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:38,9384274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55190 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,1776592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983036, endtime: 40983286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,1776797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983037, endtime: 40983286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,1776880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983040, endtime: 40983286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,1776963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983041, endtime: 40983286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,1777030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983042, endtime: 40983286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,1777102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983044, endtime: 40983286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,1777163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983047, endtime: 40983286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,1777235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983049, endtime: 40983286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,1777296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983052, endtime: 40983286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,1777603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983053, endtime: 40983286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,1777667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983055, endtime: 40983286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,1777736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983056, endtime: 40983286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,1777797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983058, endtime: 40983286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,8470136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982968, endtime: 40983353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,8470305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982970, endtime: 40983353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,8470377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982975, endtime: 40983353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,8470449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982977, endtime: 40983353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,8470507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982978, endtime: 40983353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,8470573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982980, endtime: 40983353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,8470626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982981, endtime: 40983353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,8470690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982983, endtime: 40983353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,8472158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982984, endtime: 40983353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,8472288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982986, endtime: 40983353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,8472358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982987, endtime: 40983353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,8472433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982989, endtime: 40983353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:40,8472493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40982991, endtime: 40983353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:41,0182320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983130, endtime: 40983370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:41,0182492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983134, endtime: 40983370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:41,0182580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983136, endtime: 40983370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:41,0182641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983139, endtime: 40983370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:41,0182711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983140, endtime: 40983370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:41,0182766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983142, endtime: 40983370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:41,0182833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983144, endtime: 40983370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:41,0182888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983145, endtime: 40983370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:41,0182954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983149, endtime: 40983370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:41,0183697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983150, endtime: 40983370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:41,0183780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983152, endtime: 40983370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:41,0183835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983153, endtime: 40983370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:41,0188548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983155, endtime: 40983370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,1100104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55196 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,1100187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55195 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,1100207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55197 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,7372911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983286, endtime: 40983542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,7373091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983287, endtime: 40983542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,7373166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983291, endtime: 40983542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,7373240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983292, endtime: 40983542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,7373299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983295, endtime: 40983542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,7373362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983297, endtime: 40983542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,7373418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983299, endtime: 40983542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,7373484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983301, endtime: 40983542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,7373537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983302, endtime: 40983542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,7373822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983303, endtime: 40983542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,7382192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983306, endtime: 40983542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,7382306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983308, endtime: 40983542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,7382394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983309, endtime: 40983542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,8954203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983370, endtime: 40983558, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,8954394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983372, endtime: 40983558, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,8954471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983373, endtime: 40983558, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,8954546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983375, endtime: 40983558, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,8954601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983377, endtime: 40983558, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,8954671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983378, endtime: 40983558, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,8954726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983380, endtime: 40983558, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,8954795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983381, endtime: 40983558, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,8954851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983383, endtime: 40983558, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,8955485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983386, endtime: 40983558, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,8955557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983387, endtime: 40983558, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:42,8957167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983391, endtime: 40983558, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,2445469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983353, endtime: 40983593, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,2445613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983355, endtime: 40983593, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,2445679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983356, endtime: 40983593, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,2445749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983358, endtime: 40983593, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,2445801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983359, endtime: 40983593, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,2445865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983361, endtime: 40983593, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,2445918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983364, endtime: 40983593, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,2445979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983367, endtime: 40983593, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,2446031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983369, endtime: 40983593, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,2446306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983372, endtime: 40983593, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,2446361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983373, endtime: 40983593, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,2446425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983375, endtime: 40983593, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,2446477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983377, endtime: 40983593, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,8593622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55197 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,8593711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55195 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:43,8593736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55196 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,4762328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,4762450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,4765844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40983716, endtime: 40983716, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,9217597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983593, endtime: 40983761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,9217774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983595, endtime: 40983761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,9217849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983598, endtime: 40983761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,9217927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983600, endtime: 40983761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,9217985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983601, endtime: 40983761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,9218051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983601, endtime: 40983761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,9218107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983603, endtime: 40983761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,9218173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983605, endtime: 40983761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,9218226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983608, endtime: 40983761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,9218531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983610, endtime: 40983761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,9218589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983611, endtime: 40983761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,9218658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983614, endtime: 40983761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:44,9227341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983616, endtime: 40983761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:45,7151967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983392, endtime: 40983840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:45,7152285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983558, endtime: 40983840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:45,7152385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983559, endtime: 40983840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:45,7152463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983561, endtime: 40983840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:45,7152521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983562, endtime: 40983840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:45,7152593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983564, endtime: 40983840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:45,7152648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983566, endtime: 40983840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:45,7152718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983567, endtime: 40983840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:45,7152773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983569, endtime: 40983840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:45,7153089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983572, endtime: 40983840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:45,7153147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983573, endtime: 40983840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:45,7153211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983575, endtime: 40983840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:45,7154361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983577, endtime: 40983840, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9825804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983542, endtime: 40983967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9825984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983545, endtime: 40983967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9826056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983547, endtime: 40983967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9826131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983550, endtime: 40983967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9826189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983551, endtime: 40983967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9826256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983553, endtime: 40983967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9826308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983555, endtime: 40983967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9826500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983558, endtime: 40983967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9826594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983559, endtime: 40983967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9827569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983561, endtime: 40983967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9827638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983562, endtime: 40983967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9827705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983564, endtime: 40983967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9829306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983566, endtime: 40983967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:46,9846079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,0002452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,0002552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,2571945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983840, endtime: 40983994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,2572200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983842, endtime: 40983994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,2572291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983844, endtime: 40983994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,2572574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983845, endtime: 40983994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,2572657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983847, endtime: 40983994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,2572735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983848, endtime: 40983994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,2572796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983850, endtime: 40983994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,2572868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983851, endtime: 40983994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,2585091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983853, endtime: 40983994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,2585692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983855, endtime: 40983994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,2585784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983856, endtime: 40983994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,2585870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983858, endtime: 40983994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:47,2585939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983859, endtime: 40983994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,2236339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983761, endtime: 40984091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,2236486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983762, endtime: 40984091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,2236558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983764, endtime: 40984091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,2236630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983767, endtime: 40984091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,2236688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983769, endtime: 40984091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,2236751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983770, endtime: 40984091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,2236804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983773, endtime: 40984091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,2238322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983775, endtime: 40984091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,2238439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983777, endtime: 40984091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,2238522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983778, endtime: 40984091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,2238586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983780, endtime: 40984091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,2238660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983781, endtime: 40984091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,2238721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983785, endtime: 40984091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,3197682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,3200859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984101, endtime: 40984101, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,3440748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984103, endtime: 40984103, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,3606445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984105, endtime: 40984105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,3760028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984106, endtime: 40984106, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4092897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984109, endtime: 40984110, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4249494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984111, endtime: 40984111, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4295477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4295851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4300101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984112, endtime: 40984112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4303177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984112, endtime: 40984112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4386438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984112, endtime: 40984112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4388579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984112, endtime: 40984112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4394112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984112, endtime: 40984113, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4543803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984114, endtime: 40984114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4545953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984114, endtime: 40984114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4562329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984114, endtime: 40984114, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4696824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984116, endtime: 40984116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4697092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984116, endtime: 40984116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4703545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984116, endtime: 40984116, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4856926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984117, endtime: 40984117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4858815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984117, endtime: 40984117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,4876314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984117, endtime: 40984117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5008938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984119, endtime: 40984119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5014931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984119, endtime: 40984119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5029438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984119, endtime: 40984119, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5166960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984120, endtime: 40984120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5167215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984120, endtime: 40984120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5173210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984120, endtime: 40984120, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5325746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984122, endtime: 40984122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5325985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984122, endtime: 40984122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5349288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984122, endtime: 40984122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5745666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984126, endtime: 40984126, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5748057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984126, endtime: 40984126, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5794556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984126, endtime: 40984127, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5956542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984128, endtime: 40984128, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,5956794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984128, endtime: 40984128, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6045707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984128, endtime: 40984129, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6104066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984130, endtime: 40984130, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6105579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984130, endtime: 40984130, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6106698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984130, endtime: 40984130, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6272704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984131, endtime: 40984131, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6275154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984131, endtime: 40984131, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6295107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984131, endtime: 40984132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6414466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984133, endtime: 40984133, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6414726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984133, endtime: 40984133, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6421309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984133, endtime: 40984133, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6573537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984134, endtime: 40984134, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6575175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984134, endtime: 40984134, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6580162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984134, endtime: 40984134, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6740059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984136, endtime: 40984136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6740284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984136, endtime: 40984136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6748778</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984136, endtime: 40984136, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6884793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984137, endtime: 40984137, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6886772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984137, endtime: 40984137, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,6925108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984137, endtime: 40984138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7041762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984139, endtime: 40984139, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7043993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984139, endtime: 40984139, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7044153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984139, endtime: 40984139, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7195467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984141, endtime: 40984141, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7197537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984141, endtime: 40984141, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7214041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984141, endtime: 40984141, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7353201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984142, endtime: 40984142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7355235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984142, endtime: 40984142, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7423163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984142, endtime: 40984143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7508089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984144, endtime: 40984144, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7509685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984144, endtime: 40984144, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7513802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984144, endtime: 40984144, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7665468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984145, endtime: 40984145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7667651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984145, endtime: 40984145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7672339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984145, endtime: 40984145, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7826989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984147, endtime: 40984147, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7829726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984147, endtime: 40984147, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7858728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984147, endtime: 40984147, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7976577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984148, endtime: 40984148, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7978719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984148, endtime: 40984148, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,7997564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984148, endtime: 40984149, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,8136297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984150, endtime: 40984150, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,8138660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984150, endtime: 40984150, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,8142844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984150, endtime: 40984150, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,8291243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984151, endtime: 40984152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,8291473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984151, endtime: 40984152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,8447254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984153, endtime: 40984153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,8447459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984153, endtime: 40984153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,8600820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984155, endtime: 40984155, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,8769498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984156, endtime: 40984156, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,9090201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984159, endtime: 40984160, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,9241596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984161, endtime: 40984161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:48,9386809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984162, endtime: 40984162, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1439312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984152, endtime: 40984183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1439517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984153, endtime: 40984183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1439595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984155, endtime: 40984183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1439675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984156, endtime: 40984183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1439736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984159, endtime: 40984183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1439814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984161, endtime: 40984183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1439875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984162, endtime: 40984183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1439947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984166, endtime: 40984183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1440010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984168, endtime: 40984183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1440326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984169, endtime: 40984183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1585806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984155, endtime: 40984184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1586011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984156, endtime: 40984184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1586085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984159, endtime: 40984184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1586166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984161, endtime: 40984184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1586224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984162, endtime: 40984184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1586296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984166, endtime: 40984184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1586354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984168, endtime: 40984184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1586423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984169, endtime: 40984184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1586479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984171, endtime: 40984184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1586833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984172, endtime: 40984184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1586889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984173, endtime: 40984184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,1586955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984176, endtime: 40984184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,4963615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983994, endtime: 40984218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,4963828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983995, endtime: 40984218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,4963914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983998, endtime: 40984218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,4964000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984002, endtime: 40984218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,4964202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984006, endtime: 40984218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,4964343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984008, endtime: 40984218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,4964451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984012, endtime: 40984218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,4964546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984012, endtime: 40984218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,4964612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984014, endtime: 40984218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,4964947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984016, endtime: 40984218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,4965014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984017, endtime: 40984218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,4965086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984019, endtime: 40984218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:49,4965147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984021, endtime: 40984218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,5041307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984166, endtime: 40984319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,5041498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984168, endtime: 40984319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,5041578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984169, endtime: 40984319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,5041659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984171, endtime: 40984319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,5041720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984172, endtime: 40984319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,5041792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984173, endtime: 40984319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,5041853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984176, endtime: 40984319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,5041930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984178, endtime: 40984319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,6261930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983967, endtime: 40984331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,6262088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983969, endtime: 40984331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,6262157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983970, endtime: 40984331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,6262232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983972, endtime: 40984331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,6262293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983973, endtime: 40984331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,6262359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983975, endtime: 40984331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,6262415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983976, endtime: 40984331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,6262484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983978, endtime: 40984331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,6262537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983980, endtime: 40984331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,6263321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983981, endtime: 40984331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,6263393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983983, endtime: 40984331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,6263459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983986, endtime: 40984331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,6268975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40983987, endtime: 40984331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,9655706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984171, endtime: 40984365, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,9655864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984172, endtime: 40984365, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,9655949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984173, endtime: 40984365, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,9656016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984183, endtime: 40984365, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,9656088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984184, endtime: 40984365, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,9656146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984186, endtime: 40984365, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,9656213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984187, endtime: 40984365, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,9656271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984189, endtime: 40984365, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,9656340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984191, endtime: 40984365, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,9656988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984191, endtime: 40984365, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,9657072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984194, endtime: 40984365, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:50,9657130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984195, endtime: 40984365, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,2526904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984178, endtime: 40984394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,2527087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984184, endtime: 40984394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,2527167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984186, endtime: 40984394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,2527250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984187, endtime: 40984394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,2527311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984189, endtime: 40984394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,2527386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984191, endtime: 40984394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,2527447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984191, endtime: 40984394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,2527516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984194, endtime: 40984394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,2527574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984195, endtime: 40984394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,2527871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984197, endtime: 40984394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,2527937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984200, endtime: 40984394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,2528007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984201, endtime: 40984394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,2528068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984203, endtime: 40984394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6526632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984180, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6526790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984181, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6526878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984183, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6526945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984184, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6527020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984186, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6527081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984319, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6527153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984320, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6527211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984322, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6527280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984323, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6527976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984325, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6528064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984326, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6528122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984328, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6528264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984218, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6528341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984220, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6528405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984224, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6528480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984227, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6528541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984228, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6528613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984230, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6529186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984231, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6529272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984233, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6529330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984234, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6529402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984236, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6529461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984238, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6529530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984239, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,6529591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984241, endtime: 40984434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,7521770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984091, endtime: 40984444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,7521950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984092, endtime: 40984444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,7522025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984094, endtime: 40984444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,7522097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984097, endtime: 40984444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,7522155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984098, endtime: 40984444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,7522222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984100, endtime: 40984444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,7522277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984100, endtime: 40984444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,7522671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984103, endtime: 40984444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,7522743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984105, endtime: 40984444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,7523072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984106, endtime: 40984444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,7523283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984109, endtime: 40984444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,7523402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984111, endtime: 40984444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:51,7523496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984112, endtime: 40984444, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:52,7058557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984197, endtime: 40984539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:52,7058743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984365, endtime: 40984539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:52,7058832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984367, endtime: 40984539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:52,7058895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984369, endtime: 40984539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:52,7058967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984370, endtime: 40984539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:52,7059023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984372, endtime: 40984539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:52,7059089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984373, endtime: 40984539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:52,7059145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984375, endtime: 40984539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:52,7059211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984376, endtime: 40984539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:52,7059364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984378, endtime: 40984539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:52,7059721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984380, endtime: 40984539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:52,7059782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984381, endtime: 40984539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:52,7059848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984383, endtime: 40984539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,4603965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984331, endtime: 40984615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,4604159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984333, endtime: 40984615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,4604240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984334, endtime: 40984615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,4604353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984336, endtime: 40984615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,4604445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984337, endtime: 40984615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,4604561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984339, endtime: 40984615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,4604625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984341, endtime: 40984615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,4604694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984342, endtime: 40984615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,4604752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984344, endtime: 40984615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,4605431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984345, endtime: 40984615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,4605506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984348, endtime: 40984615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,4605578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984350, endtime: 40984615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,6746451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984352, endtime: 40984636, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,8393117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984330, endtime: 40984653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,8393377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984434, endtime: 40984653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,8393519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984436, endtime: 40984653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,8393621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984438, endtime: 40984653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,8393735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984439, endtime: 40984653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,8393835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984441, endtime: 40984653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,8393945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984442, endtime: 40984653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,8394042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984444, endtime: 40984653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,8394153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984445, endtime: 40984653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,8394247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984447, endtime: 40984653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,8394682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984450, endtime: 40984653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,8394779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984451, endtime: 40984653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:53,8394893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984453, endtime: 40984653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,0156775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984539, endtime: 40984670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,0157058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984540, endtime: 40984670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,0157180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984542, endtime: 40984670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,0157293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984545, endtime: 40984670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,0157388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984547, endtime: 40984670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,0157507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984548, endtime: 40984670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,0157609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984550, endtime: 40984670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,0157731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984554, endtime: 40984670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,0157837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984555, endtime: 40984670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,0158280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984558, endtime: 40984670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,0158360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984559, endtime: 40984670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,0158432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984561, endtime: 40984670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,0158493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984562, endtime: 40984670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,1744697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984434, endtime: 40984686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,1744874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984436, endtime: 40984686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,1744952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984438, endtime: 40984686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,1745138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984439, endtime: 40984686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,1745265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984441, endtime: 40984686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,1745387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984442, endtime: 40984686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,1745484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984444, endtime: 40984686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,1745600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984445, endtime: 40984686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,1745703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984447, endtime: 40984686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,1746213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984450, endtime: 40984686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,1746304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984451, endtime: 40984686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,1746412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984453, endtime: 40984686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,1746495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984455, endtime: 40984686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,2491430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984686, endtime: 40984694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,3740922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984444, endtime: 40984706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,3741108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984445, endtime: 40984706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,3741185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984447, endtime: 40984706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,3741263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984450, endtime: 40984706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,3741327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984451, endtime: 40984706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,3741399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984453, endtime: 40984706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,3741457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984455, endtime: 40984706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,3741523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984456, endtime: 40984706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,3741584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984459, endtime: 40984706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,3741864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984461, endtime: 40984706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,3741925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984463, endtime: 40984706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,3741994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984464, endtime: 40984706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,3742050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984466, endtime: 40984706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,6199479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,6199637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:54,6202933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40984731, endtime: 40984731, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:55,7415234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984653, endtime: 40984843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:55,7415430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984655, endtime: 40984843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:55,7415511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984656, endtime: 40984843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:55,7415594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984659, endtime: 40984843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:55,7415658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984662, endtime: 40984843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:55,7415730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984662, endtime: 40984843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:55,7415796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984664, endtime: 40984843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:55,7415865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984666, endtime: 40984843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:55,7415926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984669, endtime: 40984843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:55,7416242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984670, endtime: 40984843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:55,7416309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984672, endtime: 40984843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:55,7416381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984673, endtime: 40984843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:55,7416442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984675, endtime: 40984843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:56,2350469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984706, endtime: 40984892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:56,2350660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984708, endtime: 40984892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:56,2350741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984709, endtime: 40984892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:56,2350818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984713, endtime: 40984892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:56,2350879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984714, endtime: 40984892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:56,2350948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984717, endtime: 40984892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:56,2351004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984719, endtime: 40984892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:56,2351073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984722, endtime: 40984892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:56,2351129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984724, endtime: 40984892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:56,2351453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984725, endtime: 40984892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:56,2351514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984729, endtime: 40984892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:56,2351580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984730, endtime: 40984892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:56,2352641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984731, endtime: 40984892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:57,9426508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984687, endtime: 40985063, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:57,9426719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984691, endtime: 40985063, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:57,9426857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984692, endtime: 40985063, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:57,9426960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984695, endtime: 40985063, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:57,9427079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984697, endtime: 40985063, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:57,9427176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984698, endtime: 40985063, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:57,9427287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984700, endtime: 40985063, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:57,9427384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984700, endtime: 40985063, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:57,9427497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984703, endtime: 40985063, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:57,9428406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984706, endtime: 40985063, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:57,9428539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984708, endtime: 40985063, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:57,9428636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984709, endtime: 40985063, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,0136298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984615, endtime: 40985070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,0136487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984615, endtime: 40985070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,0136575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984617, endtime: 40985070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,0136639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984620, endtime: 40985070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,0136711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984623, endtime: 40985070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,0136769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984625, endtime: 40985070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,0136838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984627, endtime: 40985070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,0136897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984628, endtime: 40985070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,0136966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984630, endtime: 40985070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,0137725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984631, endtime: 40985070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,0137816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984633, endtime: 40985070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,0137872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984634, endtime: 40985070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,4818695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984713, endtime: 40985117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,4818875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985063, endtime: 40985117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,4818961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985064, endtime: 40985117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,4819025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985066, endtime: 40985117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,4819094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985070, endtime: 40985117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,4819149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985073, endtime: 40985117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,4819216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985075, endtime: 40985117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,4819271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985078, endtime: 40985117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,4819338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985080, endtime: 40985117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,4819390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985081, endtime: 40985117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,4819823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985083, endtime: 40985117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,4819897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985085, endtime: 40985117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:58,4819969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985088, endtime: 40985117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:59,3641071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984670, endtime: 40985205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:59,3641251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984672, endtime: 40985205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:59,3641331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984673, endtime: 40985205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:59,3641409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984675, endtime: 40985205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:59,3641473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984677, endtime: 40985205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:59,3641542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984680, endtime: 40985205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:59,3641603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984681, endtime: 40985205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:59,3641672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984682, endtime: 40985205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:59,3641730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984684, endtime: 40985205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:59,3642019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984686, endtime: 40985205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:59,3642082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984687, endtime: 40985205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:59,3642152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984691, endtime: 40985205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>12:59:59,3642210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984692, endtime: 40985205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:00,4619445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984394, endtime: 40985315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:00,4619625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984395, endtime: 40985315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:00,4619716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984398, endtime: 40985315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:00,4619783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984400, endtime: 40985315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:00,4619852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984400, endtime: 40985315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:00,4619910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984401, endtime: 40985315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:00,4619979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984403, endtime: 40985315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:00,4620035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984407, endtime: 40985315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:00,4620101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984409, endtime: 40985315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:00,4620378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984411, endtime: 40985315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:00,4620448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984412, endtime: 40985315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:00,4620506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984415, endtime: 40985315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:00,4620572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984417, endtime: 40985315, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,0307505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984636, endtime: 40985372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,0307668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985070, endtime: 40985372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,0307754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985073, endtime: 40985372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,0307815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985075, endtime: 40985372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,0307887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985078, endtime: 40985372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,0307943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985080, endtime: 40985372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,0308009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985081, endtime: 40985372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,0308062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985083, endtime: 40985372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,0308128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985085, endtime: 40985372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,0308184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985088, endtime: 40985372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,0308497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985091, endtime: 40985372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,0308555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985092, endtime: 40985372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,0308621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985093, endtime: 40985372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,1984786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985205, endtime: 40985388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,1984963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985206, endtime: 40985388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,1985038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985208, endtime: 40985388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,1985110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985209, endtime: 40985388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,1985165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985211, endtime: 40985388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,1985232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985212, endtime: 40985388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,1985284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985214, endtime: 40985388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,1985351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985216, endtime: 40985388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,1985403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985217, endtime: 40985388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,1985891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985219, endtime: 40985388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,1985991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985220, endtime: 40985388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,1986099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985222, endtime: 40985388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,1986182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985223, endtime: 40985388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,2825155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984892, endtime: 40985397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,2825363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984894, endtime: 40985397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,2825448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984895, endtime: 40985397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,2825534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984898, endtime: 40985397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,2825598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984902, endtime: 40985397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,2825676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984905, endtime: 40985397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,2825739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984906, endtime: 40985397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,2825814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984909, endtime: 40985397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,2825875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984911, endtime: 40985397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,2826197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984912, endtime: 40985397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,2826257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984914, endtime: 40985397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,2826327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984916, endtime: 40985397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,2826385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984917, endtime: 40985397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,4763475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984843, endtime: 40985416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,4763625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984844, endtime: 40985416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,4763697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984844, endtime: 40985416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,4763769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984845, endtime: 40985416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,4763824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984848, endtime: 40985416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,4763891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984850, endtime: 40985416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,4763943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984851, endtime: 40985416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,4764010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984853, endtime: 40985416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,4764062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984856, endtime: 40985416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,4764353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984858, endtime: 40985416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,4764411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984861, endtime: 40985416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,4764475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984863, endtime: 40985416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:01,4764528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40984866, endtime: 40985416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:02,0960063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985315, endtime: 40985478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:02,0960410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985315, endtime: 40985478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:02,0960501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985317, endtime: 40985478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:02,0960590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985319, endtime: 40985478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:02,0960653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985322, endtime: 40985478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:02,0960734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985323, endtime: 40985478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:02,0960795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985327, endtime: 40985478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:02,0960870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985329, endtime: 40985478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:02,0960931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985330, endtime: 40985478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:02,0961241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985333, endtime: 40985478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:02,0961302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985334, endtime: 40985478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:02,0961374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985336, endtime: 40985478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:02,0961432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985339, endtime: 40985478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,1252116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985117, endtime: 40985581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,1252313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985120, endtime: 40985581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,1252391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985122, endtime: 40985581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,1252468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985127, endtime: 40985581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,1252529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985128, endtime: 40985581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,1252601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985130, endtime: 40985581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,1252659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985133, endtime: 40985581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,1252729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985135, endtime: 40985581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,1252787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985136, endtime: 40985581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,1253119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985139, endtime: 40985581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,1253180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985142, endtime: 40985581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,1253250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985146, endtime: 40985581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,1253311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985148, endtime: 40985581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,8626193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985397, endtime: 40985655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,8626373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985398, endtime: 40985655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,8626567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985400, endtime: 40985655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,8626686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985400, endtime: 40985655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,8626756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985401, endtime: 40985655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,8626830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985404, endtime: 40985655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,8626900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985406, endtime: 40985655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,8626977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985408, endtime: 40985655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,8627044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985409, endtime: 40985655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,8627429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985412, endtime: 40985655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,8627490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985414, endtime: 40985655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,8627559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985416, endtime: 40985655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:03,8627614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985419, endtime: 40985655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8353509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8353623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8358335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40985752, endtime: 40985752, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8533066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985416, endtime: 40985754, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8533235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985419, endtime: 40985754, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8533307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985420, endtime: 40985754, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8533382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985422, endtime: 40985754, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8533438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985423, endtime: 40985754, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8533507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985425, endtime: 40985754, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8533562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985426, endtime: 40985754, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8533631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985428, endtime: 40985754, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8533687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985430, endtime: 40985754, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8533950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985431, endtime: 40985754, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8534005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985433, endtime: 40985754, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8534072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985434, endtime: 40985754, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:04,8534127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985436, endtime: 40985754, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:05,4656085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985372, endtime: 40985815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:05,4656296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985373, endtime: 40985815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:05,4656371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985376, endtime: 40985815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:05,4656448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985378, endtime: 40985815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:05,4656509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985380, endtime: 40985815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:05,4656581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985383, endtime: 40985815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:05,4656639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985384, endtime: 40985815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:05,4656711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985386, endtime: 40985815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:05,4656770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985388, endtime: 40985815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:05,4657083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985389, endtime: 40985815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:05,4657146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985391, endtime: 40985815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:05,4657216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985392, endtime: 40985815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:05,4657274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985394, endtime: 40985815, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,4747359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55101 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,5763545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,5768618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985926, endtime: 40985926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,5953605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985928, endtime: 40985928, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,6271114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985931, endtime: 40985931, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,6413258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985933, endtime: 40985933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,6584038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985934, endtime: 40985934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,6731193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985936, endtime: 40985936, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,6905428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985938, endtime: 40985938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,7195999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985941, endtime: 40985941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,7367705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985942, endtime: 40985942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,7540338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985944, endtime: 40985944, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,7688417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985945, endtime: 40985945, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,8004219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985949, endtime: 40985949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,8142259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985950, endtime: 40985950, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,8459541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985953, endtime: 40985953, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,8601075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985955, endtime: 40985955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,8784411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985956, endtime: 40985956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,9085776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985959, endtime: 40985959, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,9227277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985961, endtime: 40985961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,9551533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985964, endtime: 40985964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:06,9797533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985965, endtime: 40985967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,0040185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985969, endtime: 40985969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,0351820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985972, endtime: 40985972, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,0651035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985975, endtime: 40985975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,0786241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985976, endtime: 40985976, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,0973900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985978, endtime: 40985978, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,1267560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985981, endtime: 40985981, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3232480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985983, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3232677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985984, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3232760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985986, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3232837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985989, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3232898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985992, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3232970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985994, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3233031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985997, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3233103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985998, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3233161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986000, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3233466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985581, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3233538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985583, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3233596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985586, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3233668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985588, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3233727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985592, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3233799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985594, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3233860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985595, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3233932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985599, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3233993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985600, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3234477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985601, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3234552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985603, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3234621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985605, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3234680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985608, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3242745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986001, endtime: 40986001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3589902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986003, endtime: 40986005, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3781738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986006, endtime: 40986006, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,3992461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986008, endtime: 40986009, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6351483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985388, endtime: 40986032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6351677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985391, endtime: 40986032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6351765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985392, endtime: 40986032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6351834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985394, endtime: 40986032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6351904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985395, endtime: 40986032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6351965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985397, endtime: 40986032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6352034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985398, endtime: 40986032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6352092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985400, endtime: 40986032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6352164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985400, endtime: 40986032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6352472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985401, endtime: 40986032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6352646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985404, endtime: 40986032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6352793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985406, endtime: 40986032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6352923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985408, endtime: 40986032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6490271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985478, endtime: 40986034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6490429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985480, endtime: 40986034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6490518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985481, endtime: 40986034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6490584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985483, endtime: 40986034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6490656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985484, endtime: 40986034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6490714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985488, endtime: 40986034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6490784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985489, endtime: 40986034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6490845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985491, endtime: 40986034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6490914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985492, endtime: 40986034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6491213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985494, endtime: 40986034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6491288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985495, endtime: 40986034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6491346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985497, endtime: 40986034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:07,6491415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985498, endtime: 40986034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:09,0748620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985754, endtime: 40986176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:09,0748825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985756, endtime: 40986176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:09,0749038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985758, endtime: 40986176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:09,0749199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985761, endtime: 40986176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:09,0749310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985764, endtime: 40986176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:09,0749404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985766, endtime: 40986176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:09,0749479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985768, endtime: 40986176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:09,0749564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985769, endtime: 40986176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:09,0749631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985772, endtime: 40986176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:09,0749991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985775, endtime: 40986176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:09,0750055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985778, endtime: 40986176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:09,0750124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985780, endtime: 40986176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:09,0750188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985781, endtime: 40986176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,1146298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985655, endtime: 40986280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,1146602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985656, endtime: 40986280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,1146749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985659, endtime: 40986280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,1146827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985659, endtime: 40986280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,1146910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985661, endtime: 40986280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,1146974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985662, endtime: 40986280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,1147048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985664, endtime: 40986280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,1147112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985666, endtime: 40986280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,1147187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985669, endtime: 40986280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,1147492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985670, endtime: 40986280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,1147567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985672, endtime: 40986280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,1147625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985673, endtime: 40986280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,1147694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40985675, endtime: 40986280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,2862798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986034, endtime: 40986297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,2862981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986034, endtime: 40986297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,2863059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986036, endtime: 40986297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,2863134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986037, endtime: 40986297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,2863195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986041, endtime: 40986297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,2863264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986042, endtime: 40986297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,2863322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986044, endtime: 40986297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,2863391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986048, endtime: 40986297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,2863444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986050, endtime: 40986297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,2863763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986051, endtime: 40986297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,2863821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986053, endtime: 40986297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,2863890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986055, endtime: 40986297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:10,2863945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986058, endtime: 40986297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,3542168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986032, endtime: 40986404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,3542350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986033, endtime: 40986404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,3542428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986034, endtime: 40986404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,3542630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986036, endtime: 40986404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,3542747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986037, endtime: 40986404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,3542849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986041, endtime: 40986404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,3542929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986042, endtime: 40986404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,3543026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986044, endtime: 40986404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,3543104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986048, endtime: 40986404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,3543547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986050, endtime: 40986404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,3543628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986051, endtime: 40986404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,3543716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986053, endtime: 40986404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,3543797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986055, endtime: 40986404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,7376562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986011, endtime: 40986442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,7376729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986014, endtime: 40986442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,7376801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986016, endtime: 40986442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,7376873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986017, endtime: 40986442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,7376928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986019, endtime: 40986442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,7376994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986022, endtime: 40986442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,7377050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986025, endtime: 40986442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,7377116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986026, endtime: 40986442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,7377169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986028, endtime: 40986442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,7377482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986030, endtime: 40986442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,7377540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986031, endtime: 40986442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,7377604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986033, endtime: 40986442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,7377659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986034, endtime: 40986442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,9887574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986176, endtime: 40986467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,9887759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986178, endtime: 40986467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,9887837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986180, endtime: 40986467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,9887915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986181, endtime: 40986467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,9887973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986184, endtime: 40986467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,9888045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986186, endtime: 40986467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,9888100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986187, endtime: 40986467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,9888170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986191, endtime: 40986467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,9888228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986192, endtime: 40986467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,9888527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986195, endtime: 40986467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,9888585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986197, endtime: 40986467, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,9889688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986200, endtime: 40986468, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:11,9889790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986203, endtime: 40986468, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,3301115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986001, endtime: 40986502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,3301303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986003, endtime: 40986502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,3301398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986006, endtime: 40986502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,3301464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986008, endtime: 40986502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,3301536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986011, endtime: 40986502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,3301594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986014, endtime: 40986502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,3301664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986016, endtime: 40986502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,3301719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986017, endtime: 40986502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,3301996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986019, endtime: 40986502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,3302057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986022, endtime: 40986502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,3302126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986025, endtime: 40986502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,3302184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986026, endtime: 40986502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,3303121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986028, endtime: 40986502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,5332252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986297, endtime: 40986522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,5332448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986298, endtime: 40986522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,5332529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986300, endtime: 40986522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,5332750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986301, endtime: 40986522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,5332844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986303, endtime: 40986522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,5332922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986305, endtime: 40986522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,5332989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986306, endtime: 40986522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,5333066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986308, endtime: 40986522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,5333133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986309, endtime: 40986522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,5333903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986311, endtime: 40986522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,5333980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986312, endtime: 40986522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,5334052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986314, endtime: 40986522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:12,5335737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986316, endtime: 40986522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:13,6354588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986280, endtime: 40986632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:13,6354757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986281, endtime: 40986632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:13,6354829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986283, endtime: 40986632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:13,6354901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986284, endtime: 40986632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:13,6354960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986286, endtime: 40986632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:13,6355029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986287, endtime: 40986632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:13,6355084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986289, endtime: 40986632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:13,6355151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986291, endtime: 40986632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:13,6355206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986292, endtime: 40986632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:13,6355503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986294, endtime: 40986632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:13,6355558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986295, endtime: 40986632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:13,6355625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986297, endtime: 40986632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:13,6356749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986298, endtime: 40986632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,3713510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986522, endtime: 40986706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,3713693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986523, endtime: 40986706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,3713765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986525, endtime: 40986706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,3713840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986528, endtime: 40986706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,3713895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986530, endtime: 40986706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,3713964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986531, endtime: 40986706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,3714167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986533, endtime: 40986706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,3714294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986534, endtime: 40986706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,3714388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986536, endtime: 40986706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,3715275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986537, endtime: 40986706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,3715347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986541, endtime: 40986706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,3715416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986542, endtime: 40986706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,3717195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986544, endtime: 40986706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,9909711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,9909835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:14,9936023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40986768, endtime: 40986768, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,0383521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986502, endtime: 40986772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,0383706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986505, endtime: 40986772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,0383787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986506, endtime: 40986772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,0383864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986509, endtime: 40986772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,0383925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986509, endtime: 40986772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,0383995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986511, endtime: 40986772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,0384053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986512, endtime: 40986772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,0384125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986514, endtime: 40986772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,0384183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986516, endtime: 40986772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,0384479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986519, endtime: 40986772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,0384540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986520, endtime: 40986772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,0384610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986522, endtime: 40986772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,0384668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986523, endtime: 40986772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,1499583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986632, endtime: 40986784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,1499788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986634, endtime: 40986784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,1499868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986636, endtime: 40986784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,1499951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986637, endtime: 40986784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,1500012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986639, endtime: 40986784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,1500087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986643, endtime: 40986784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,1500148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986646, endtime: 40986784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,1500220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986647, endtime: 40986784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,1500284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986648, endtime: 40986784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,1500602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986652, endtime: 40986784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,1500666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986653, endtime: 40986784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,1500735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986655, endtime: 40986784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,1500796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986658, endtime: 40986784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,5302643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986467, endtime: 40986822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,5302837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986469, endtime: 40986822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,5302914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986470, endtime: 40986822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,5302989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986472, endtime: 40986822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,5303047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986473, endtime: 40986822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,5303114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986475, endtime: 40986822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,5303169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986476, endtime: 40986822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,5303238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986478, endtime: 40986822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,5303294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986480, endtime: 40986822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,5303740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986481, endtime: 40986822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,5303812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986483, endtime: 40986822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,5303884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986484, endtime: 40986822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,5303939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986486, endtime: 40986822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,9374799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986404, endtime: 40986862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,9374981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986406, endtime: 40986862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,9375056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986410, endtime: 40986862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,9375128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986411, endtime: 40986862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,9375184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986412, endtime: 40986862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,9375250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986414, endtime: 40986862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,9375306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986416, endtime: 40986862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,9375369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986417, endtime: 40986862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,9375425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986420, endtime: 40986862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,9375718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986422, endtime: 40986862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,9375779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986425, endtime: 40986862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,9375846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986428, endtime: 40986862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:15,9375898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986431, endtime: 40986862, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,1482810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986442, endtime: 40986883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,1482998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986445, endtime: 40986883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,1483084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986447, endtime: 40986883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,1483167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986450, endtime: 40986883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,1483234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986452, endtime: 40986883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,1483309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986453, endtime: 40986883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,1483370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986455, endtime: 40986883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,1483442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986456, endtime: 40986883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,1483500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986460, endtime: 40986883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,1483788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986461, endtime: 40986883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,1483852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986462, endtime: 40986883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,1483924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986464, endtime: 40986883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,1483985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986466, endtime: 40986883, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:16,7582994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55133 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,8478234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986772, endtime: 40987053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,8478447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986773, endtime: 40987053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,8478531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986775, endtime: 40987053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,8478608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986776, endtime: 40987053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,8478672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986778, endtime: 40987053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,8478741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986781, endtime: 40987053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,8478802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986783, endtime: 40987053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,8480608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986784, endtime: 40987053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,8485291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986786, endtime: 40987053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,8485404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986788, endtime: 40987053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,8485468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986791, endtime: 40987053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,8485537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986795, endtime: 40987053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,8485593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986797, endtime: 40987053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,9178612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986822, endtime: 40987060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,9178801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986823, endtime: 40987060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,9178870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986825, endtime: 40987060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,9178942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986826, endtime: 40987060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,9178997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986828, endtime: 40987060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,9179064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986830, endtime: 40987060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,9179119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986831, endtime: 40987060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,9179186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986833, endtime: 40987060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,9179239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986834, endtime: 40987060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,9179535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986838, endtime: 40987060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,9179590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986841, endtime: 40987060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,9179657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986844, endtime: 40987060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:17,9179712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986845, endtime: 40987060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,1843301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986706, endtime: 40987087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,1843484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986708, endtime: 40987087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,1843565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986709, endtime: 40987087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,1843645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986711, endtime: 40987087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,1843709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986712, endtime: 40987087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,1843781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986714, endtime: 40987087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,1843839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986716, endtime: 40987087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,1843911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986719, endtime: 40987087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,1843969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986722, endtime: 40987087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,1844277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986725, endtime: 40987087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,1844340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986727, endtime: 40987087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,1844412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986730, endtime: 40987087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,1844471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986733, endtime: 40987087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,5355721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986883, endtime: 40987122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,5355929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986886, endtime: 40987122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,5356012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986889, endtime: 40987122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,5356089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986891, endtime: 40987122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,5356150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986894, endtime: 40987122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,5356353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986895, endtime: 40987122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,5356433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986897, endtime: 40987122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,5356511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986899, endtime: 40987122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,5356574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986900, endtime: 40987122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,5356904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986901, endtime: 40987122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,5356971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986901, endtime: 40987122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,5357043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986903, endtime: 40987122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:18,5357101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986905, endtime: 40987122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:19,7809972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55232 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:20,6191774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986862, endtime: 40987331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:20,6191929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986864, endtime: 40987331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:20,6192001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986866, endtime: 40987331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:20,6192076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986867, endtime: 40987331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:20,6192134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986869, endtime: 40987331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:20,6192200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986870, endtime: 40987331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:20,6192253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986872, endtime: 40987331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:20,6192319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986873, endtime: 40987331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:20,6192375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986877, endtime: 40987331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:20,6192774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986878, endtime: 40987331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:20,6192843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986881, endtime: 40987331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:20,6192915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986883, endtime: 40987331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:20,6192973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40986886, endtime: 40987331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,0053874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987087, endtime: 40987369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,0054046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987090, endtime: 40987369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,0054123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987092, endtime: 40987369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,0054198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987095, endtime: 40987369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,0054259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987098, endtime: 40987369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,0054331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987103, endtime: 40987369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,0054389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987103, endtime: 40987369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,0054459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987104, endtime: 40987369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,0054517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987104, endtime: 40987369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,0054788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987105, endtime: 40987369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,0054852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987106, endtime: 40987369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,0055836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987108, endtime: 40987369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,0055944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987109, endtime: 40987369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,6028272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987122, endtime: 40987429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,6028432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987123, endtime: 40987429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,6028505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987125, endtime: 40987429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,6028574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987126, endtime: 40987429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,6028632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987128, endtime: 40987429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,6028698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987130, endtime: 40987429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,6028754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987131, endtime: 40987429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,6028818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987133, endtime: 40987429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,6028873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987134, endtime: 40987429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,6029158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987136, endtime: 40987429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,6029217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987137, endtime: 40987429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,6029283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987139, endtime: 40987429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:21,6029336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987142, endtime: 40987429, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,1866283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987060, endtime: 40987487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,1866455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987062, endtime: 40987487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,1866530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987066, endtime: 40987487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,1866605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987067, endtime: 40987487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,1866663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987069, endtime: 40987487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,1866727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987070, endtime: 40987487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,1866782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987073, endtime: 40987487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,1866846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987075, endtime: 40987487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,1866901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987077, endtime: 40987487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,1867209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987080, endtime: 40987487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,1867264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987082, endtime: 40987487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,1867328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987083, endtime: 40987487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,1867383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987087, endtime: 40987487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,2733133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987487, endtime: 40987496, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,3576245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987053, endtime: 40987504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,3576561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987055, endtime: 40987504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,3576653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987056, endtime: 40987504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,3576736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987058, endtime: 40987504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,3576802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987059, endtime: 40987504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,3576877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987061, endtime: 40987504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,3576941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987062, endtime: 40987504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,3577018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987066, endtime: 40987504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,3577079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987067, endtime: 40987504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,3577392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987069, endtime: 40987504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,3577456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987070, endtime: 40987504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,3577528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987073, endtime: 40987504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:22,3577586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987075, endtime: 40987504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:24,1734582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987331, endtime: 40987686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:24,1734801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987331, endtime: 40987686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:24,1734881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987333, endtime: 40987686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:24,1734959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987334, endtime: 40987686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:24,1735022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987336, endtime: 40987686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:24,1735094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987339, endtime: 40987686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:24,1735153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987342, endtime: 40987686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:24,1735225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987344, endtime: 40987686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:24,1735280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987345, endtime: 40987686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:24,1735704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987348, endtime: 40987686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:24,1735829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987350, endtime: 40987686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:24,1735953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987352, endtime: 40987686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:24,1736056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987353, endtime: 40987686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,0661954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,0662067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,0666716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40987775, endtime: 40987775, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7391393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987369, endtime: 40987843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7391584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987370, endtime: 40987843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7391662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987372, endtime: 40987843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7391739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987373, endtime: 40987843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7391800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987375, endtime: 40987843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7391870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987376, endtime: 40987843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7391925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987378, endtime: 40987843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7391992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987380, endtime: 40987843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7392050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987381, endtime: 40987843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7394391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987384, endtime: 40987843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7394504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987386, endtime: 40987843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7394585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987387, endtime: 40987843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7394646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987389, endtime: 40987843, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7535919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987429, endtime: 40987844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7536102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987430, endtime: 40987844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7536177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987431, endtime: 40987844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7536249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987434, endtime: 40987844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7536307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987436, endtime: 40987844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7536374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987438, endtime: 40987844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7536429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987441, endtime: 40987844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7538019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987442, endtime: 40987844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7538122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987446, endtime: 40987844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7538200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987448, endtime: 40987844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7538266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987451, endtime: 40987844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7538338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987453, endtime: 40987844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7538396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987455, endtime: 40987844, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,7967132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55232 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,9041010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987504, endtime: 40987859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,9041176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987506, endtime: 40987859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,9041251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987508, endtime: 40987859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,9041326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987509, endtime: 40987859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,9041384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987511, endtime: 40987859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,9041456</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987514, endtime: 40987859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,9041511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987517, endtime: 40987859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,9041578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987519, endtime: 40987859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,9041636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987522, endtime: 40987859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,9041921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987523, endtime: 40987859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,9041982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987525, endtime: 40987859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,9042051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987527, endtime: 40987859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:25,9043052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987530, endtime: 40987859, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,5811176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987489, endtime: 40987927, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,5811312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987491, endtime: 40987927, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,5811395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987492, endtime: 40987927, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,5811459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987494, endtime: 40987927, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,5811528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987495, endtime: 40987927, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,5811581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987497, endtime: 40987927, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,5811647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987498, endtime: 40987927, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,5811703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987500, endtime: 40987927, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,5811766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987500, endtime: 40987927, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,5812334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987501, endtime: 40987927, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,5812415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987503, endtime: 40987927, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,5813307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987505, endtime: 40987927, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,6649750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987506, endtime: 40987935, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,6649911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987927, endtime: 40987935, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,6649999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987928, endtime: 40987935, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,6650066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987931, endtime: 40987935, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,6650141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987933, endtime: 40987935, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,6746750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987936, endtime: 40987936, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,6889938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987937, endtime: 40987938, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,7043203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987939, endtime: 40987939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,7199909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987941, endtime: 40987941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,7358745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987942, endtime: 40987942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,7522795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987944, endtime: 40987944, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,7666033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987945, endtime: 40987945, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,7829488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987947, endtime: 40987947, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,9976362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:26,9979460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987968, endtime: 40987968, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,0162469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987970, endtime: 40987970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,0322111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987972, endtime: 40987972, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,0655390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987975, endtime: 40987975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,0798836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987977, endtime: 40987977, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,0984788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987978, endtime: 40987978, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1104864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987980, endtime: 40987980, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1279426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987981, endtime: 40987981, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1430759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987983, endtime: 40987983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1581287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987984, endtime: 40987984, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1634077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987686, endtime: 40987985, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1634249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987689, endtime: 40987985, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1634329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987690, endtime: 40987985, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1634415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987692, endtime: 40987985, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1634479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987694, endtime: 40987985, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1634554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987695, endtime: 40987985, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1634617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987697, endtime: 40987985, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1634695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987700, endtime: 40987985, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1634756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987703, endtime: 40987985, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1635066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987706, endtime: 40987985, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1635130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987708, endtime: 40987985, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1635202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987711, endtime: 40987985, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1635263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987713, endtime: 40987985, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1703311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987986, endtime: 40987986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1761185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987986, endtime: 40987986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1819940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987987, endtime: 40987987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,1875997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987987, endtime: 40987987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,2043538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987989, endtime: 40987989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,2218493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987991, endtime: 40987991, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,2528774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987994, endtime: 40987994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,2676556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987995, endtime: 40987995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,3152424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988000, endtime: 40988000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,3206298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988001, endtime: 40988001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,3524444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988003, endtime: 40988004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,3695856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988005, endtime: 40988006, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,3927242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988008, endtime: 40988008, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,4067011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988009, endtime: 40988009, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,4248832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988011, endtime: 40988011, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,4398775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988012, endtime: 40988013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,5276971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988015, endtime: 40988021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,5277176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988017, endtime: 40988021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,5277259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988019, endtime: 40988021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,5277339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988020, endtime: 40988021, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,5490259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988023, endtime: 40988024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,5655235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988025, endtime: 40988025, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,5799703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988027, endtime: 40988027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,6147367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988030, endtime: 40988030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,6427368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988033, endtime: 40988033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,6576776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988034, endtime: 40988034, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,6887140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988037, endtime: 40988037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,7050833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988039, endtime: 40988039, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:27,7220039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988040, endtime: 40988041, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,5204108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987948, endtime: 40988121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,5204282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987950, endtime: 40988121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,5204351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987951, endtime: 40988121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,5204423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987953, endtime: 40988121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,5204482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987955, endtime: 40988121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,5204545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987958, endtime: 40988121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,5204601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987960, endtime: 40988121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,5205994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987962, endtime: 40988121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,5206102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987966, endtime: 40988121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,5206183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987967, endtime: 40988121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,5206247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987969, endtime: 40988121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,5208305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987970, endtime: 40988121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,5208385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987972, endtime: 40988121, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,8941921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987843, endtime: 40988158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,8942101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987844, endtime: 40988158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,8942176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987845, endtime: 40988158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,8942250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987848, endtime: 40988158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,8942309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987850, endtime: 40988158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,8942378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987853, endtime: 40988158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,8942430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987855, endtime: 40988158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,8942497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987856, endtime: 40988158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,8942552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987858, endtime: 40988158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,8942982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987859, endtime: 40988158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,8943040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987861, endtime: 40988158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,8943106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987864, endtime: 40988158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:28,8943165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987867, endtime: 40988158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,5721715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987844, endtime: 40988226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,5721923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987845, endtime: 40988226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,5722003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987848, endtime: 40988226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,5722081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987850, endtime: 40988226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,5722141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987853, endtime: 40988226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,5722211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987855, endtime: 40988226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,5722266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987856, endtime: 40988226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,5722335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987858, endtime: 40988226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,5722394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987859, endtime: 40988226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,5722696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987861, endtime: 40988226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,5722757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987864, endtime: 40988226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,5722829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987867, endtime: 40988226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,5722887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987869, endtime: 40988226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,6539961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987859, endtime: 40988234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,6540260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987861, endtime: 40988234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,6540346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987864, endtime: 40988234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,6540432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987867, endtime: 40988234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,6540499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987869, endtime: 40988234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,6540576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987870, endtime: 40988234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,6540640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987873, endtime: 40988234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,6540715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987875, endtime: 40988234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,6540776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987876, endtime: 40988234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,6541116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987878, endtime: 40988234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,6541177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987879, endtime: 40988234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,6541244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987880, endtime: 40988234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,6541302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987885, endtime: 40988234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,9731034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987985, endtime: 40988266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,9731170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987986, endtime: 40988266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,9731239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987986, endtime: 40988266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,9731309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987987, endtime: 40988266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,9731361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987987, endtime: 40988266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,9731425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987989, endtime: 40988266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,9731478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987991, endtime: 40988266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,9731541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987994, endtime: 40988266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,9731591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40987995, endtime: 40988266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,9731857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988000, endtime: 40988266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,9731913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988001, endtime: 40988266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,9731974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988003, endtime: 40988266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:29,9732026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988005, endtime: 40988266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:30,8764267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988158, endtime: 40988356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:30,8764444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988161, endtime: 40988356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:30,8764519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988162, endtime: 40988356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:30,8764591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988164, endtime: 40988356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:30,8764649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988167, endtime: 40988356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:30,8764716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988169, endtime: 40988356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:30,8764771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988172, endtime: 40988356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:30,8764835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988175, endtime: 40988356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:30,8764890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988176, endtime: 40988356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:30,8765178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988178, endtime: 40988356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:30,8765236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988180, endtime: 40988356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:30,8765300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988183, endtime: 40988356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:30,8765353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988186, endtime: 40988356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,1654119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988234, endtime: 40988385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,1654308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988236, endtime: 40988385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,1654385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988239, endtime: 40988385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,1654460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988242, endtime: 40988385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,1654518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988244, endtime: 40988385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,1654587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988247, endtime: 40988385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,1654643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988251, endtime: 40988385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,1654709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988254, endtime: 40988385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,1654765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988256, endtime: 40988385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,1655086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988258, endtime: 40988385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,1655144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988261, endtime: 40988385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,1655211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988262, endtime: 40988385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,1655269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988265, endtime: 40988385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,9743122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988266, endtime: 40988466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,9743297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988267, endtime: 40988466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,9743375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988269, endtime: 40988466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,9743449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988270, endtime: 40988466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,9743510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988272, endtime: 40988466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,9743582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988273, endtime: 40988466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,9743643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988275, endtime: 40988466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,9743713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988277, endtime: 40988466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,9743771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988280, endtime: 40988466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,9744051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988283, endtime: 40988466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,9744114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988284, endtime: 40988466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,9744184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988286, endtime: 40988466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:31,9744244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988290, endtime: 40988466, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:32,1155942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988226, endtime: 40988480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:32,1156092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988228, endtime: 40988480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:32,1156158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988230, endtime: 40988480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:32,1156227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988231, endtime: 40988480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:32,1156283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988234, endtime: 40988480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:32,1156346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988236, endtime: 40988480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:32,1156396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988239, endtime: 40988480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:32,1156463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988242, endtime: 40988480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:32,1156513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988244, endtime: 40988480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:32,1156798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988247, endtime: 40988480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:32,1156854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988251, endtime: 40988480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:32,1156914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988254, endtime: 40988480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:32,1156970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988256, endtime: 40988480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,7280673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988356, endtime: 40988641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,7280848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988358, endtime: 40988641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,7280917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988361, endtime: 40988641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,7280989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988362, endtime: 40988641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,7281047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988364, endtime: 40988641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,7281114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988367, endtime: 40988641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,7281166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988370, endtime: 40988641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,7281233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988372, endtime: 40988641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,7281285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988375, endtime: 40988641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,7281732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988376, endtime: 40988641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,7281801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988378, endtime: 40988641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,7281867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988380, endtime: 40988641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,7281923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988383, endtime: 40988641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,8765284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988385, endtime: 40988656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,8765464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988386, endtime: 40988656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,8765538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988389, endtime: 40988656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,8765613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988392, endtime: 40988656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,8765674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988394, endtime: 40988656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,8765746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988395, endtime: 40988656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,8765804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988397, endtime: 40988656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,8775288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988399, endtime: 40988656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,8775407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988400, endtime: 40988656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,8775490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988400, endtime: 40988656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,8775554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988401, endtime: 40988656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,8775621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988403, endtime: 40988656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:33,8775679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988405, endtime: 40988656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:34,4270296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988042, endtime: 40988711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:34,4270506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988044, endtime: 40988711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:34,4270601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988046, endtime: 40988711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:34,4270670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988048, endtime: 40988711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:34,4270742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988051, endtime: 40988711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:34,4270806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988053, endtime: 40988711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:34,4270878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988057, endtime: 40988711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:34,4270936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988058, endtime: 40988711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:34,4271008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988061, endtime: 40988711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:34,4271764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988062, endtime: 40988711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:34,4271856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988064, endtime: 40988711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:34,4271917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988066, endtime: 40988711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:34,4273119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988069, endtime: 40988711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3259299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3259509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3264616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40988801, endtime: 40988801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3300794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988466, endtime: 40988802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3300985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988467, endtime: 40988802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3301065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988469, endtime: 40988802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3301143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988470, endtime: 40988802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3301201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988472, endtime: 40988802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3301270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988473, endtime: 40988802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3301325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988475, endtime: 40988802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3301398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988476, endtime: 40988802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3301453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988480, endtime: 40988802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3301977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988481, endtime: 40988802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3302049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988483, endtime: 40988802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3302115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988484, endtime: 40988802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,3302171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988486, endtime: 40988802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4134488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988802, endtime: 40988810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4971511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988641, endtime: 40988818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4971707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988642, endtime: 40988818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4971791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988644, endtime: 40988818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4971874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988647, endtime: 40988818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4971937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988648, endtime: 40988818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4972012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988650, endtime: 40988818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4972073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988651, endtime: 40988818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4972145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988653, endtime: 40988818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4972206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988656, endtime: 40988818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4972505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988658, endtime: 40988818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4972572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988661, endtime: 40988818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4972644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988662, endtime: 40988818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,4972705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988664, endtime: 40988818, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,6562486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988480, endtime: 40988834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,6562655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988481, endtime: 40988834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,6562730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988483, endtime: 40988834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,6562810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988484, endtime: 40988834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,6562871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988486, endtime: 40988834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,6562943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988487, endtime: 40988834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,6562998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988489, endtime: 40988834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,6563068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988491, endtime: 40988834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,6563123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988494, endtime: 40988834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,6563417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988495, endtime: 40988834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,6563475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988497, endtime: 40988834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,6563541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988498, endtime: 40988834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:35,6563599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988501, endtime: 40988834, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:36,2845225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988121, endtime: 40988897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:36,2845388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988122, endtime: 40988897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:36,2845474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988125, endtime: 40988897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:36,2845535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988127, endtime: 40988897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:36,2845602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988129, endtime: 40988897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:36,2845657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988130, endtime: 40988897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:36,2845723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988133, endtime: 40988897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:36,2845776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988134, endtime: 40988897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:36,2845840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988136, endtime: 40988897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:36,2846114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988139, endtime: 40988897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:36,2846183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988141, endtime: 40988897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:36,2846236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988142, endtime: 40988897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:36,2846300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988145, endtime: 40988897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,2640115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988803, endtime: 40988995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,2640264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988806, endtime: 40988995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,2640347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988808, endtime: 40988995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,2640408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988809, endtime: 40988995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,2640478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988811, endtime: 40988995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,2640533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988812, endtime: 40988995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,2640599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988816, endtime: 40988995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,2640655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988817, endtime: 40988995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,2640719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988820, endtime: 40988995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,2641314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988822, endtime: 40988995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,2641395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988823, endtime: 40988995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,2641461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988825, endtime: 40988995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,3548507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988826, endtime: 40989004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,3548695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988995, endtime: 40989004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,3548775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988997, endtime: 40989004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,3548853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988999, endtime: 40989004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,3548914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989000, endtime: 40989004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,3548986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989000, endtime: 40989004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,3549044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989001, endtime: 40989004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,3549116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989003, endtime: 40989004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,3861242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989006, endtime: 40989007, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,4079282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989009, endtime: 40989009, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,4407973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989012, endtime: 40989013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,4731622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989016, endtime: 40989016, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,5031108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989019, endtime: 40989019, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,5076712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55201 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6098650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988834, endtime: 40989030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6098855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988836, endtime: 40989030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6098938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988839, endtime: 40989030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6099018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988842, endtime: 40989030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6099082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988844, endtime: 40989030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6099154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988845, endtime: 40989030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6099212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988848, endtime: 40989030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6102758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988850, endtime: 40989030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6102869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988851, endtime: 40989030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6102949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988853, endtime: 40989030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6103016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988855, endtime: 40989030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6103088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988856, endtime: 40989030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6103149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988859, endtime: 40989030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6674732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988656, endtime: 40989035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6674904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988658, endtime: 40989035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6674976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988661, endtime: 40989035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6675048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988662, endtime: 40989035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6675106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988664, endtime: 40989035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6675173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988665, endtime: 40989035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6675228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988667, endtime: 40989035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6675297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988669, endtime: 40989035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6675525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988670, endtime: 40989035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6675885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988672, endtime: 40989035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6675946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988673, endtime: 40989035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6676012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988675, endtime: 40989035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6676070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988678, endtime: 40989035, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6824024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988897, endtime: 40989037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6824209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988898, endtime: 40989037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6824284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988900, endtime: 40989037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6824365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988901, endtime: 40989037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6824426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988903, endtime: 40989037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6824498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988905, endtime: 40989037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6824553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988906, endtime: 40989037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6824625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988908, endtime: 40989037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6824683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988909, endtime: 40989037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6825049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988911, endtime: 40989037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6825115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988912, endtime: 40989037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6825185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988914, endtime: 40989037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:37,6825243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988916, endtime: 40989037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:38,6966641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988711, endtime: 40989138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:38,6966830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988712, endtime: 40989138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:38,6966904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988714, endtime: 40989138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:38,6966982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988717, endtime: 40989138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:38,6967043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988719, endtime: 40989138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:38,6967112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988720, endtime: 40989138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:38,6967168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988722, endtime: 40989138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:38,6967234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988723, endtime: 40989138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:38,6967290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988725, endtime: 40989138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:38,6968104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988726, endtime: 40989138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:38,6968187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988728, endtime: 40989138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:38,6968270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988730, endtime: 40989138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:38,6974083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40988733, endtime: 40989138, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,0406253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989022, endtime: 40989173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,0406444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989025, endtime: 40989173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,0406525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989027, endtime: 40989173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,0406602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989030, endtime: 40989173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,0406661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989031, endtime: 40989173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,0406730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989036, endtime: 40989173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,0406785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989037, endtime: 40989173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,0406854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989039, endtime: 40989173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,0406907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989041, endtime: 40989173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,0407220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989042, endtime: 40989173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,0407278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989045, endtime: 40989173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,0407345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989047, endtime: 40989173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,0407403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989048, endtime: 40989173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,2532171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989036, endtime: 40989194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,2532345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989037, endtime: 40989194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,2532420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989039, endtime: 40989194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,2532498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989041, endtime: 40989194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,2532561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989042, endtime: 40989194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,2532633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989045, endtime: 40989194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,2532692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989047, endtime: 40989194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,2532764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989048, endtime: 40989194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,2532822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989050, endtime: 40989194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,2533584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989052, endtime: 40989194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,2533661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989053, endtime: 40989194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,2533733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989056, endtime: 40989194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,2535210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989058, endtime: 40989194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,8671040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989030, endtime: 40989255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,8671237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989031, endtime: 40989255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,8671317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989036, endtime: 40989255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,8671398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989037, endtime: 40989255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,8671461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989039, endtime: 40989255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,8671533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989041, endtime: 40989255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,8671592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989042, endtime: 40989255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,8671661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989045, endtime: 40989255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,8671719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989047, endtime: 40989255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,8672018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989048, endtime: 40989255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,8672082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989050, endtime: 40989255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,8672151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989052, endtime: 40989255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:39,8672209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989053, endtime: 40989255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,5161327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,6573410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989037, endtime: 40989334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,6573621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989039, endtime: 40989334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,6573701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989041, endtime: 40989334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,6573781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989042, endtime: 40989334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,6573845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989045, endtime: 40989334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,6573917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989047, endtime: 40989334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,6573978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989048, endtime: 40989334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,6574047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989050, endtime: 40989334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,6574108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989052, endtime: 40989334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,6574405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989053, endtime: 40989334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,6574466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989056, endtime: 40989334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,6574538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989058, endtime: 40989334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:40,6574596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989059, endtime: 40989334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:41,4474082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989194, endtime: 40989413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:41,4474262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989195, endtime: 40989413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:41,4474339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989197, endtime: 40989413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:41,4474417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989198, endtime: 40989413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:41,4474630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989200, endtime: 40989413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:41,4474760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989202, endtime: 40989413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:41,4474863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989202, endtime: 40989413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:41,4474985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989205, endtime: 40989413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:41,4475090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989206, endtime: 40989413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:41,4475830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989206, endtime: 40989413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:41,4475907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989210, endtime: 40989413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:41,4475977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989212, endtime: 40989413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:42,0655540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989138, endtime: 40989475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:42,0655726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989141, endtime: 40989475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:42,0655803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989144, endtime: 40989475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:42,0655878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989145, endtime: 40989475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:42,0655936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989147, endtime: 40989475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:42,0656005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989148, endtime: 40989475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:42,0656061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989150, endtime: 40989475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:42,0656125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989151, endtime: 40989475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:42,0656180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989153, endtime: 40989475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:42,0656476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989156, endtime: 40989475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:42,0656537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989158, endtime: 40989475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:42,0656604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989159, endtime: 40989475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:42,0656659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989161, endtime: 40989475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:43,4672667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989214, endtime: 40989615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:43,4672872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989413, endtime: 40989615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:43,4672952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989414, endtime: 40989615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:43,4673036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989416, endtime: 40989615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:43,4673099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989417, endtime: 40989615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:43,4673171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989419, endtime: 40989615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:43,4673238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989420, endtime: 40989615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:43,4673310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989424, endtime: 40989615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:43,4673371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989427, endtime: 40989615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:43,4673670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989428, endtime: 40989615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:43,4673736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989430, endtime: 40989615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:43,4673809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989431, endtime: 40989615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:43,4673869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989433, endtime: 40989615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,1539133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989334, endtime: 40989684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,1539318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989336, endtime: 40989684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,1539399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989337, endtime: 40989684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,1539479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989339, endtime: 40989684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,1539540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989341, endtime: 40989684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,1539615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989342, endtime: 40989684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,1539673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989345, endtime: 40989684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,1539742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989349, endtime: 40989684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,1539803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989350, endtime: 40989684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,1540100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989352, endtime: 40989684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,1540163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989353, endtime: 40989684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,1540233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989355, endtime: 40989684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,1540291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989356, endtime: 40989684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,3344000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989255, endtime: 40989702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,3344305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989256, endtime: 40989702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,3344394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989258, endtime: 40989702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,3344474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989259, endtime: 40989702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,3344538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989261, endtime: 40989702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,3344613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989262, endtime: 40989702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,3344674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989266, endtime: 40989702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,3344746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989267, endtime: 40989702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,3344807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989269, endtime: 40989702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,3345095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989270, endtime: 40989702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,3345156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989272, endtime: 40989702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,3345225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989273, endtime: 40989702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,3345283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989275, endtime: 40989702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,5329082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989173, endtime: 40989722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,5329273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989173, endtime: 40989722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,5329395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989175, endtime: 40989722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,5329489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989176, endtime: 40989722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,5329589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989178, endtime: 40989722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,5329658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989180, endtime: 40989722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,5329744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989183, endtime: 40989722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,5329814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989184, endtime: 40989722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,5329897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989186, endtime: 40989722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,5330201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989188, endtime: 40989722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,5330268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989189, endtime: 40989722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,5330321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989191, endtime: 40989722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:44,5330384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989192, endtime: 40989722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:45,4236528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:45,4236645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:45,4239227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40989811, endtime: 40989811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,5324369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6103470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6110599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989930, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6142255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989615, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6142424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989617, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6142496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989621, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6142571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989622, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6142627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989623, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6142693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989625, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6142749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989628, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6142815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989630, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6142870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989633, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6143391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989634, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6143499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989637, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6143574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989639, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6143632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989641, endtime: 40989930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6257076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989931, endtime: 40989931, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6411895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989933, endtime: 40989933, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6570767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989934, endtime: 40989934, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6724428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989936, endtime: 40989936, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,6882549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989937, endtime: 40989937, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,7037872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989939, endtime: 40989939, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,7192941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989940, endtime: 40989941, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,7517736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989944, endtime: 40989944, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,7937484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989947, endtime: 40989948, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8080528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989475, endtime: 40989949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8080775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989476, endtime: 40989949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8080858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989478, endtime: 40989949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8080938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989480, endtime: 40989949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8081002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989481, endtime: 40989949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8081077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989483, endtime: 40989949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8081138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989486, endtime: 40989949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8081207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989487, endtime: 40989949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8081265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989489, endtime: 40989949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8081590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989492, endtime: 40989949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8081653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989495, endtime: 40989949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8081723</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989499, endtime: 40989949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8081784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989500, endtime: 40989949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8336163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989951, endtime: 40989952, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8446032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989953, endtime: 40989953, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8610794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989955, endtime: 40989955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8759953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989956, endtime: 40989956, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,8943705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989958, endtime: 40989958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,9232500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989961, endtime: 40989961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,9391560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989962, endtime: 40989963, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,9542584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989964, endtime: 40989964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,9714791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989966, endtime: 40989966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:46,9852560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989967, endtime: 40989967, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,0016314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989969, endtime: 40989969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,0170902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989970, endtime: 40989970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,0349737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989972, endtime: 40989972, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,0479801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989973, endtime: 40989973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,0649846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989975, endtime: 40989975, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,1832103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989702, endtime: 40989987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,1832283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989703, endtime: 40989987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,1832358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989705, endtime: 40989987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,1832433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989706, endtime: 40989987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,1832491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989708, endtime: 40989987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,1832560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989709, endtime: 40989987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,1832615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989712, endtime: 40989987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,1832685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989716, endtime: 40989987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,1832740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989717, endtime: 40989987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,1833028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989719, endtime: 40989987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,1833086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989722, endtime: 40989987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,1833156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989723, endtime: 40989987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,1833211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989725, endtime: 40989987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2509380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989684, endtime: 40989994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2509557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989687, endtime: 40989994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2509632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989691, endtime: 40989994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2509704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989692, endtime: 40989994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2509763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989694, endtime: 40989994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2509829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989695, endtime: 40989994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2509884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989697, endtime: 40989994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2509954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989698, endtime: 40989994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2510009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989700, endtime: 40989994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2510308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989702, endtime: 40989994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2510366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989703, endtime: 40989994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2510430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989705, endtime: 40989994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2510486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989706, endtime: 40989994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,2648327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989987, endtime: 40989995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,3014761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989976, endtime: 40989999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,3014947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989978, endtime: 40989999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,3015021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989980, endtime: 40989999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,3015099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989981, endtime: 40989999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,3015160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989983, endtime: 40989999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,3015229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989984, endtime: 40989999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,3015290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989986, endtime: 40989999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,3015357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989987, endtime: 40989999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,3015415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989989, endtime: 40989999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,3015664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989991, endtime: 40989999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,3015725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989994, endtime: 40989999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,3015792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989995, endtime: 40989999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,3045550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989998, endtime: 40989999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,4430492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989722, endtime: 40990013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,4430675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989723, endtime: 40990013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,4430750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989725, endtime: 40990013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,4430822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989727, endtime: 40990013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,4430880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989730, endtime: 40990013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,4430949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989731, endtime: 40990013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,4431005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989733, endtime: 40990013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,4431071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989733, endtime: 40990013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,4431127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989734, endtime: 40990013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,4431423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989736, endtime: 40990013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,4431479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989739, endtime: 40990013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,4431545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989741, endtime: 40990013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:47,4431601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989744, endtime: 40990013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,0053866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55174 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,0843417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989989, endtime: 40990177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,0843556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989991, endtime: 40990177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,0843636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989994, endtime: 40990177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,0843697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989995, endtime: 40990177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,0843761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989998, endtime: 40990177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,0843813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990000, endtime: 40990177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,0843877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990001, endtime: 40990177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,0845797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990005, endtime: 40990177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,0845880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990006, endtime: 40990177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,0845933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990008, endtime: 40990177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,0845997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990009, endtime: 40990177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,0846052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990013, endtime: 40990177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,1565273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990017, endtime: 40990184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,1565470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990177, endtime: 40990184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,1565561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990178, endtime: 40990184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,1565628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990180, endtime: 40990184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,1565700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990181, endtime: 40990184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,1565758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990183, endtime: 40990184, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,1638837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990184, endtime: 40990185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,1735277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990186, endtime: 40990186, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,2045198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990189, endtime: 40990189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,2202455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990191, endtime: 40990191, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,2512098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990194, endtime: 40990194, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,2674860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990195, endtime: 40990195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:49,2832211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990197, endtime: 40990197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0066430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989949, endtime: 40990269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0066607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989951, endtime: 40990269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0066688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989953, endtime: 40990269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0066771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989955, endtime: 40990269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0066832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989956, endtime: 40990269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0066904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989958, endtime: 40990269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0066965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989961, endtime: 40990269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0067034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989962, endtime: 40990269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0067092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989964, endtime: 40990269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0067840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989966, endtime: 40990269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0067918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989967, endtime: 40990269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0067990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989969, endtime: 40990269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0069957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989970, endtime: 40990269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0957833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990198, endtime: 40990278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0958041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990201, endtime: 40990278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0958121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990201, endtime: 40990278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0958202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990202, endtime: 40990278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0958263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990202, endtime: 40990278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0958335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990205, endtime: 40990278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0958390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990208, endtime: 40990278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0958462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990209, endtime: 40990278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0958520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990211, endtime: 40990278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0958814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990213, endtime: 40990278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0958878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990214, endtime: 40990278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0958944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990216, endtime: 40990278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,0959002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990217, endtime: 40990278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,3238506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989994, endtime: 40990301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,3238666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989995, endtime: 40990301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,3238744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40989998, endtime: 40990301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,3238819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990000, endtime: 40990301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,3238880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990001, endtime: 40990301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,3238949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990005, endtime: 40990301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,3239010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990006, endtime: 40990301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,3239079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990008, endtime: 40990301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,3239137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990009, endtime: 40990301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,3239434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990013, endtime: 40990301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,3239498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990017, endtime: 40990301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,3239570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990019, endtime: 40990301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:50,3239628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990020, endtime: 40990301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:51,1459235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990269, endtime: 40990383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:51,1459413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990270, endtime: 40990383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:51,1459490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990272, endtime: 40990383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:51,1459565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990275, endtime: 40990383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:51,1459623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990277, endtime: 40990383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:51,1459698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990278, endtime: 40990383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:51,1459756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990281, endtime: 40990383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:51,1459825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990283, endtime: 40990383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:51,1459884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990284, endtime: 40990383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:51,1460659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990286, endtime: 40990383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:51,1460737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990287, endtime: 40990383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:51,1460806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990292, endtime: 40990383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:51,1461765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990294, endtime: 40990383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0162660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0698511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990301, endtime: 40990476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0698711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990302, endtime: 40990476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0698786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990303, endtime: 40990476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0698863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990303, endtime: 40990476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0698924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990304, endtime: 40990476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0698993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990304, endtime: 40990476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0699052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990305, endtime: 40990476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0699118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990306, endtime: 40990476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0699176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990308, endtime: 40990476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0699473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990312, endtime: 40990476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0699534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990312, endtime: 40990476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0699603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990314, endtime: 40990476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0699664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990316, endtime: 40990476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0807990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,0900416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990477, endtime: 40990478, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,1117223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990480, endtime: 40990480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,1284876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990481, endtime: 40990481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,1585783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990484, endtime: 40990484, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,1905024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990487, endtime: 40990488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,2098431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990489, endtime: 40990490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,2206960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990491, endtime: 40990491, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,2384312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990492, endtime: 40990492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,2695227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990495, endtime: 40990496, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,2815347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990497, endtime: 40990497, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,2997896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990498, endtime: 40990499, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3146701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990500, endtime: 40990500, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3201774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990501, endtime: 40990501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3312474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990502, endtime: 40990502, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3404944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990503, endtime: 40990503, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3462253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990503, endtime: 40990503, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3522502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990504, endtime: 40990504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3580324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990504, endtime: 40990504, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3636951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990505, endtime: 40990505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3698125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990506, endtime: 40990506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3754805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990506, endtime: 40990506, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3815830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990507, endtime: 40990507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3871590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990507, endtime: 40990507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3932459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990508, endtime: 40990508, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,3988325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990508, endtime: 40990508, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,4047213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990509, endtime: 40990509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,5486799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990510, endtime: 40990523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,5487001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990510, endtime: 40990523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,5487084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990511, endtime: 40990523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,5487165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990511, endtime: 40990523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,5487226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990512, endtime: 40990523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,5487298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990513, endtime: 40990523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,5487356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990513, endtime: 40990523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,5487425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990514, endtime: 40990523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,5487481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990514, endtime: 40990523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,5488107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990515, endtime: 40990523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,5488184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990515, endtime: 40990523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:52,5488254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990516, endtime: 40990523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:54,7713942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990476, endtime: 40990746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:54,7714138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990477, endtime: 40990746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:54,7714216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990480, endtime: 40990746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:54,7714296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990481, endtime: 40990746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:54,7714360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990484, endtime: 40990746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:54,7714432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990487, endtime: 40990746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:54,7714490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990489, endtime: 40990746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:54,7714562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990491, endtime: 40990746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:54,7714621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990492, endtime: 40990746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:54,7714895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990495, endtime: 40990746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:54,7714956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990497, endtime: 40990746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:54,7715031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990498, endtime: 40990746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:54,7715089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990500, endtime: 40990746, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,4168483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990013, endtime: 40990810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,4168647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990017, endtime: 40990810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,4168716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990019, endtime: 40990810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,4168788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990020, endtime: 40990810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,4168843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990022, endtime: 40990810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,4168907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990023, endtime: 40990810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,4168963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990025, endtime: 40990810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,4169029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990026, endtime: 40990810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,4169082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990028, endtime: 40990810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,4169384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990030, endtime: 40990810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,4169439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990031, endtime: 40990810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,4169658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990034, endtime: 40990810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,4169766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990036, endtime: 40990810, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,5356231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990810, endtime: 40990822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,5356436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990812, endtime: 40990822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,5356522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990814, endtime: 40990822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,5356602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990816, endtime: 40990822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,5356666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990819, endtime: 40990822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,5356738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990820, endtime: 40990822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,5356799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990822, endtime: 40990822, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,5658588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990825, endtime: 40990825, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,5725089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990826, endtime: 40990826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,5782673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990826, endtime: 40990826, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,5960609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990828, endtime: 40990828, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,6097672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990830, endtime: 40990830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,6269712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990831, endtime: 40990831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,6464643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,6464746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,6468553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40990833, endtime: 40990833, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,7778767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990000, endtime: 40990846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,7778931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990001, endtime: 40990846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,7779019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990005, endtime: 40990846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,7779089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990006, endtime: 40990846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,7789157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990008, endtime: 40990846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,7789237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990009, endtime: 40990846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,7789315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990013, endtime: 40990846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,7789379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990017, endtime: 40990846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,7789453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990019, endtime: 40990846, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,7789769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990020, endtime: 40990847, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,7789844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990022, endtime: 40990847, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,7789902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990023, endtime: 40990847, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,7789974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990025, endtime: 40990847, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:55,9974436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55200 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:56,0127255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55199 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:56,0165046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55250 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,6420583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990383, endtime: 40991033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,6420741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990384, endtime: 40991033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,6420827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990388, endtime: 40991033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,6420891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990389, endtime: 40991033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,6420960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990392, endtime: 40991033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,6421015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990394, endtime: 40991033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,6421184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990395, endtime: 40991033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,6421254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990397, endtime: 40991033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,6421328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990399, endtime: 40991033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,6421971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990401, endtime: 40991033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,6422052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990402, endtime: 40991033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,6422110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990405, endtime: 40991033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,7820666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55263 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,8123142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55265 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:57,8123245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55264 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:59,5584614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55263 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:59,6875795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55264 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:00:59,6875875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55265 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2543960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990406, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2544131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991033, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2544214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991037, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2544278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991039, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2544353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991042, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2544411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991044, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2544478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991047, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2544533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991050, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2544600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991052, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2544655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991052, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2544965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991053, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2545126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991053, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2545209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991054, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:01,2551110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991394, endtime: 40991394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,6474936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991395, endtime: 40991533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,6475122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991398, endtime: 40991533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,6475196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991401, endtime: 40991533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,6475274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991402, endtime: 40991533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,6475332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991405, endtime: 40991533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,6475399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991408, endtime: 40991533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,6475454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991410, endtime: 40991533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,6475521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991412, endtime: 40991533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,6475573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991414, endtime: 40991533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,6476360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991416, endtime: 40991533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,6476432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991417, endtime: 40991533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,6476499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991420, endtime: 40991533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,6477266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991425, endtime: 40991533, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,7340539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990517, endtime: 40991542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,7340756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990523, endtime: 40991542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,7340841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990524, endtime: 40991542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,7340922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990525, endtime: 40991542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,7340986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990526, endtime: 40991542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,7341058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990527, endtime: 40991542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,7341116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990528, endtime: 40991542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,7341188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990528, endtime: 40991542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,7341246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990531, endtime: 40991542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,7341512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990533, endtime: 40991542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,7341576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990534, endtime: 40991542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,7341645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990537, endtime: 40991542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,7341706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990539, endtime: 40991542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,8050446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,8054527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991549, endtime: 40991549, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,8280954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55268 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,8288747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991551, endtime: 40991551, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,8440477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991553, endtime: 40991553, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,8599230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991555, endtime: 40991555, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,8764566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991556, endtime: 40991556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,9094509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991560, endtime: 40991560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,9235464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991561, endtime: 40991561, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,9547931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991564, endtime: 40991564, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:02,9873336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991567, endtime: 40991567, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,0096006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991570, endtime: 40991570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,0320851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991572, endtime: 40991572, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,0485694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991573, endtime: 40991573, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,0779168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55270 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,0797348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991576, endtime: 40991577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,0998499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991578, endtime: 40991579, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,1257272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55269 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,1263883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991581, endtime: 40991581, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,1594890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991584, endtime: 40991585, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,1746670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991586, endtime: 40991586, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,2053493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991589, endtime: 40991589, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,2206982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991591, endtime: 40991591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,2766945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991596, endtime: 40991596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,2831779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991597, endtime: 40991597, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,3038712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991599, endtime: 40991599, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,3296181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991601, endtime: 40991602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,3348877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991602, endtime: 40991602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,3589821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,3602934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991605, endtime: 40991605, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,3757160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991606, endtime: 40991606, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,3957743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991608, endtime: 40991608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,4238914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991611, endtime: 40991611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,4403158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991612, endtime: 40991613, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,4709524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991615, endtime: 40991616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,4884690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991617, endtime: 40991617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,5027482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991619, endtime: 40991619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,5155099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,5158235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991620, endtime: 40991620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,5163253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991620, endtime: 40991620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,5320673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991622, endtime: 40991622, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,5474104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991623, endtime: 40991623, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,5631993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991625, endtime: 40991625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,5791270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991626, endtime: 40991627, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,5947468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991628, endtime: 40991628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,6101861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991630, endtime: 40991630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,6259550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991631, endtime: 40991631, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,6413959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991633, endtime: 40991633, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,6571396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991634, endtime: 40991634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,6877097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991637, endtime: 40991637, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,7127744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991639, endtime: 40991640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,7194988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991641, endtime: 40991641, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,7361831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991642, endtime: 40991642, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,7529555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991644, endtime: 40991644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,7663191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991645, endtime: 40991645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,7840041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991647, endtime: 40991647, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,7976112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991648, endtime: 40991648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,8138807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991650, endtime: 40991650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,8288825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991651, endtime: 40991651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,8447323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991653, endtime: 40991653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,8602430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991655, endtime: 40991655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,8758942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991656, endtime: 40991656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,9067078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991659, endtime: 40991659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,9234065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991661, endtime: 40991661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:03,9382157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991662, endtime: 40991662, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,4686326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991664, endtime: 40991715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,4686509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991666, endtime: 40991715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,4686584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991669, endtime: 40991715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,4686658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991670, endtime: 40991715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,4686717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991672, endtime: 40991715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,4686783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991674, endtime: 40991715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,4686838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991675, endtime: 40991715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,4686902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991678, endtime: 40991715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,4686958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991680, endtime: 40991715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,4687251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991683, endtime: 40991715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,4687309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991684, endtime: 40991715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,4687373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991686, endtime: 40991715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,4687429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991688, endtime: 40991715, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,7029176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55268 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,8434767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55270 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:04,9225197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55269 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:05,8354631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:05,8354745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:05,8358468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40991852, endtime: 40991852, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4731619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991622, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4731791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991623, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4731871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991625, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4731946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991627, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4732010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991628, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4732084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991630, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4732301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991533, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4732373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991534, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4732434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991536, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4733132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991539, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4733209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991541, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4733279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991544, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4733337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991547, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4733409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991548, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4733470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991551, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4733542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991553, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4733603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991555, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4733675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991556, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:06,4734500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991560, endtime: 40991916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:07,8596274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55275 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:07,9689739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55276 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:08,1572643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55277 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,4378791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991916, endtime: 40992212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,4378963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991917, endtime: 40992212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,4379035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991919, endtime: 40992212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,4379110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991920, endtime: 40992212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,4379168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991922, endtime: 40992212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,4379231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991923, endtime: 40992212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,4379287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991925, endtime: 40992212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,4379353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991926, endtime: 40992212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,4379406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991928, endtime: 40992212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,4379719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991930, endtime: 40992212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,4379777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991931, endtime: 40992212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,4379844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991933, endtime: 40992212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,4379899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991934, endtime: 40992212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,6877435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55275 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,7502415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55276 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,8056893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991631, endtime: 40992249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,8057109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991633, endtime: 40992249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,8057189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991634, endtime: 40992249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,8057272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991637, endtime: 40992249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,8057452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991639, endtime: 40992249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,8057605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991641, endtime: 40992249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,8057707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991642, endtime: 40992249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,8057821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991916, endtime: 40992249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,8057890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991917, endtime: 40992249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,8058253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991919, endtime: 40992249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,8058320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991920, endtime: 40992249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,8058392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991922, endtime: 40992249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,8058450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991923, endtime: 40992249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:09,9844996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55277 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,4796132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55276 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,4803615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55276 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992317, endtime: 40992317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,5015419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55276 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992319, endtime: 40992319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,5176250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55276 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992320, endtime: 40992320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,5582599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55276 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992323, endtime: 40992324, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,5833898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55276 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,7391947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992249, endtime: 40992343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,7392122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992252, endtime: 40992343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,7392194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992256, endtime: 40992343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,7392269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992258, endtime: 40992343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,7392327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992261, endtime: 40992343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,7392393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992262, endtime: 40992343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,7392449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992264, endtime: 40992343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,7392515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992267, endtime: 40992343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,7392568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992269, endtime: 40992343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,7393180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992270, endtime: 40992343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,7393249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992272, endtime: 40992343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,7393316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992274, endtime: 40992343, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,8691631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992212, endtime: 40992356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,8691830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992214, endtime: 40992356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,8691911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992216, endtime: 40992356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,8691991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992217, endtime: 40992356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,8692052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992219, endtime: 40992356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,8692127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992220, endtime: 40992356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,8692188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992222, endtime: 40992356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,8692260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992223, endtime: 40992356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,8692318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992225, endtime: 40992356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,8692634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992226, endtime: 40992356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,8692692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992228, endtime: 40992356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,8692759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992230, endtime: 40992356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:10,8692814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992231, endtime: 40992356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:11,1658970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990278, endtime: 40992385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:11,1659187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990281, endtime: 40992385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:11,1659267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990283, endtime: 40992385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:11,1659345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990284, endtime: 40992385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:11,1659403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990286, endtime: 40992385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:11,1659472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990287, endtime: 40992385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:11,1659527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990289, endtime: 40992385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:11,1659597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990292, endtime: 40992385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:11,1659652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990294, endtime: 40992385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:11,1659932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990295, endtime: 40992385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:11,1659996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990297, endtime: 40992385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:11,1660062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990299, endtime: 40992385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:11,1660118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40990300, endtime: 40992385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:12,2026305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992356, endtime: 40992489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:12,2026474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992356, endtime: 40992489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:12,2026549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992358, endtime: 40992489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:12,2026627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992361, endtime: 40992489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:12,2026685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992362, endtime: 40992489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:12,2026754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992364, endtime: 40992489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:12,2026809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992367, endtime: 40992489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:12,2026879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992369, endtime: 40992489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:12,2026937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992370, endtime: 40992489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:12,2027250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992373, endtime: 40992489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:12,2047650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992377, endtime: 40992489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:12,2047785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992380, endtime: 40992489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:12,2047857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992381, endtime: 40992489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,5937605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55281 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,9547582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991716, endtime: 40992664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,9547748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991717, endtime: 40992664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,9547834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991719, endtime: 40992664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,9547898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991722, endtime: 40992664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,9547964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991723, endtime: 40992664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,9548017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991727, endtime: 40992664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,9548083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991729, endtime: 40992664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,9548136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991730, endtime: 40992664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,9548202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991731, endtime: 40992664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,9549094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991733, endtime: 40992664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,9549175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991734, endtime: 40992664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,9549227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991737, endtime: 40992664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:13,9550039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40991737, endtime: 40992664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,0944557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55282 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,3433913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55283 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5324009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992489, endtime: 40992722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5324217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992492, endtime: 40992722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5324300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992496, endtime: 40992722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5324383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992497, endtime: 40992722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5324444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992498, endtime: 40992722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5324516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992502, endtime: 40992722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5324574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992505, endtime: 40992722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5324646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992506, endtime: 40992722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5324707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992510, endtime: 40992722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5325015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992513, endtime: 40992722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5325076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992514, endtime: 40992722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5325148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992517, endtime: 40992722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5325206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992519, endtime: 40992722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:14,5658654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55222 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:16,0949452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:16,0949555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:16,0959332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40992878, endtime: 40992878, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:19,5938722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55281 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:20,1096799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55282 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:20,3438313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55283 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:23,7033595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55286 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,0013568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,0859367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,0862620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993677, endtime: 40993677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,0946399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993678, endtime: 40993678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,1103110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993680, endtime: 40993680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,1270103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993681, endtime: 40993681, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,1429139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993683, endtime: 40993683, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,1599251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993684, endtime: 40993685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,1886262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993687, endtime: 40993687, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,2043272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55288 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,2090405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993689, endtime: 40993690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,2362992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993692, endtime: 40993692, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,2512442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993694, endtime: 40993694, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,2684139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993695, endtime: 40993695, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,2738245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,2741498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993696, endtime: 40993696, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,2820894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993697, endtime: 40993697, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,2838492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993697, endtime: 40993697, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,2975128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993698, endtime: 40993698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,2994965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993698, endtime: 40993699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,3132737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993700, endtime: 40993700, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,3137053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993700, endtime: 40993700, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,3187439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993700, endtime: 40993700, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,3197247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993701, endtime: 40993701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,3459899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993703, endtime: 40993703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,3488942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993703, endtime: 40993703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,3602142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993705, endtime: 40993705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,3607179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993705, endtime: 40993705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,3770905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993706, endtime: 40993706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,3776369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993706, endtime: 40993706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,3913775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993708, endtime: 40993708, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,3930669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993708, endtime: 40993708, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,4083790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993709, endtime: 40993709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,4088932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993709, endtime: 40993709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,4241391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993711, endtime: 40993711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,4257427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993711, endtime: 40993711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,4451391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55260 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,4554932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993714, endtime: 40993714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,4556240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993714, endtime: 40993714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,4844971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55289 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,4869371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993717, endtime: 40993717, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,4871036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993717, endtime: 40993717, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,5022780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993719, endtime: 40993719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,5024199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993719, endtime: 40993719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,5178308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993720, endtime: 40993720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,5179932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993720, endtime: 40993720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,5321142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993722, endtime: 40993722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,5322624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993722, endtime: 40993722, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,5503176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993723, endtime: 40993724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,5504916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993723, endtime: 40993724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,5875190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993726, endtime: 40993727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,5943617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993728, endtime: 40993728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,6115090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993730, endtime: 40993730, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,6271239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993731, endtime: 40993731, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,6411069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993726, endtime: 40993733, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,6411238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993728, endtime: 40993733, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,6411310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993730, endtime: 40993733, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,6411382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993731, endtime: 40993733, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,6422124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993733, endtime: 40993733, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,6423268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993733, endtime: 40993733, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,6596940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993734, endtime: 40993735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,6598647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993734, endtime: 40993735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,6885273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993737, endtime: 40993737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,6886774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993737, endtime: 40993737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,7210121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993741, endtime: 40993741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,7210340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993741, endtime: 40993741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,7370963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993742, endtime: 40993742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,7372254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993742, endtime: 40993742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,7537997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993744, endtime: 40993744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,7539388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993744, endtime: 40993744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,7836273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993747, endtime: 40993747, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,7837392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993747, endtime: 40993747, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,8004704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993748, endtime: 40993749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,8005842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993748, endtime: 40993749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,8277596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993750, endtime: 40993751, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,8439241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993753, endtime: 40993753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,8621478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993755, endtime: 40993755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,8784337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993756, endtime: 40993756, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,9068197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,9079842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993759, endtime: 40993759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,9119993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993759, endtime: 40993760, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,9226000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993761, endtime: 40993761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,9230494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993761, endtime: 40993761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,9387213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993762, endtime: 40993762, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,9391951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993762, endtime: 40993763, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,9539173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993764, endtime: 40993764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,9543423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993764, endtime: 40993764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,9697799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993766, endtime: 40993766, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:24,9709540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993766, endtime: 40993766, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,0010698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993769, endtime: 40993769, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,0053982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993769, endtime: 40993769, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,0166796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993770, endtime: 40993770, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,0320964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993772, endtime: 40993772, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,0478271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993773, endtime: 40993773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,0635783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993775, endtime: 40993775, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,0789754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993776, endtime: 40993777, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,0944327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993778, endtime: 40993778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,1270203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993781, endtime: 40993781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,1524925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993783, endtime: 40993784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,1943634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993787, endtime: 40993788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,2067581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993789, endtime: 40993789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,2364394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993792, endtime: 40993792, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,2516714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993794, endtime: 40993794, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,2822251</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993797, endtime: 40993797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,2996409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993798, endtime: 40993799, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,3304573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993801, endtime: 40993802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,3622830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993805, endtime: 40993805, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,3767688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993806, endtime: 40993806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,4019247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993808, endtime: 40993809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,4257130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993811, endtime: 40993811, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:25,6411659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55289 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:26,2664202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 10032</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:26,2700230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:26,2700336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:26,2707841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40993896, endtime: 40993896, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:27,4811455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992664, endtime: 40994017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:27,4811627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992665, endtime: 40994017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:27,4811702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992667, endtime: 40994017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:27,4811780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992669, endtime: 40994017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:27,4811838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992670, endtime: 40994017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:27,4811910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992672, endtime: 40994017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:27,4811965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992673, endtime: 40994017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:27,4812037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992675, endtime: 40994017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:27,4812093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992677, endtime: 40994017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:27,4812353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992678, endtime: 40994017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:27,4812414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992680, endtime: 40994017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:27,4812483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992681, endtime: 40994017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:27,4812544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992684, endtime: 40994017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:28,8599377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55293 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,2010097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993750, endtime: 40994189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,2010261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993753, endtime: 40994189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,2010333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993755, endtime: 40994189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,2010408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993756, endtime: 40994189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,2010463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993759, endtime: 40994189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,2010530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993761, endtime: 40994189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,2010585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993762, endtime: 40994189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,2010649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993764, endtime: 40994189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,2010704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993766, endtime: 40994189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,2011003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993769, endtime: 40994189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,2011064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993770, endtime: 40994189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,2011128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993772, endtime: 40994189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,2011184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993773, endtime: 40994189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:29,7039765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55286 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,1457141</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993770, endtime: 40994283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,1457351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993772, endtime: 40994283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,1457429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993773, endtime: 40994283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,1457512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993775, endtime: 40994283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,1457573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993777, endtime: 40994283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,1457645</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993778, endtime: 40994283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,1457700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993781, endtime: 40994283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,1457770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993784, endtime: 40994283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,1457828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993787, endtime: 40994283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,1458146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993789, endtime: 40994283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,1458207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993792, endtime: 40994283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,1458462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993794, endtime: 40994283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,1458540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993797, endtime: 40994283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,2191375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55288 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:30,6559516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55293 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:32,3216959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55267 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:32,8910785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55308 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4387053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55322 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4505206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994189, endtime: 40994614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4505381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994190, endtime: 40994614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4505455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994192, endtime: 40994614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4505530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994194, endtime: 40994614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4505586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994195, endtime: 40994614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4505652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994197, endtime: 40994614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4508522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994198, endtime: 40994614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4509475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994200, endtime: 40994614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4509578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994200, endtime: 40994614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4509656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994204, endtime: 40994614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4509717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994205, endtime: 40994614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4509786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994206, endtime: 40994614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:33,4509841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994209, endtime: 40994614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,0928953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994283, endtime: 40994678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,0929144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994284, endtime: 40994678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,0929219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994287, endtime: 40994678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,0929294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994289, endtime: 40994678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,0929349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994291, endtime: 40994678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,0929415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994293, endtime: 40994678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,0929471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994294, endtime: 40994678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,0929537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994298, endtime: 40994678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,0929590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994298, endtime: 40994678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,0929898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994300, endtime: 40994678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,0929956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994304, endtime: 40994678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,0930019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994305, endtime: 40994678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,0930274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994308, endtime: 40994678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,3865320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993812, endtime: 40994707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,3865492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993816, endtime: 40994707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,3865583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993819, endtime: 40994707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,3865650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993820, endtime: 40994707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,3865722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993822, endtime: 40994707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,3865780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993823, endtime: 40994707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,3865849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993825, endtime: 40994707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,3865908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993827, endtime: 40994707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,3865980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993828, endtime: 40994707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,3866240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993830, endtime: 40994707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,3866315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993834, endtime: 40994707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,3866373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993836, endtime: 40994707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:34,3866442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40993838, endtime: 40994707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,1001652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55243 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,4050579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994614, endtime: 40994809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,4050770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994616, endtime: 40994809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,4050845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994617, endtime: 40994809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,4050923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994619, endtime: 40994809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,4050981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994620, endtime: 40994809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,4051045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994623, endtime: 40994809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,4051103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994625, endtime: 40994809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,4051169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994626, endtime: 40994809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,4051228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994628, endtime: 40994809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,4051549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994630, endtime: 40994809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,4051607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994632, endtime: 40994809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,4051674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994634, endtime: 40994809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:35,4051729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994638, endtime: 40994809, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,4264890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,4265001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,4279932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40994911, endtime: 40994911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,5139321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994678, endtime: 40994920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,5139504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994680, endtime: 40994920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,5139576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994680, endtime: 40994920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,5139651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994683, endtime: 40994920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,5139706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994684, endtime: 40994920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,5139772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994688, endtime: 40994920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,5139828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994691, endtime: 40994920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,5140656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994694, endtime: 40994920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,5142017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994695, endtime: 40994920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,5142125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994699, endtime: 40994920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,5142191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994702, endtime: 40994920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,5142266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994705, endtime: 40994920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:36,5142327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994706, endtime: 40994920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,3601859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994809, endtime: 40995105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,3602073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994810, endtime: 40995105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,3602158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994810, endtime: 40995105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,3602239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994811, endtime: 40995105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,3602300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994812, endtime: 40995105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,3602538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994812, endtime: 40995105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,3602607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994813, endtime: 40995105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,3602682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994813, endtime: 40995105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,3602746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994814, endtime: 40995105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,3603170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994814, endtime: 40995105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,3603256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994815, endtime: 40995105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,3603350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994816, endtime: 40995105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,3603425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994816, endtime: 40995105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:38,9060196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55308 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:39,4536087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55322 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,1877679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55324 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,8455031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994920, endtime: 40995353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,8455247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994921, endtime: 40995353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,8455330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994921, endtime: 40995353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,8455410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994922, endtime: 40995353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,8455471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994922, endtime: 40995353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,8455543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994923, endtime: 40995353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,8455604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994924, endtime: 40995353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,8455673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994924, endtime: 40995353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,8455732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994925, endtime: 40995353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,8456039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994925, endtime: 40995353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,8456103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994927, endtime: 40995353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,8456172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994927, endtime: 40995353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:40,8456380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994928, endtime: 40995353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0467402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0608698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995105, endtime: 40995575, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0608881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995106, endtime: 40995575, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0608959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995109, endtime: 40995575, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0609036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995113, endtime: 40995575, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0609100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995115, endtime: 40995575, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0609172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995117, endtime: 40995575, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0609230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995119, endtime: 40995575, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0609302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995120, endtime: 40995575, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0609363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995123, endtime: 40995575, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0609673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995125, endtime: 40995575, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0609737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995129, endtime: 40995575, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0609806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995130, endtime: 40995575, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,0609867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995133, endtime: 40995575, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,5319479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55326 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,8215546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995353, endtime: 40995651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,8215737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995356, endtime: 40995651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,8215809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995362, endtime: 40995651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,8215881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995364, endtime: 40995651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,8215942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995366, endtime: 40995651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,8216009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995368, endtime: 40995651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,8216067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995369, endtime: 40995651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,8216136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995370, endtime: 40995651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,8216192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995372, endtime: 40995651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,8216682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995374, endtime: 40995651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,8216757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995375, endtime: 40995651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,8216823</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995376, endtime: 40995651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:43,8216884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995378, endtime: 40995651, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:44,7492388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:44,7495610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995744, endtime: 40995744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:44,7659708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995745, endtime: 40995745, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:44,7852345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995747, endtime: 40995747, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:44,8255434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995751, endtime: 40995751, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:44,8464874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995753, endtime: 40995753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:44,8619087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995755, endtime: 40995755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:44,8935886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995758, endtime: 40995758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:44,9075431</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995759, endtime: 40995759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:44,9397201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995763, endtime: 40995763, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:44,9547875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995764, endtime: 40995764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:44,9868931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995767, endtime: 40995767, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,0071916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995769, endtime: 40995769, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,0166126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995770, endtime: 40995770, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,0499956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995773, endtime: 40995774, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,0652237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995775, endtime: 40995775, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,0805339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995776, endtime: 40995777, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,1120930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995780, endtime: 40995780, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,1262451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995781, endtime: 40995781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,1579403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995784, endtime: 40995784, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,1902517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995787, endtime: 40995788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,2066844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995789, endtime: 40995789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,2401799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995792, endtime: 40995793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,2513766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995794, endtime: 40995794, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,2772340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995795, endtime: 40995796, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,3012317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995798, endtime: 40995799, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,3363996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995801, endtime: 40995802, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,3421180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995803, endtime: 40995803, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,8605137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995805, endtime: 40995855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,8605358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995806, endtime: 40995855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,8605444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995809, endtime: 40995855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,8605633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995811, endtime: 40995855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,8605752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995814, endtime: 40995855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,8605835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995817, endtime: 40995855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,8605902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995819, endtime: 40995855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,8605979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995820, endtime: 40995855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,8606046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995822, endtime: 40995855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,8606699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995824, endtime: 40995855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,8606780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995825, endtime: 40995855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:45,8606855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995827, endtime: 40995855, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:46,1877845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55324 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:46,3518773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:46,3518887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:46,3521909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40995904, endtime: 40995904, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,0412459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995651, endtime: 40995973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,0412639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995651, endtime: 40995973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,0412711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995653, endtime: 40995973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,0412786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995656, endtime: 40995973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,0412844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995659, endtime: 40995973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,0412911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995661, endtime: 40995973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,0412966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995662, endtime: 40995973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,0413030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995664, endtime: 40995973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,0413085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995666, endtime: 40995973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,0413382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995667, endtime: 40995973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,0413443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995669, endtime: 40995973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,0413507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995669, endtime: 40995973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,0413565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995672, endtime: 40995973, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,2196393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995973, endtime: 40995991, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,4074503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,4217065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996009, endtime: 40996011, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,4388565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996012, endtime: 40996012, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,4554248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996014, endtime: 40996014, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,4748156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996016, endtime: 40996016, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,5115281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996020, endtime: 40996020, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,5351263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996022, endtime: 40996022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,5524343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996024, endtime: 40996024, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,5899094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996028, endtime: 40996028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,6114467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996030, endtime: 40996030, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,6273043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996031, endtime: 40996031, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,6431075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996033, endtime: 40996033, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,6729096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996036, endtime: 40996036, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,6888257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996037, endtime: 40996037, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,7075111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996039, endtime: 40996039, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,7205331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996041, endtime: 40996041, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,7376385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996042, endtime: 40996042, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,7781311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996045, endtime: 40996046, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,7995361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996048, endtime: 40996049, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,8301265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996051, endtime: 40996052, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,8446558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996053, endtime: 40996053, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,8628357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996055, endtime: 40996055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,8768844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996056, endtime: 40996056, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,9088514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996059, endtime: 40996059, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,9226515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996061, endtime: 40996061, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,9386230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996062, endtime: 40996062, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,9536968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996064, endtime: 40996064, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,9699938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996065, endtime: 40996066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:47,9866831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996067, endtime: 40996067, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,0022492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996069, endtime: 40996069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,0344744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996072, endtime: 40996072, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,0477944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996073, endtime: 40996073, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,0804419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996077, endtime: 40996077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,0966688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996078, endtime: 40996078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,1280382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996081, endtime: 40996081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,1597902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996084, endtime: 40996085, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,1738037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996086, endtime: 40996086, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,1930505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996087, endtime: 40996088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,2036077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996089, endtime: 40996089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,2208882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996090, endtime: 40996091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,9202589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995575, endtime: 40996161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,9202919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995576, endtime: 40996161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,9203032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995578, endtime: 40996161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,9203101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995582, endtime: 40996161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,9203179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995584, endtime: 40996161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,9203243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995588, endtime: 40996161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,9203315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995591, endtime: 40996161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,9203376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995592, endtime: 40996161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,9203450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995595, endtime: 40996161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,9203755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995597, endtime: 40996161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,9203830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995598, endtime: 40996161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,9203885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995600, endtime: 40996161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:48,9203957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995603, endtime: 40996161, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,0624662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,1258444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,1266327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996181, endtime: 40996181, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,1422182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996183, endtime: 40996183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,1640474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996184, endtime: 40996185, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,1893928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996187, endtime: 40996188, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,2053429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996189, endtime: 40996189, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,2472776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996192, endtime: 40996193, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,2676603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996195, endtime: 40996195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,2831934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996197, endtime: 40996197, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,3262391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996201, endtime: 40996201, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,3429220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996203, endtime: 40996203, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,3593783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 9864, User Time: 0.0156250, Kernel Time: 0.0468750</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,4890184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995978, endtime: 40996218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,4890480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995980, endtime: 40996218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,4890663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995981, endtime: 40996218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,4890799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995983, endtime: 40996218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,4890948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995985, endtime: 40996218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,4891076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995987, endtime: 40996218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,4891198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995989, endtime: 40996218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,4891295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995991, endtime: 40996218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,4891406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995992, endtime: 40996218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,4892597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995995, endtime: 40996218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,4892733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995995, endtime: 40996218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,4892827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995999, endtime: 40996218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,4893334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996000, endtime: 40996218, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,5634038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55326 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,6327988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55326 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,6377393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 13024, User Time: 0.0156250, Kernel Time: 0.0781250</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,7361920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55326 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,8993719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996092, endtime: 40996259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:49,9778278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 9328, User Time: 0.0000000, Kernel Time: 0.0781250</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,0627754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55325 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,3236303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996094, endtime: 40996301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,3236458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996095, endtime: 40996301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,3236541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996098, endtime: 40996301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,3236608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996100, endtime: 40996301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,3236677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996104, endtime: 40996301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,3236735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996105, endtime: 40996301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,3236805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996106, endtime: 40996301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,3236860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996108, endtime: 40996301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,3236929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996109, endtime: 40996301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,3237215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996111, endtime: 40996301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,3237287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996112, endtime: 40996301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,3237345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996114, endtime: 40996301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,3237417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996259, endtime: 40996301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:50,8983027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55328 -&gt; ns3077914.ip-164-132-207.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:51,5553775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996161, endtime: 40996424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:51,5553949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996162, endtime: 40996424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:51,5554024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996164, endtime: 40996424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:51,5554101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996166, endtime: 40996424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:51,5554162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996167, endtime: 40996424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:51,5554232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996169, endtime: 40996424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:51,5554293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996172, endtime: 40996424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:51,5554359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996175, endtime: 40996424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:51,5554417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996177, endtime: 40996424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:51,5554725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996178, endtime: 40996424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:51,5554786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996180, endtime: 40996424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:51,5554855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996181, endtime: 40996424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:51,5554913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996183, endtime: 40996424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,1981832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995828, endtime: 40996488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,1982007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995855, endtime: 40996488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,1982087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995856, endtime: 40996488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,1982167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995858, endtime: 40996488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,1982231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995859, endtime: 40996488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,1982303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995861, endtime: 40996488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,1982361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995863, endtime: 40996488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,1982433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995866, endtime: 40996488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,1982492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995867, endtime: 40996488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,1982760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995869, endtime: 40996488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,1982824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995870, endtime: 40996488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,1984162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995872, endtime: 40996488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,1984259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40995875, endtime: 40996488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,3777851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 5892, User Time: 0.0312500, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5290929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996218, endtime: 40996522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5291100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996220, endtime: 40996522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5291175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996222, endtime: 40996522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5291253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996225, endtime: 40996522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5291314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996229, endtime: 40996522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5291383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996232, endtime: 40996522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5291441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996236, endtime: 40996522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5291511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996238, endtime: 40996522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5291569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996240, endtime: 40996522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5292336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996241, endtime: 40996522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5292414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996244, endtime: 40996522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5292483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996246, endtime: 40996522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5296780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996248, endtime: 40996522, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,5478606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 8696, User Time: 0.0000000, Kernel Time: 0.0312500</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,6848732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996424, endtime: 40996537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,6849025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996425, endtime: 40996537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,6849131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996426, endtime: 40996537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,6849217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996429, endtime: 40996537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,6849286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996433, endtime: 40996537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,6849366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996434, endtime: 40996537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,6849430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996436, endtime: 40996537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,6849510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996439, endtime: 40996537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,6849580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996441, endtime: 40996537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,6849929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996442, endtime: 40996537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,6849990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996444, endtime: 40996537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,6850062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996445, endtime: 40996537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,6850123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996447, endtime: 40996537, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,7040939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 336, User Time: 0.0000000, Kernel Time: 0.0312500</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:52,7722988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996537, endtime: 40996546, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2229651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992276, endtime: 40996591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2229814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992343, endtime: 40996591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2229892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992345, endtime: 40996591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2229969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992347, endtime: 40996591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2230030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992351, endtime: 40996591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2230099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992352, endtime: 40996591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2230158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992353, endtime: 40996591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2231047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992356, endtime: 40996591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2231792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992358, endtime: 40996591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2231914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992361, endtime: 40996591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2231983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992362, endtime: 40996591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2232058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992364, endtime: 40996591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2232119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40992367, endtime: 40996591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2808695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996488, endtime: 40996597, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2808875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996491, endtime: 40996597, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2808966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996495, endtime: 40996597, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2809052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996497, endtime: 40996597, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2809122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996500, endtime: 40996597, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2809196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996501, endtime: 40996597, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2809260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996504, endtime: 40996597, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,2809479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40996522, endtime: 40996597, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:53,8513985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55287 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,0340511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55272 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,1372472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55290 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,5833463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994707, endtime: 40996727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,5833629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994709, endtime: 40996727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,5833704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994711, endtime: 40996727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,5833781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994714, endtime: 40996727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,5833839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994716, endtime: 40996727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,5833909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994717, endtime: 40996727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,5833967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994719, endtime: 40996727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,5834033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994724, endtime: 40996727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,5834089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994725, endtime: 40996727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,5834371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994726, endtime: 40996727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,5834432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994728, endtime: 40996727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,5834499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994730, endtime: 40996727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,5834557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 40994733, endtime: 40996727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:54,8316148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55327 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:56,1706910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55291 -&gt; ns3054486.ip-213-32-6.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:56,5135071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:56,5135173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:01:56,5137598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40996920, endtime: 40996920, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:06,6586529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:06,6586642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:06,6590202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40997934, endtime: 40997935, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:16,9505832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:16,9505946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:16,9509819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40998964, endtime: 40998964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:26,9686146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:26,9686268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:26,9689991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 40999965, endtime: 40999966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:37,2649252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:37,2649379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:37,2652862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41000995, endtime: 41000995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:47,2490366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:47,2490499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:47,2494605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41001994, endtime: 41001994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:57,5319308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:57,5319416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:02:57,5333296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41003022, endtime: 41003022, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:07,6379415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:07,6379562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:07,6383441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41004032, endtime: 41004032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:17,8130728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:17,8130834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:17,8135502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41005050, endtime: 41005050, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:27,9141828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:27,9141941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:27,9145482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41006060, endtime: 41006060, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:38,1294711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:38,1294822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:38,1300349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41007082, endtime: 41007082, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:48,3771617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:48,3771728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:48,3777593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41008106, endtime: 41008106, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:58,5953705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:58,5953819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:03:58,5961327</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41009128, endtime: 41009128, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:08,5378437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:08,5378789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:08,5430210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41010122, endtime: 41010123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:18,8540541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:18,8540647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:18,8547986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41011154, endtime: 41011154, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:29,0021062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:29,0021179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:29,0034619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41012169, endtime: 41012169, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:39,1263445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:39,1263545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:39,1445230</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41013183, endtime: 41013183, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:49,2751896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:49,2752001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:49,2759717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41014196, endtime: 41014196, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:50,3794313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:50,3795098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKLM</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:50,3795297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\KnownClasses</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,1918337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 9340</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,4553491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,4699661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,4699924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,5330110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 517, startime: 41014422, endtime: 41014422, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,5338103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 517, startime: 41014422, endtime: 41014422, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,5342744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 517, startime: 41014422, endtime: 41014422, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6055537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6055700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6062663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6062726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6062851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6062907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6062981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6062998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1192, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6064358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 512, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6064389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 512, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6067531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6067564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6118201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6118293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6178231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 158, startime: 41014430, endtime: 41014430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6184811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 158, startime: 41014430, endtime: 41014430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6209004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6209106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 1306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6214462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6214512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 626, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6252912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 158, startime: 41014431, endtime: 41014431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6898383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,6898499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,7034129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 291, startime: 41014438, endtime: 41014439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,7178572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,7178694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,7192921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 292, startime: 41014440, endtime: 41014441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,7440499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,7440615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 51, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,7941372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,7941493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 539, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,7948630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:51,7948727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:59,4254684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:59,4254839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:04:59,4262112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41015211, endtime: 41015211, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:09,5721596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:09,5721743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:09,5729819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41016226, endtime: 41016226, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:19,7943375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:19,7943580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:19,7955180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41017248, endtime: 41017248, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:21,3603361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 2896</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:21,4229873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 9340, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:29,8180795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:29,8180925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:29,8187181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41018250, endtime: 41018250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:31,7721951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:31,7722104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:31,7994721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:31,7994838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:31,8070599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55695 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:31,8074719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55696 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:39,9835845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:39,9835967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:39,9844076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41019267, endtime: 41019267, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:50,2659262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:50,2659378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:50,2716147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41020295, endtime: 41020296, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:51,5493662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:51,5493809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 31, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:51,5500242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55694 -&gt; fr.cloudtree.ru:https</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,4288399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 58, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,4288512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 58, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,4296494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 7656</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,4299533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 5856</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,4305692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 11044</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5213605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55798 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5213996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55797 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5214226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55796 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5221213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55798 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020621, endtime: 41020621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5223349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55797 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020621, endtime: 41020621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5226549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55796 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020621, endtime: 41020621, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5316911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55796 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020622, endtime: 41020622, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5317149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55797 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020622, endtime: 41020622, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5320352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55798 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020622, endtime: 41020622, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5484353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55798 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020623, endtime: 41020623, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5484607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55797 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020623, endtime: 41020623, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5488223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55796 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020623, endtime: 41020623, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5635110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55796 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020625, endtime: 41020625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5635390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55797 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020625, endtime: 41020625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5635670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55798 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020625, endtime: 41020625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5798703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55798 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020627, endtime: 41020627, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5798941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55797 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020627, endtime: 41020627, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5802992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55796 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020627, endtime: 41020627, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5944266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55796 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020628, endtime: 41020628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5944584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55797 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020628, endtime: 41020628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,5948895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55798 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020628, endtime: 41020628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6108371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6108601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6108909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6109161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6109305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6109413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6109621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6109699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6109779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6109937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6110020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6110289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6110344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6110477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6110557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6110718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6110857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6110934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6111012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6111145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6111217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6111289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6111563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6111624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6111696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6111771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6113480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55798 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6118490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6118620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6118819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6118988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6119085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6119174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6119332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6119404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6119481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6119598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6120085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6120302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6120351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6120479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6120556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6120717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6120858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6120936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6121559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6121726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6121817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6121892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6122014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6122075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6122144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6122188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6122731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55796 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6408825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6409049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6409326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6409559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6409656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6409747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6409922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6409997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6410072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6410213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6410277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6410501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6410554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6410673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6410748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6410897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6411033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6411108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6411183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6411313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6411382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6411462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6411590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6411648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6411709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6411753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6412562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55797 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6989299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6994122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6996261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020638, endtime: 41020639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,6998641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020639, endtime: 41020639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,7359166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020642, endtime: 41020642, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,7359385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020642, endtime: 41020642, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,7654297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,7659395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020645, endtime: 41020645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,7672957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020645, endtime: 41020645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,7673311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020645, endtime: 41020645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,7818957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020647, endtime: 41020647, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,7831045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020647, endtime: 41020647, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,7831355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020647, endtime: 41020647, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,8001579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020649, endtime: 41020649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,8015695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020649, endtime: 41020649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,8016046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020649, endtime: 41020649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,8300045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020652, endtime: 41020652, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,8341014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020652, endtime: 41020652, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,8341346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020652, endtime: 41020652, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,8610465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020655, endtime: 41020655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,8610725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020655, endtime: 41020655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,8614557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020655, endtime: 41020655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,8767240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020656, endtime: 41020656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,8767486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020656, endtime: 41020656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,8767603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020656, endtime: 41020656, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9102802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020660, endtime: 41020660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9103034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020660, endtime: 41020660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9106636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020660, endtime: 41020660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9227236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020661, endtime: 41020661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9227491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020661, endtime: 41020661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9230854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020661, endtime: 41020661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9381609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020662, endtime: 41020662, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9381825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020662, endtime: 41020662, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9381938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020662, endtime: 41020662, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9551034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020664, endtime: 41020664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9551350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020664, endtime: 41020664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9555353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020664, endtime: 41020664, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9859037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020667, endtime: 41020667, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9864916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020667, endtime: 41020667, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:53,9865146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020667, endtime: 41020667, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0029116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020669, endtime: 41020669, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0029446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020669, endtime: 41020669, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0032790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020669, endtime: 41020669, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0250897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020670, endtime: 41020671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0251157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020670, endtime: 41020671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0254742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020670, endtime: 41020671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0492035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020673, endtime: 41020674, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0492276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020673, endtime: 41020674, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0492396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020673, endtime: 41020674, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0548998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020674, endtime: 41020674, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0549203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020674, endtime: 41020674, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0549319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020674, endtime: 41020674, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0806234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020676, endtime: 41020677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0806547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020676, endtime: 41020677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,0806660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020676, endtime: 41020677, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,1155770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020680, endtime: 41020680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,1156000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020680, endtime: 41020680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,1156122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020680, endtime: 41020680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,1253233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020681, endtime: 41020681, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,1253485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020681, endtime: 41020681, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,1256995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020681, endtime: 41020681, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,1422082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020683, endtime: 41020683, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,1422329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020683, endtime: 41020683, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,1426049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020683, endtime: 41020683, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,1748246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020686, endtime: 41020686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,1748498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020686, endtime: 41020686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,1752117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020686, endtime: 41020686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,2141278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020689, endtime: 41020690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,2141522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020689, endtime: 41020690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,2144913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020689, endtime: 41020690, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,2359737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020692, endtime: 41020692, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,2360014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020692, endtime: 41020692, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,2363632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020692, endtime: 41020692, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,2674281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020695, endtime: 41020695, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,2693598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020695, endtime: 41020696, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,2693955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020695, endtime: 41020696, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,2996927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020698, endtime: 41020699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,2997151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020698, endtime: 41020699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,2997265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020698, endtime: 41020699, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,3142650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020700, endtime: 41020700, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,3146266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020700, endtime: 41020700, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,3146457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020700, endtime: 41020700, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,3201727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020701, endtime: 41020701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,3205193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020701, endtime: 41020701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,3465700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020703, endtime: 41020703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,3465913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020703, endtime: 41020703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:54,3803135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020706, endtime: 41020707, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,2284106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020709, endtime: 41020891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,2284269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020711, endtime: 41020891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,2284352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020712, endtime: 41020891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,2284436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020714, endtime: 41020891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,2284499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020716, endtime: 41020891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,2284577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020717, endtime: 41020891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,2284641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020720, endtime: 41020891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,2284715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020722, endtime: 41020891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,2284807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020723, endtime: 41020891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,2285120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020725, endtime: 41020891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,2285186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020727, endtime: 41020891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,2285258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020730, endtime: 41020891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,2285322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020731, endtime: 41020891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,3162609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020706, endtime: 41020900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,3162795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020709, endtime: 41020900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,3162875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020711, endtime: 41020900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,3162950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020712, endtime: 41020900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,3163011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020714, endtime: 41020900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,3163086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020716, endtime: 41020900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,3163144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020717, endtime: 41020900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,3163219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020720, endtime: 41020900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,3163282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020722, endtime: 41020900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,3163559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020723, endtime: 41020900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,3163620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020725, endtime: 41020900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,3163695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020727, endtime: 41020900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:56,3163773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020730, endtime: 41020900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:57,1863718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020891, endtime: 41020987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:57,1863903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020892, endtime: 41020987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:57,1863981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020894, endtime: 41020987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:57,1864061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020895, endtime: 41020987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:57,1864125</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020898, endtime: 41020987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:57,1864203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020900, endtime: 41020987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:57,1864266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020901, endtime: 41020987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:57,1864341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020903, endtime: 41020987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:57,1864405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020905, endtime: 41020987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:57,1865255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020906, endtime: 41020987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:57,1865336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020908, endtime: 41020987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:57,1865413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020909, endtime: 41020987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:57,1866835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020911, endtime: 41020987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,0555866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020900, endtime: 41021074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,0556038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020903, endtime: 41021074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,0556118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020905, endtime: 41021074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,0556196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020906, endtime: 41021074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,0556257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020908, endtime: 41021074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,0556335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020909, endtime: 41021074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,0556398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020911, endtime: 41021074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,0556473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020914, endtime: 41021074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,0556537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020916, endtime: 41021074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,0557329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020919, endtime: 41021074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,0557410</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020922, endtime: 41021074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,0557515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020925, endtime: 41021074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,0558188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020927, endtime: 41021074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,2532018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020987, endtime: 41021094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,2532273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020990, endtime: 41021094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,2532381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020992, endtime: 41021094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,2532512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020995, endtime: 41021094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,2532614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020997, endtime: 41021094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,2532742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41020998, endtime: 41021094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,2532841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021001, endtime: 41021094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,2532971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021005, endtime: 41021094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,2533060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021006, endtime: 41021094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,2533988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021009, endtime: 41021094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,2534066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021011, endtime: 41021094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,2534171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021012, endtime: 41021094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,2534786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021014, endtime: 41021094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,9865670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021074, endtime: 41021167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,9865853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021075, endtime: 41021167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,9865933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021076, endtime: 41021167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,9866016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021078, endtime: 41021167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,9866083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021081, endtime: 41021167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,9866157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021084, endtime: 41021167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,9866221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021086, endtime: 41021167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,9866296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021087, endtime: 41021167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,9866360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021089, endtime: 41021167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,9867119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021090, endtime: 41021167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,9869285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021092, endtime: 41021167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,9869416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021095, endtime: 41021167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:58,9869493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021097, endtime: 41021167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,7486933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021094, endtime: 41021243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,7487121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021095, endtime: 41021243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,7487199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021097, endtime: 41021243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,7487277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021100, endtime: 41021243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,7487338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021103, endtime: 41021243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,7488097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021106, endtime: 41021243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,7489352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021108, endtime: 41021244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,7490659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021109, endtime: 41021244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,7490740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021111, endtime: 41021244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,7490812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021114, endtime: 41021244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,7490870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021117, endtime: 41021244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,7490937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021119, endtime: 41021244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,7490995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021121, endtime: 41021244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,9503940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021167, endtime: 41021264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,9504117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021169, endtime: 41021264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,9504192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021170, endtime: 41021264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,9504267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021172, endtime: 41021264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,9504328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021173, endtime: 41021264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,9504397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021174, endtime: 41021264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,9504455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021175, endtime: 41021264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,9504524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021178, endtime: 41021264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,9504583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021180, endtime: 41021264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,9504863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021181, endtime: 41021264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,9504923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021183, endtime: 41021264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,9504993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021184, endtime: 41021264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:05:59,9505054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021186, endtime: 41021264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,2985440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,2985559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,2991070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41021298, endtime: 41021299, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,4817457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021243, endtime: 41021317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,4817626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021247, endtime: 41021317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,4817698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021248, endtime: 41021317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,4817775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021250, endtime: 41021317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,4817833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021252, endtime: 41021317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,4817905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021255, endtime: 41021317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,4817961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021256, endtime: 41021317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,4818027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021259, endtime: 41021317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,4818085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021261, endtime: 41021317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,4818387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021262, endtime: 41021317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,4818448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021265, endtime: 41021317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,4818515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021267, endtime: 41021317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,4818573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021269, endtime: 41021317, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,7191021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 60, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,7191123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 60, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,7207314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 5252</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,7211273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 8528</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,7215161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 11120</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,7971565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55809 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,7977511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55809 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021348, endtime: 41021348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8122331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55807 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8128138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55808 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8129385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55809 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021350, endtime: 41021350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8133845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55807 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021350, endtime: 41021350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8138206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55808 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021350, endtime: 41021350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8290019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55808 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021351, endtime: 41021352, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8290249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55807 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021351, endtime: 41021352, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8290390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55809 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021351, endtime: 41021352, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8446295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55809 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021353, endtime: 41021353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8446564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55807 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021353, endtime: 41021353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8449866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55808 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021353, endtime: 41021353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8602250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55808 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021355, endtime: 41021355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8602513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55807 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021355, endtime: 41021355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8605960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55809 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021355, endtime: 41021355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8762145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8762383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8762646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8762879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8762976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8763073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8763261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8763333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8763416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8763563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8763630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8763857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8763912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8764028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8764103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8764258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8764403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8764477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8764555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8764691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8764760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8764832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8764954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8765009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8765073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8765139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8765907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55809 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8772628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55807 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021356, endtime: 41021356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,8772833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55808 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021356, endtime: 41021356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9067034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9067258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9067535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9067762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9067862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9067951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9068128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9068200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9068278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9068424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9068488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9068718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9068771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9068893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9068967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9069120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9069261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9069336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9069414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9069541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9069610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9069685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9069804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9069857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9069921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9069962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9070893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55808 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9074317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9074417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9074600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9074755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9074835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9074916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9075052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9075121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9075193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9075315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9075370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9075545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9075592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9075705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9075777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9075927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9076074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9076146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9076221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9076351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9076420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9076490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9076606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9076656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9076714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9076758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9077551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55807 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9499765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9505198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021364, endtime: 41021364, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9692826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021365, endtime: 41021366, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9848628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021264, endtime: 41021367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9848797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021265, endtime: 41021367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9848872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021267, endtime: 41021367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9848949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021269, endtime: 41021367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9849010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021272, endtime: 41021367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9849080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021273, endtime: 41021367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9849138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021274, endtime: 41021367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9849207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021277, endtime: 41021367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9849265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021278, endtime: 41021367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9849562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021281, endtime: 41021367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9849626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021283, endtime: 41021367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9849692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021284, endtime: 41021367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9849753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021286, endtime: 41021367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9949975</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9955541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9956802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021368, endtime: 41021368, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:00,9960224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021368, endtime: 41021368, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0035192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021369, endtime: 41021369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0160585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021370, endtime: 41021370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0160829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021370, endtime: 41021370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0167669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021370, endtime: 41021370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0322566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021372, endtime: 41021372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0322818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021372, endtime: 41021372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0357156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021372, endtime: 41021372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0473196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021373, endtime: 41021373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0473409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021373, endtime: 41021373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0490739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021373, endtime: 41021374, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0552395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021374, endtime: 41021374, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0552603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021374, endtime: 41021374, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0552716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021374, endtime: 41021374, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0796074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021376, endtime: 41021377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0796332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021376, endtime: 41021377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0800244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021376, endtime: 41021377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0945379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021378, endtime: 41021378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0945640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021378, endtime: 41021378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,0949197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021378, endtime: 41021378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1109989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021380, endtime: 41021380, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1110167</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021380, endtime: 41021380, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1110283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021380, endtime: 41021380, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1286607</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021381, endtime: 41021381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1286862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021381, endtime: 41021381, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1290422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021381, endtime: 41021382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1414992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021383, endtime: 41021383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1415253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021383, endtime: 41021383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1415380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021383, endtime: 41021383, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1588050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021384, endtime: 41021384, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1588307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021384, endtime: 41021384, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1591848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021384, endtime: 41021385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1949888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021387, endtime: 41021388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1953697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021387, endtime: 41021388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,1953863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021388, endtime: 41021388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2041989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021389, endtime: 41021389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2042258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021389, endtime: 41021389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2045439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021389, endtime: 41021389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2198105</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021390, endtime: 41021391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2198382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021390, endtime: 41021391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2202241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021390, endtime: 41021391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2352433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021392, endtime: 41021392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2352788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021392, endtime: 41021392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2356847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021392, endtime: 41021392, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2522335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021394, endtime: 41021394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2522604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021394, endtime: 41021394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2526505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021394, endtime: 41021394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2691799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021395, endtime: 41021396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2692032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021395, endtime: 41021396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2692146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021395, endtime: 41021396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2989571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021398, endtime: 41021399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2989790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021398, endtime: 41021399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,2989901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021398, endtime: 41021399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3415869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021401, endtime: 41021403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3416132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021401, endtime: 41021403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3422219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021401, endtime: 41021403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3479617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021403, endtime: 41021403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3479830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021403, endtime: 41021403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3479946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021403, endtime: 41021403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3538170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021404, endtime: 41021404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3538416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021404, endtime: 41021404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3542140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021404, endtime: 41021404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3597604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021405, endtime: 41021405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3597839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021405, endtime: 41021405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3597958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021405, endtime: 41021405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3655073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021405, endtime: 41021405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3655290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021405, endtime: 41021405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3659041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021405, endtime: 41021405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3708814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021406, endtime: 41021406, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3910868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021408, endtime: 41021408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3947199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021408, endtime: 41021408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,3947390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021408, endtime: 41021408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,4169057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021409, endtime: 41021410, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,4173753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021409, endtime: 41021410, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,4385712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021412, endtime: 41021412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,4559811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021414, endtime: 41021414, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5017569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021419, endtime: 41021419, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5240092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021420, endtime: 41021421, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5317113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021422, endtime: 41021422, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5477085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021423, endtime: 41021423, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5642679</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021425, endtime: 41021425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5748506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021317, endtime: 41021426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5748678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021320, endtime: 41021426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5748755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021322, endtime: 41021426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5748836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021325, endtime: 41021426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5748897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021327, endtime: 41021426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5748972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021328, endtime: 41021426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5749035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021330, endtime: 41021426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5749107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021331, endtime: 41021426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5749168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021333, endtime: 41021426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5749470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021334, endtime: 41021426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5749537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021336, endtime: 41021426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5749609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021338, endtime: 41021426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5749673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021339, endtime: 41021426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,5949300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021428, endtime: 41021428, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6104681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021430, endtime: 41021430, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6286413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021431, endtime: 41021431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6430485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021433, endtime: 41021433, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6637670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021367, endtime: 41021435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6637842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021369, endtime: 41021435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6638047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021370, endtime: 41021435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6638177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021372, endtime: 41021435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6638244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021373, endtime: 41021435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6638319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021374, endtime: 41021435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6638377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021376, endtime: 41021435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6638452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021378, endtime: 41021435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6640674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021380, endtime: 41021435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6640834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021381, endtime: 41021435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6642394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021383, endtime: 41021435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6643940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021384, endtime: 41021435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6644040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021386, endtime: 41021435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6748573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021436, endtime: 41021436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,6885323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021437, endtime: 41021437, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,7048328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021439, endtime: 41021439, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:01,7272101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021440, endtime: 41021441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,4948061</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021426, endtime: 41021518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,4948255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021428, endtime: 41021518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,4948341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021430, endtime: 41021518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,4948421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021431, endtime: 41021518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,4948487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021433, endtime: 41021518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,4948562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021436, endtime: 41021518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,4972536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021437, endtime: 41021518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,4972677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021439, endtime: 41021518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,4972749</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021440, endtime: 41021518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,4972821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021442, endtime: 41021518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,4972877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021444, endtime: 41021518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,4972943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021445, endtime: 41021518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,4972999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021447, endtime: 41021518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,7833732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021435, endtime: 41021547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,7834037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021436, endtime: 41021547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,7834176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021437, endtime: 41021547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,7834309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021439, endtime: 41021547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,7834414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021440, endtime: 41021547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,7834541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021442, endtime: 41021547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,7834652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021444, endtime: 41021547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,7834780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021445, endtime: 41021547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,7834891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021447, endtime: 41021547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,7835423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021448, endtime: 41021547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,7835536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021450, endtime: 41021547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,7835661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021451, endtime: 41021547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:02,7835766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021453, endtime: 41021547, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,3810255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021518, endtime: 41021607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,3810424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021519, endtime: 41021607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,3810496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021522, endtime: 41021607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,3810568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021525, endtime: 41021607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,3810627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021527, endtime: 41021607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,3810818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021528, endtime: 41021607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,3810901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021530, endtime: 41021607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,3810973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021532, endtime: 41021607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,3811037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021533, endtime: 41021607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,3811366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021534, endtime: 41021607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,3811424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021536, endtime: 41021607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,3811494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021537, endtime: 41021607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,3811552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021539, endtime: 41021607, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,6047594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021547, endtime: 41021629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,6047757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021548, endtime: 41021629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,6047832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021550, endtime: 41021629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,6047912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021551, endtime: 41021629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,6047973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021553, endtime: 41021629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,6048043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021556, endtime: 41021629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,6048101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021558, endtime: 41021629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,6048170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021559, endtime: 41021629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,6048228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021561, endtime: 41021629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,6048516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021564, endtime: 41021629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,6048577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021566, endtime: 41021629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,6048644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021567, endtime: 41021629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,6048702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021569, endtime: 41021629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,9629748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021607, endtime: 41021665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,9631001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021608, endtime: 41021665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,9631120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021609, endtime: 41021665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,9631203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021612, endtime: 41021665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,9631264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021614, endtime: 41021665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,9631336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021617, endtime: 41021665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,9631394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021619, endtime: 41021665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,9631463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021622, endtime: 41021665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,9631521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021623, endtime: 41021665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,9631591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021625, endtime: 41021665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,9631649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021627, endtime: 41021665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,9631904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021629, endtime: 41021665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:03,9631965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021631, endtime: 41021665, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:04,5987461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021629, endtime: 41021728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:04,5987639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021631, endtime: 41021728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:04,5987722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021633, endtime: 41021728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:04,5987811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021635, endtime: 41021728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:04,5987877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021636, endtime: 41021728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:04,5987952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021639, endtime: 41021728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:04,5988013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021641, endtime: 41021728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:04,5988090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021644, endtime: 41021728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:04,5988154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021647, endtime: 41021728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:04,5988437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021648, endtime: 41021728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:04,5988503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021652, endtime: 41021728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:04,5988578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021655, endtime: 41021728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:04,5988639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021658, endtime: 41021728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,3213097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55801 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,7900082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021728, endtime: 41021848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,7900323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021731, endtime: 41021848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,7900442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021733, endtime: 41021848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,7900572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021734, endtime: 41021848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,7900675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021736, endtime: 41021848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,7900786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021737, endtime: 41021848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,7900880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021739, endtime: 41021848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,7901004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021741, endtime: 41021848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,7901107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021744, endtime: 41021848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,7901664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021745, endtime: 41021848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,7901772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021747, endtime: 41021848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,7901897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021749, endtime: 41021848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:05,7901999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021750, endtime: 41021848, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,0073215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021442, endtime: 41021869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,0073404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021444, endtime: 41021869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,0073481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021445, endtime: 41021869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,0073559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021447, endtime: 41021869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,0073617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021448, endtime: 41021869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,0073686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021450, endtime: 41021869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,0073742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021451, endtime: 41021869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,0073913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021453, endtime: 41021869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,0073994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021455, endtime: 41021869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,0074637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021456, endtime: 41021869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,0074709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021458, endtime: 41021869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,0074783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021459, endtime: 41021869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,3171647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021665, endtime: 41021900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,3171932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021665, endtime: 41021900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,3172023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021667, endtime: 41021900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,3172109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021669, endtime: 41021900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,3172176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021670, endtime: 41021900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,3172253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021672, endtime: 41021900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,3172317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021675, endtime: 41021900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,3172395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021676, endtime: 41021900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,3172458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021678, endtime: 41021900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,3172774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021681, endtime: 41021900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,3172841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021685, endtime: 41021900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,3172913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021687, endtime: 41021900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,3172977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021690, endtime: 41021900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,6158405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021848, endtime: 41021930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,6158591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021848, endtime: 41021930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,6158665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021850, endtime: 41021930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,6158740</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021851, endtime: 41021930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,6158798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021853, endtime: 41021930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,6158870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021855, endtime: 41021930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,6158926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021856, endtime: 41021930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,6158992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021858, endtime: 41021930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,6159048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021859, endtime: 41021930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,6159350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021861, endtime: 41021930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,6159411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021864, endtime: 41021930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,6159477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021865, endtime: 41021930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:06,6159533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021867, endtime: 41021930, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:07,5942415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55815 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,0063793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021900, endtime: 41022069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,0063973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021903, endtime: 41022069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,0064053</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021905, endtime: 41022069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,0064133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021906, endtime: 41022069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,0064197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021908, endtime: 41022069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,0064269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021909, endtime: 41022069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,0064330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021912, endtime: 41022069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,0064402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021914, endtime: 41022069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,0065765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021917, endtime: 41022069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,0065890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021919, endtime: 41022069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,0065956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021921, endtime: 41022069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,0066031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021922, endtime: 41022069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,0066095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021923, endtime: 41022069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,5469563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021930, endtime: 41022123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,5469741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021931, endtime: 41022123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,5469818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021933, endtime: 41022123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,5469893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021934, endtime: 41022123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,5469951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021937, endtime: 41022123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,5470020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021941, endtime: 41022123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,5470076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021942, endtime: 41022123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,5470142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021944, endtime: 41022123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,5470300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021945, endtime: 41022123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,5470624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021947, endtime: 41022123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,5470685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021949, endtime: 41022123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,5470755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021950, endtime: 41022123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,5470810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021951, endtime: 41022123, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,9814583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022069, endtime: 41022167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,9814769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022072, endtime: 41022167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,9814855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022073, endtime: 41022167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,9814935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022074, endtime: 41022167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,9814999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022076, endtime: 41022167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,9815074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022078, endtime: 41022167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,9815132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022079, endtime: 41022167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,9815204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022081, endtime: 41022167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,9815265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022085, endtime: 41022167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,9815550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022087, endtime: 41022167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,9815611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022089, endtime: 41022167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,9815683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022091, endtime: 41022167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:08,9815883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022095, endtime: 41022167, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:09,7438803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022167, endtime: 41022243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:09,7439052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022169, endtime: 41022243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:09,7439144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022170, endtime: 41022243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:09,7439232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022173, endtime: 41022243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:09,7439299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022174, endtime: 41022243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:09,7439374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022177, endtime: 41022243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:09,7439432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022178, endtime: 41022243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:09,7439507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022180, endtime: 41022243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:09,7439565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022181, endtime: 41022243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:09,7439886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022183, endtime: 41022243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:09,7439950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022185, endtime: 41022243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:09,7440022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022187, endtime: 41022243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:09,7440080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022189, endtime: 41022243, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,4295416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022123, endtime: 41022312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,4295680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022125, endtime: 41022312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,4295785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022128, endtime: 41022312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,4295874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022130, endtime: 41022312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,4295943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022131, endtime: 41022312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,4296026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022133, endtime: 41022312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,4296092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022134, endtime: 41022312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,4296173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022136, endtime: 41022312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,4296239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022139, endtime: 41022312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,4296569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022141, endtime: 41022312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,4296635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022144, endtime: 41022312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,4296708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022145, endtime: 41022312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,4296768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022148, endtime: 41022312, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,5124953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022312, endtime: 41022320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,5723826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,5723956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,5731060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41022326, endtime: 41022326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,5973902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55812 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,5991240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55811 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,6486401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022243, endtime: 41022333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,6486650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022244, endtime: 41022333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,6486747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022245, endtime: 41022333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,6488285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022247, endtime: 41022333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,6488401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022248, endtime: 41022333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,6488487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022250, endtime: 41022333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,6488553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022251, endtime: 41022333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,6488631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022253, endtime: 41022333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,6488692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022256, endtime: 41022333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,6488769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022258, endtime: 41022333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,6488830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022261, endtime: 41022333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,6488905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022262, endtime: 41022333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:10,6489132</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022264, endtime: 41022334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:11,0887297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021463, endtime: 41022377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:11,0887500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021869, endtime: 41022377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:11,0887580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021872, endtime: 41022377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:11,0887663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021873, endtime: 41022377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:11,0887727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021874, endtime: 41022377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:11,0887799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021876, endtime: 41022377, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:11,0889373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021878, endtime: 41022378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:11,0889489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021881, endtime: 41022378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:11,0889555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021883, endtime: 41022378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:11,0889630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021886, endtime: 41022378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:11,0889691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021887, endtime: 41022378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:11,0889763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021888, endtime: 41022378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:11,0889827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41021889, endtime: 41022378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,2894688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022314, endtime: 41022498, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,2894962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022316, endtime: 41022498, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,2895064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022319, endtime: 41022498, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,2895131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022322, endtime: 41022498, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,2895206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022325, endtime: 41022498, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,2895264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022326, endtime: 41022498, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,2895336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022328, endtime: 41022498, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,2895394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022331, endtime: 41022498, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,2895469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022333, endtime: 41022498, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,2896153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022336, endtime: 41022498, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,2896236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022337, endtime: 41022498, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,2896297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022339, endtime: 41022498, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,4792305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022340, endtime: 41022517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,4792461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022500, endtime: 41022517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,4792732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022500, endtime: 41022517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,4792862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022503, endtime: 41022517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,4792990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022506, endtime: 41022517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,4793089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022508, endtime: 41022517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,4793214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022511, endtime: 41022517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,4793314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022512, endtime: 41022517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,4793425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022514, endtime: 41022517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,4793519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022516, endtime: 41022517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,4962152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022517, endtime: 41022518, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,5180270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022520, endtime: 41022520, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:12,5532671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022523, endtime: 41022524, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,6097824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55815 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,6097915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55836 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,6097938</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55837 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,7092475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022333, endtime: 41022640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,7092813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022336, endtime: 41022640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,7092957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022337, endtime: 41022640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,7093084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022339, endtime: 41022640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,7093184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022340, endtime: 41022640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,7093289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022342, endtime: 41022640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,7093383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022344, endtime: 41022640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,7093511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022347, endtime: 41022640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,7093599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022348, endtime: 41022640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,7094040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022352, endtime: 41022640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,7094106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022355, endtime: 41022640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,7094173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022358, endtime: 41022640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:13,7094231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022359, endtime: 41022640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,5463709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022528, endtime: 41022823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,5463909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022531, endtime: 41022823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,5463989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022533, endtime: 41022823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,5464069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022535, endtime: 41022823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,5464130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022537, endtime: 41022823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,5464202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022539, endtime: 41022823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,5464260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022541, endtime: 41022823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,5464333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022544, endtime: 41022823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,5464391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022545, endtime: 41022823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,5464887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022547, endtime: 41022823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,5464967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022550, endtime: 41022823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,5465042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022551, endtime: 41022823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,5465103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022553, endtime: 41022823, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,6790129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022640, endtime: 41022837, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,6790314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022641, endtime: 41022837, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,6790386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022644, endtime: 41022837, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,6790461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022647, endtime: 41022837, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,6790517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022649, endtime: 41022837, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,6790583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022651, endtime: 41022837, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,6790639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022655, endtime: 41022837, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,6792168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022656, endtime: 41022837, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,6792326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022658, endtime: 41022837, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,6792448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022659, endtime: 41022837, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,6792517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022661, endtime: 41022837, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,6792595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022662, endtime: 41022837, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:15,6792658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022664, endtime: 41022837, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,1833338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022377, endtime: 41022987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,1833535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022380, endtime: 41022987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,1833629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022383, endtime: 41022987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,1833699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022386, endtime: 41022987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,1833776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022387, endtime: 41022987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,1833837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022391, endtime: 41022987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,1833909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022394, endtime: 41022987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,1833970</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022395, endtime: 41022987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,1834039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022398, endtime: 41022987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,1834100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022400, endtime: 41022987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,1834419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022401, endtime: 41022987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,1834485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022403, endtime: 41022987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,1834555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022405, endtime: 41022987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:17,7197914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55843 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:18,8452066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022837, endtime: 41023153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:18,8452216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022837, endtime: 41023153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:18,8452296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022840, endtime: 41023153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:18,8452376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022842, endtime: 41023153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:18,8452440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022844, endtime: 41023153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:18,8452515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022845, endtime: 41023153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:18,8452576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022849, endtime: 41023153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:18,8452648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022850, endtime: 41023153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:18,8452712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022853, endtime: 41023153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:18,8454028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022855, endtime: 41023153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:18,8454116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022858, endtime: 41023153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:18,8454194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022859, endtime: 41023153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:18,8454258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022863, endtime: 41023153, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,5584353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022987, endtime: 41023224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,5584567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022989, endtime: 41023224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,5584647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022990, endtime: 41023224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,5584724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022992, endtime: 41023224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,5584785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022995, endtime: 41023224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,5584855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022997, endtime: 41023224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,5584913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023000, endtime: 41023224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,5584982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023000, endtime: 41023224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,5585040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023003, endtime: 41023224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,5585356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023005, endtime: 41023224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,5585420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023006, endtime: 41023224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,5585489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023008, endtime: 41023224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,5585547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023011, endtime: 41023224, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,6093929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55836 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:19,6094014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55837 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:20,6508338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:20,6508568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:20,6513408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41023334, endtime: 41023334, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,0167896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023153, endtime: 41023370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,0168110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023154, endtime: 41023370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,0168193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023156, endtime: 41023370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,0168273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023158, endtime: 41023370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,0168337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023159, endtime: 41023370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,0168553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023161, endtime: 41023370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,0168678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023162, endtime: 41023370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,0168805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023164, endtime: 41023370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,0168874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023166, endtime: 41023370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,0169207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023167, endtime: 41023370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,0169271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023170, endtime: 41023370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,0169343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023172, endtime: 41023370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,0169404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023173, endtime: 41023370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,6697373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022823, endtime: 41023436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,6697556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022825, endtime: 41023436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,6697631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022828, endtime: 41023436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,6697711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022830, endtime: 41023436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,6697772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022831, endtime: 41023436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,6698091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022833, endtime: 41023436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,6698215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022834, endtime: 41023436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,6698332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022836, endtime: 41023436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,6698432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022837, endtime: 41023436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,6698831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022840, endtime: 41023436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,6700202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022842, endtime: 41023436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,6700318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022844, endtime: 41023436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:21,6700388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41022845, endtime: 41023436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,4881664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023224, endtime: 41023617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,4881872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023226, endtime: 41023617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,4881950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023228, endtime: 41023617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,4882027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023230, endtime: 41023617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,4882088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023231, endtime: 41023617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,4882157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023233, endtime: 41023617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,4882216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023234, endtime: 41023617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,4882282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023236, endtime: 41023617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,4882340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023237, endtime: 41023617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,4882825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023239, endtime: 41023617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,4882900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023240, endtime: 41023617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,4882969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023242, endtime: 41023617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,4884219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023244, endtime: 41023617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,7241946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55847 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,7242063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55848 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:23,7242099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55843 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:25,9973071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023436, endtime: 41023868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:25,9973253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023437, endtime: 41023868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:25,9973447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023439, endtime: 41023868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:25,9973564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023441, endtime: 41023868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:25,9973630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023442, endtime: 41023868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:25,9973702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023444, endtime: 41023868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:25,9973766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023447, endtime: 41023868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:25,9975437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023449, endtime: 41023868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:25,9975545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023450, endtime: 41023868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:25,9975628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023451, endtime: 41023868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:25,9975692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023453, endtime: 41023868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:25,9975766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023455, endtime: 41023868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:25,9975830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023456, endtime: 41023868, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,4170860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023370, endtime: 41024010, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,4171049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023373, endtime: 41024010, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,4171124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023374, endtime: 41024010, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,4171198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023376, endtime: 41024010, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,4171257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023379, endtime: 41024010, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,4171326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023381, endtime: 41024010, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,4171381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023384, endtime: 41024010, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,4171450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023386, endtime: 41024010, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,4171506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023388, endtime: 41024010, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,4171800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023389, endtime: 41024010, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,4171858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023391, endtime: 41024010, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,4172082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023392, endtime: 41024010, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,4172154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023395, endtime: 41024010, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:27,8284001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55852 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,0457082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023868, endtime: 41024173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,0457245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023870, endtime: 41024173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,0457317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023874, endtime: 41024173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,0457395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023875, endtime: 41024173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,0457453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023878, endtime: 41024173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,0457522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023881, endtime: 41024173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,0457578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023883, endtime: 41024173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,0457647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023884, endtime: 41024173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,0457703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023886, endtime: 41024173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,0458010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023888, endtime: 41024173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,0458068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023889, endtime: 41024173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,0458138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023891, endtime: 41024173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,0458193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023892, endtime: 41024173, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,7342404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55847 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,7342487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55848 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,9370812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023617, endtime: 41024262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,9371003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023619, endtime: 41024262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,9371097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023620, endtime: 41024262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,9371355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023622, endtime: 41024262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,9371441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023623, endtime: 41024262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,9371504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023625, endtime: 41024262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,9371582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023627, endtime: 41024262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,9373075</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023630, endtime: 41024262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,9373194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023638, endtime: 41024262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,9373261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023641, endtime: 41024262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,9373336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023644, endtime: 41024262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,9373397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023645, endtime: 41024262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:29,9373471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41023648, endtime: 41024262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:30,9110013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:30,9110157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:30,9114665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41024360, endtime: 41024360, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:31,9076332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024010, endtime: 41024459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:31,9076537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024012, endtime: 41024459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:31,9076623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024014, endtime: 41024459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:31,9076706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024017, endtime: 41024459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:31,9076767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024019, endtime: 41024459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:31,9076841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024020, endtime: 41024459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:31,9076900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024023, endtime: 41024459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:31,9076972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024023, endtime: 41024459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:31,9077033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024025, endtime: 41024459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:31,9077312</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024027, endtime: 41024459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:31,9078667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024028, endtime: 41024459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:31,9078786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024030, endtime: 41024459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:31,9078858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024033, endtime: 41024459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:32,9915354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024173, endtime: 41024568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:32,9915543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024174, endtime: 41024568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:32,9915623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024175, endtime: 41024568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:32,9915701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024178, endtime: 41024568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:32,9915767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024179, endtime: 41024568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:32,9915839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024181, endtime: 41024568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:32,9915897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024183, endtime: 41024568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:32,9915969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024184, endtime: 41024568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:32,9916028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024187, endtime: 41024568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:32,9916324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024190, endtime: 41024568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:32,9916388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024192, endtime: 41024568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:32,9916460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024194, endtime: 41024568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:32,9916518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024195, endtime: 41024568, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,0796908</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024568, endtime: 41024577, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,8430212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55852 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,8430301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55854 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,8430320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55855 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,9207476</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024262, endtime: 41024661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,9207656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024264, endtime: 41024661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,9207731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024266, endtime: 41024661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,9207806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024267, endtime: 41024661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,9207861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024269, endtime: 41024661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,9207930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024270, endtime: 41024661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,9207986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024273, endtime: 41024661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,9208052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024274, endtime: 41024661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,9208108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024277, endtime: 41024661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,9209837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024278, endtime: 41024661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,9209950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024280, endtime: 41024661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,9210031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024282, endtime: 41024661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:33,9210094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024283, endtime: 41024661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,1147597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024459, endtime: 41024680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,1147797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024461, endtime: 41024680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,1147877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024462, endtime: 41024680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,1147954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024464, endtime: 41024680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,1148018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024467, endtime: 41024680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,1148090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024469, endtime: 41024680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,1148148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024470, endtime: 41024680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,1148220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024472, endtime: 41024680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,1148279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024473, endtime: 41024680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,1148575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024474, endtime: 41024680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,1148642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024475, endtime: 41024680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,1148714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024478, endtime: 41024680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,1148775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024480, endtime: 41024680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,9015853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024569, endtime: 41024759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,9016091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024570, endtime: 41024759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,9016238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024572, endtime: 41024759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,9016346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024573, endtime: 41024759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,9016468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024574, endtime: 41024759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,9016576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024577, endtime: 41024759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,9016704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024578, endtime: 41024759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,9016798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024580, endtime: 41024759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,9016903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024581, endtime: 41024759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,9017870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024583, endtime: 41024759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,9017995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024584, endtime: 41024759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,9018083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024586, endtime: 41024759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:34,9023832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024587, endtime: 41024759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,0827315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024759, endtime: 41024877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,0827517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024761, endtime: 41024877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,0827606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024762, endtime: 41024877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,0827692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024765, endtime: 41024877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,0827755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024767, endtime: 41024877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,0827827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024769, endtime: 41024877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,0827888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024770, endtime: 41024877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,0827963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024772, endtime: 41024877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,0828024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024773, endtime: 41024877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,0828869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024774, endtime: 41024877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,0828947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024775, endtime: 41024877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,0829024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024778, endtime: 41024877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,0829672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024780, endtime: 41024877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,9493038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024680, endtime: 41024964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,9493232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024681, endtime: 41024964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,9493306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024683, endtime: 41024964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,9493381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024684, endtime: 41024964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,9493442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024686, endtime: 41024964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,9493512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024689, endtime: 41024964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,9493567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024691, endtime: 41024964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,9493636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024694, endtime: 41024964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,9493692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024695, endtime: 41024964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,9493996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024697, endtime: 41024964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,9494057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024698, endtime: 41024964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,9495409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024700, endtime: 41024964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:36,9495523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024701, endtime: 41024964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:37,9532801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55874 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:38,1888744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024661, endtime: 41025087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:38,1888933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024662, endtime: 41025087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:38,1889010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024664, endtime: 41025087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:38,1889085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024666, endtime: 41025087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:38,1889146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024667, endtime: 41025087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:38,1889215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024669, endtime: 41025087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:38,1889271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024670, endtime: 41025087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:38,1889337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024672, endtime: 41025087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:38,1889392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024673, endtime: 41025087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:38,1889703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024674, endtime: 41025088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:38,1889764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024676, endtime: 41025088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:38,1891127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024678, endtime: 41025088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:38,1891238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024680, endtime: 41025088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,6762315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024964, endtime: 41025236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,6762515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024967, endtime: 41025236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,6762595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024969, endtime: 41025236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,6762675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024973, endtime: 41025236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,6762739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024974, endtime: 41025236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,6762811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024978, endtime: 41025236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,6762872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024980, endtime: 41025236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,6762941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024983, endtime: 41025236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,6763002</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024984, endtime: 41025236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,6763296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024986, endtime: 41025236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,6764662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024988, endtime: 41025236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,6764792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024988, endtime: 41025236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,6764864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024989, endtime: 41025236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,7654067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025236, endtime: 41025245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8303963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024877, endtime: 41025252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8304165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024878, endtime: 41025252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8304243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024880, endtime: 41025252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8305878</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024881, endtime: 41025252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8305974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024883, endtime: 41025252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8306052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024884, endtime: 41025252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8306113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024886, endtime: 41025252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8306185</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024889, endtime: 41025252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8306246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024890, endtime: 41025252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8306318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024892, endtime: 41025252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8306379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024895, endtime: 41025252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8306448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024897, endtime: 41025252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8433395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55854 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:39,8433487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55855 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:41,0466480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:41,0466599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:41,0504240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41025373, endtime: 41025374, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:42,3837656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025237, endtime: 41025507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:42,3837822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025239, endtime: 41025507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:42,3837917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025242, endtime: 41025507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:42,3837989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025244, endtime: 41025507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:42,3838066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025247, endtime: 41025507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:42,3838130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025248, endtime: 41025507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:42,3838202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025250, endtime: 41025507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:42,3838263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025253, endtime: 41025507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:42,3838338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025255, endtime: 41025507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:42,3839180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025256, endtime: 41025507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:42,3839271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025258, endtime: 41025507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:42,3839335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025261, endtime: 41025507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:42,3839936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025262, endtime: 41025507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,7158472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025507, endtime: 41025640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,7158849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025508, endtime: 41025640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,7158957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025509, endtime: 41025640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,7159059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025511, endtime: 41025640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,7159137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025512, endtime: 41025640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,7159228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025514, endtime: 41025640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,7159303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025516, endtime: 41025640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,7159397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025517, endtime: 41025640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,7159475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025519, endtime: 41025640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,7160287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025520, endtime: 41025640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,7160373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025522, endtime: 41025640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,7160450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025523, endtime: 41025640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,7161115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025526, endtime: 41025640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,9531452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55874 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,9844417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55881 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:43,9844494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55882 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,5214905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41024898, endtime: 41025821, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,5215065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025252, endtime: 41025821, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,5215134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025253, endtime: 41025821, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,5215206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025255, endtime: 41025821, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,5215262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025256, endtime: 41025821, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,5215326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025258, endtime: 41025821, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,5215381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025261, endtime: 41025821, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,5215445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025262, endtime: 41025821, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,5215497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025264, endtime: 41025821, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,5215774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025265, endtime: 41025821, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,5215833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025267, endtime: 41025821, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,5215896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025269, endtime: 41025821, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,5215949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025272, endtime: 41025821, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,6132057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025645, endtime: 41025830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,6132259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025646, endtime: 41025830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,6132337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025663, endtime: 41025830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,6132417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025664, endtime: 41025830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,6132475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025669, endtime: 41025830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,6132547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025670, endtime: 41025830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,6134030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025673, endtime: 41025830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,6134146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025674, endtime: 41025830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,6134212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025675, endtime: 41025830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,6134287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025678, endtime: 41025830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,6134351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025681, endtime: 41025830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,6134562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025684, endtime: 41025830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:45,6134683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025687, endtime: 41025830, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,0847775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025088, endtime: 41025877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,0847955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025089, endtime: 41025877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,0848044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025090, endtime: 41025877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,0848108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025092, endtime: 41025877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,0848180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025094, endtime: 41025877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,0848235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025095, endtime: 41025877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,0848302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025098, endtime: 41025877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,0848357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025101, endtime: 41025877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,0848424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025105, endtime: 41025877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,0848479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025106, endtime: 41025877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,0848775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025109, endtime: 41025877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,0848831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025111, endtime: 41025877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,0848900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025112, endtime: 41025877, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:46,1752837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025877, endtime: 41025886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,0782069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55883 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,1885068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025830, endtime: 41026087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,1885270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025831, endtime: 41026087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,1885350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025834, endtime: 41026087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,1885433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025837, endtime: 41026087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,1885497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025845, endtime: 41026087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,1885575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025847, endtime: 41026087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,1885633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025848, endtime: 41026087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,1885705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025852, endtime: 41026087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,1885766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025853, endtime: 41026087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,1886079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025856, endtime: 41026087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,1886140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025856, endtime: 41026087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,1886215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025858, endtime: 41026087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,1886273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025859, endtime: 41026087, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,4855169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025821, endtime: 41026117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,4855394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025822, endtime: 41026117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,4855474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025825, endtime: 41026117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,4855555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025827, endtime: 41026117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,4855615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025828, endtime: 41026117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,4855687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025831, endtime: 41026117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,4855748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025834, endtime: 41026117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,4855820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025838, endtime: 41026117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,4855879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025845, endtime: 41026117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,4856175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025847, endtime: 41026117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,4856239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025848, endtime: 41026117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,4856308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025852, endtime: 41026117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,4856366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025853, endtime: 41026117, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:48,5946501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026117, endtime: 41026128, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:49,9993249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55881 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:49,9993351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55882 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,1271585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,1271724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,1297980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41026381, endtime: 41026382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,3212454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025878, endtime: 41026401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,3212609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025881, endtime: 41026401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,3212690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025883, endtime: 41026401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,3212748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025884, endtime: 41026401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,3212814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025886, endtime: 41026401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,3212867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025887, endtime: 41026401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,3212931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025889, endtime: 41026401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,3212983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025891, endtime: 41026401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,3213047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025892, endtime: 41026401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,3214416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025894, endtime: 41026401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,3214529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025895, endtime: 41026401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,3217056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025897, endtime: 41026401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:51,3217197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41025898, endtime: 41026401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:52,8760831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026087, endtime: 41026556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:52,8761036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026089, endtime: 41026556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:52,8761117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026090, endtime: 41026556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:52,8761197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026092, endtime: 41026556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:52,8761261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026094, endtime: 41026556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:52,8761330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026095, endtime: 41026556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:52,8761391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026097, endtime: 41026556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:52,8761460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026098, endtime: 41026556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:52,8762070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026100, endtime: 41026556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:52,8763170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026100, endtime: 41026556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:52,8764837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026103, endtime: 41026556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:52,8766037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026105, endtime: 41026556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:52,8766140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026106, endtime: 41026556, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0098042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026119, endtime: 41026670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0098281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026120, endtime: 41026670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0098430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026123, endtime: 41026670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0098544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026125, endtime: 41026670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0098671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026128, endtime: 41026670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0098776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026130, endtime: 41026670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0098896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026131, endtime: 41026670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0098998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026133, endtime: 41026670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0099120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026135, endtime: 41026670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0099519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026136, endtime: 41026670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0099644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026138, endtime: 41026670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0099746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026139, endtime: 41026670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0099868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026141, endtime: 41026670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0630522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55889 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0630622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55890 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0933472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55883 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0997549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026670, endtime: 41026679, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0997704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026672, endtime: 41026679, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0997779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026672, endtime: 41026679, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0997857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026675, endtime: 41026679, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,0997920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026678, endtime: 41026679, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,1228195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026680, endtime: 41026681, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,1417524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026683, endtime: 41026683, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,1564425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026684, endtime: 41026684, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,1727869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026686, endtime: 41026686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,1893144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026687, endtime: 41026688, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,2039859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026689, endtime: 41026689, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:54,2216479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026691, endtime: 41026691, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:55,6750019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026401, endtime: 41026836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:55,6750194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026403, endtime: 41026836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:55,6750269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026405, endtime: 41026836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:55,6750344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026406, endtime: 41026836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:55,6750405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026408, endtime: 41026836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:55,6750474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026409, endtime: 41026836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:55,6750532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026411, endtime: 41026836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:55,6750598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026412, endtime: 41026836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:55,6750770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026417, endtime: 41026836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:55,6751637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026420, endtime: 41026836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:55,6751715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026422, endtime: 41026836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:55,6751784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026424, endtime: 41026836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:55,6752621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026425, endtime: 41026836, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:57,3268907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026694, endtime: 41027001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,0231351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026556, endtime: 41027071, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,0231531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026558, endtime: 41027071, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,0231619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026559, endtime: 41027071, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,0231686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026561, endtime: 41027071, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,0231758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026562, endtime: 41027071, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,0233841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026564, endtime: 41027071, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,0234733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026567, endtime: 41027071, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,0234825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026569, endtime: 41027071, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,0234900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026570, endtime: 41027071, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,0234958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026572, endtime: 41027071, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,0235024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026573, endtime: 41027071, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,0235080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026575, endtime: 41027071, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,0235149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026576, endtime: 41027071, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:58,1872534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55906 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:59,8073486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026836, endtime: 41027249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:59,8073713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026837, endtime: 41027249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:59,8073790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026840, endtime: 41027249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:59,8073874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026842, endtime: 41027249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:59,8073935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026844, endtime: 41027249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:59,8074007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026847, endtime: 41027249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:59,8074223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026848, endtime: 41027249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:59,8074325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026851, endtime: 41027249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:59,8074394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026854, endtime: 41027249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:59,8075237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026857, endtime: 41027249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:59,8075311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026858, endtime: 41027249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:06:59,8075384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026859, endtime: 41027249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0591316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027071, endtime: 41027275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0591493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027072, endtime: 41027275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0591568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027073, endtime: 41027275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0591643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027074, endtime: 41027275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0591704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027077, endtime: 41027275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0591770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027080, endtime: 41027275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0591825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027081, endtime: 41027275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0591892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027083, endtime: 41027275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0591947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027084, endtime: 41027275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0592424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027086, endtime: 41027275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0592493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027087, endtime: 41027275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0592562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027089, endtime: 41027275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0592618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027093, endtime: 41027275, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0778173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55889 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,0778262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55890 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,2144184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026697, endtime: 41027290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,2144362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026700, endtime: 41027290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,2144442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026701, endtime: 41027290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,2144525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026703, endtime: 41027290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,2144589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026705, endtime: 41027290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,2144666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026706, endtime: 41027290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,2144727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026708, endtime: 41027290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,2144802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026709, endtime: 41027290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,2144863</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026711, endtime: 41027290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,2145683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026714, endtime: 41027290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,2145761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026716, endtime: 41027290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,2145836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026718, endtime: 41027290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:00,2146686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027001, endtime: 41027290, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:01,2706971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:01,2707115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:01,2711387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41027396, endtime: 41027396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:03,4487256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55799 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:03,6670222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:03,6781499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027636, endtime: 41027636, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:03,7319469</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027642, endtime: 41027642, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:03,7522948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027644, endtime: 41027644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:03,8438211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027653, endtime: 41027653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:03,8996071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027658, endtime: 41027659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:03,9209895</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027661, endtime: 41027661, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,0383202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027672, endtime: 41027672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,0599242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027675, endtime: 41027675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,0681977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027675, endtime: 41027675, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,1593236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027685, endtime: 41027685, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,2188286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55906 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,2188400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55913 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,2188430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55914 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,4975905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027718, endtime: 41027718, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,5031178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027719, endtime: 41027719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,5085982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027719, endtime: 41027719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,5146599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027720, endtime: 41027720, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,5721612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027725, endtime: 41027726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,5781864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027726, endtime: 41027726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,5953048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027728, endtime: 41027728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,6276860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027731, endtime: 41027731, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,6585498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027734, endtime: 41027734, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,6981516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027738, endtime: 41027738, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,7209509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027740, endtime: 41027741, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,7347870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027742, endtime: 41027742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,7510297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027744, endtime: 41027744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,7823121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027747, endtime: 41027747, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,7986008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027748, endtime: 41027748, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,8298253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027751, endtime: 41027752, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,8437205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027753, endtime: 41027753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,8619691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027755, endtime: 41027755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,8909289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027758, endtime: 41027758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,9080352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027759, endtime: 41027759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,9233359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027761, endtime: 41027761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,9398955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027762, endtime: 41027763, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,9746647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027765, endtime: 41027766, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:04,9847376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027767, endtime: 41027767, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0008625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027769, endtime: 41027769, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0198974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027770, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0199198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027290, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0199295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027292, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0199364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027294, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0199439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027295, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0199497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027297, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0199569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027298, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0199630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027301, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0200398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027306, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0200487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027308, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0200559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027309, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0200619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027311, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0200694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027312, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0201478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027314, endtime: 41027771, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0523819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027774, endtime: 41027774, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,0583794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027774, endtime: 41027774, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,5120351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027775, endtime: 41027820, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,5120503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027778, endtime: 41027820, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,5120572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027781, endtime: 41027820, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,5120642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027783, endtime: 41027820, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:05,5120694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027784, endtime: 41027820, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1003542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027786, endtime: 41027979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1003702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027789, endtime: 41027979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1003794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027790, endtime: 41027979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1003860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027792, endtime: 41027979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1003932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027795, endtime: 41027979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1003991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027797, endtime: 41027979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1004060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027798, endtime: 41027979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1004118</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027800, endtime: 41027979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1004187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027820, endtime: 41027979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1004464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027822, endtime: 41027979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1004539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027823, endtime: 41027979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1004597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027825, endtime: 41027979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1004667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027828, endtime: 41027979, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1381280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41026863, endtime: 41027982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1381482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027249, endtime: 41027982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1381560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027250, endtime: 41027982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1381637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027251, endtime: 41027982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1381701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027255, endtime: 41027982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1381773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027256, endtime: 41027982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1381834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027258, endtime: 41027982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1381906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027260, endtime: 41027982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1381964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027262, endtime: 41027982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1382288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027264, endtime: 41027982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1382349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027266, endtime: 41027982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1382419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027267, endtime: 41027982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,1382477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027270, endtime: 41027982, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,7952703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027771, endtime: 41028048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,7952867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027773, endtime: 41028048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,7952947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027774, endtime: 41028048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,7953027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027775, endtime: 41028048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,7953091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027778, endtime: 41028048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,7953163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027781, endtime: 41028048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,7953224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027783, endtime: 41028048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,7953296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027784, endtime: 41028048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,7953357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027786, endtime: 41028048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,7954177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027789, endtime: 41028048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,7954257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027790, endtime: 41028048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,7954335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027792, endtime: 41028048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:07,7956715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027795, endtime: 41028048, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:08,3126359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55916 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,2346374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55913 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,2346460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55914 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,6284751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027979, endtime: 41028331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,6284928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027980, endtime: 41028331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,6285000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027983, endtime: 41028331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,6285072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027984, endtime: 41028331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,6285130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027986, endtime: 41028331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,6285200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027987, endtime: 41028331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,6285255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027989, endtime: 41028331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,6285319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027992, endtime: 41028331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,6285374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027994, endtime: 41028331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,6285676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027995, endtime: 41028331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,6285734</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027997, endtime: 41028331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,6285798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028000, endtime: 41028331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:10,6285856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028001, endtime: 41028331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:11,3694360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:11,3694518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:11,3698502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41028406, endtime: 41028406, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:12,3217563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028048, endtime: 41028501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:12,3217832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028050, endtime: 41028501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:12,3217948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028053, endtime: 41028501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:12,3218062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028056, endtime: 41028501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:12,3218153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028058, endtime: 41028501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:12,3218267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028059, endtime: 41028501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:12,3218361</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028061, endtime: 41028501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:12,3218466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028062, endtime: 41028501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:12,3218552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028064, endtime: 41028501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:12,3219605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028065, endtime: 41028501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:12,3219691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028068, endtime: 41028501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:12,3219769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028070, endtime: 41028501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:12,3222594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028072, endtime: 41028501, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,1003880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55800 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,1922578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,1926659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028588, endtime: 41028588, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,2038825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028589, endtime: 41028589, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,2342049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028592, endtime: 41028592, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,2506815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028594, endtime: 41028594, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,2838980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028597, endtime: 41028597, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,2989770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028598, endtime: 41028599, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,3150939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028600, endtime: 41028600, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,3207016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028601, endtime: 41028601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,3536610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028603, endtime: 41028604, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,3597784</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028605, endtime: 41028605, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,3765915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028606, endtime: 41028606, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,3926577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028608, endtime: 41028608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,4070458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028609, endtime: 41028609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,4240443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028611, endtime: 41028611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,4598319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028614, endtime: 41028615, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,4865462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028617, endtime: 41028617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,5011091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028619, endtime: 41028619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,5162106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028620, endtime: 41028620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,5338402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028622, endtime: 41028622, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,5482934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028623, endtime: 41028623, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,5632165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028625, endtime: 41028625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,5802532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028626, endtime: 41028627, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,5944936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028628, endtime: 41028628, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,6116293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028630, endtime: 41028630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,6268726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028631, endtime: 41028631, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,6415014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028633, endtime: 41028633, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,7702851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028634, endtime: 41028646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,7702998</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028636, endtime: 41028646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,7703073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028638, endtime: 41028646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,7703150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028639, endtime: 41028646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,7703211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028641, endtime: 41028646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,7703281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028643, endtime: 41028646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,7703339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028644, endtime: 41028646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,7703411</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028646, endtime: 41028646, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,7835722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028647, endtime: 41028647, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,7976486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028648, endtime: 41028648, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,8127154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028650, endtime: 41028650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,8291626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028651, endtime: 41028652, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:13,8452266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028653, endtime: 41028653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0111388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027982, endtime: 41028670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0111554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027984, endtime: 41028670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0111637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027986, endtime: 41028670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0111698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027987, endtime: 41028670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0111765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027989, endtime: 41028670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0111817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027992, endtime: 41028670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0111884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027994, endtime: 41028670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0111939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027995, endtime: 41028670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0112003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41027997, endtime: 41028670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0112056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028000, endtime: 41028670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0112372</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028001, endtime: 41028670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0112427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028004, endtime: 41028670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0112494</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028005, endtime: 41028670, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,0941672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028670, endtime: 41028678, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,3277862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55916 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,3291961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55923 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,3292055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55924 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,4228433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028331, endtime: 41028711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,4228629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028333, endtime: 41028711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,4228710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028334, endtime: 41028711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,4228790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028336, endtime: 41028711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,4228981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028337, endtime: 41028711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,4229114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028339, endtime: 41028711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,4229211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028341, endtime: 41028711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,4229322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028342, endtime: 41028711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,4229391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028344, endtime: 41028711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,4229726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028345, endtime: 41028711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,4229790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028347, endtime: 41028711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,4229862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028348, endtime: 41028711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:14,4229923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028350, endtime: 41028711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:17,6927574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028656, endtime: 41029038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:17,6927790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028658, endtime: 41029038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:17,6927873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028660, endtime: 41029038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:17,6927959</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028663, endtime: 41029038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:17,6928028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028664, endtime: 41029038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:17,6928103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028665, endtime: 41029038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:17,6928164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028667, endtime: 41029038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:17,6928238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028669, endtime: 41029038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:17,6928299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028670, endtime: 41029038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:17,6928590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028672, endtime: 41029038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:17,6928657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028674, endtime: 41029038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:17,6928729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028675, endtime: 41029038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:17,6928790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028678, endtime: 41029038, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,2226093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028711, endtime: 41029091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,2226293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028714, endtime: 41029091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,2226373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028715, endtime: 41029091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,2226453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028717, endtime: 41029091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,2226514</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028720, endtime: 41029091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,2226586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028722, endtime: 41029091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,2226644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028724, endtime: 41029091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,2226711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028725, endtime: 41029091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,2226769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028727, endtime: 41029091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,2227063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028729, endtime: 41029091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,2227121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028731, endtime: 41029091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,2227190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028733, endtime: 41029091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,2227243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028734, endtime: 41029091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:18,4217029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55933 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:19,4995108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028672, endtime: 41029219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:19,4995268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028674, endtime: 41029219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:19,4995351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028675, endtime: 41029219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:19,4995415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028678, endtime: 41029219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:19,4995484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028679, endtime: 41029219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:19,4995540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028681, endtime: 41029219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:19,4995609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028684, endtime: 41029219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:19,4995665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028686, endtime: 41029219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:19,4995731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028687, endtime: 41029219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:19,4996601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028689, endtime: 41029219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:19,4996692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028691, endtime: 41029219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:19,4996753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028692, endtime: 41029219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:19,4999471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41028694, endtime: 41029219, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:20,3299209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55923 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:20,3299289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55924 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,0951159</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029091, endtime: 41029378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,0951347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029092, endtime: 41029378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,0951422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029094, endtime: 41029378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,0951502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029095, endtime: 41029378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,0951566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029097, endtime: 41029378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,0951638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029098, endtime: 41029378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,0951699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029100, endtime: 41029378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,0951774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029100, endtime: 41029378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,0951835</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029103, endtime: 41029378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,0952165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029105, endtime: 41029378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,0952223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029108, endtime: 41029378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,0952289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029109, endtime: 41029378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,0952342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029111, endtime: 41029378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,4377544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029038, endtime: 41029412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,4377843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029039, endtime: 41029412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,4377954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029042, endtime: 41029412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,4378154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029044, endtime: 41029412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,4378323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029048, endtime: 41029412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,4378472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029048, endtime: 41029412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,4378586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029050, endtime: 41029412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,4378716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029051, endtime: 41029412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,4378796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029053, endtime: 41029412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,4379226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029055, endtime: 41029412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,4379295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029056, endtime: 41029412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,4379370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029059, endtime: 41029412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,4379436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029061, endtime: 41029412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,5647303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,5647442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:21,5650880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41029425, endtime: 41029425, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:23,6387708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029378, endtime: 41029632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:23,6388029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029380, endtime: 41029632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:23,6388121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029383, endtime: 41029632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:23,6388215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029384, endtime: 41029632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:23,6388281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029386, endtime: 41029632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:23,6388362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029387, endtime: 41029632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:23,6388428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029389, endtime: 41029632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:23,6388506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029391, endtime: 41029632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:23,6388569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029392, endtime: 41029632, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:23,6389007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029394, endtime: 41029633, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:23,6389165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029396, endtime: 41029633, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:23,6389401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029397, endtime: 41029633, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:23,6389475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029398, endtime: 41029633, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:24,4373269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55933 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:24,4529617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55936 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:24,4529703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55937 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,3176420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029412, endtime: 41029900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,3176603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029414, endtime: 41029900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,3176775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029415, endtime: 41029900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,3176897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029417, endtime: 41029900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,3176961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029419, endtime: 41029900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,3177033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029422, endtime: 41029900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,3177094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029423, endtime: 41029900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,3177168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029426, endtime: 41029900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,3177224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029428, endtime: 41029900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,3177556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029431, endtime: 41029900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,3177617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029433, endtime: 41029900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,3177684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029434, endtime: 41029900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,3177739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029437, endtime: 41029900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,5353649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029633, endtime: 41029922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,5353851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029634, endtime: 41029922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,5353934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029636, endtime: 41029922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,5354014</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029637, endtime: 41029922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,5354078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029641, endtime: 41029922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,5354150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029642, endtime: 41029922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,5354208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029645, endtime: 41029922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,5354280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029647, endtime: 41029922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,5354339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029649, endtime: 41029922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,5354632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029649, endtime: 41029922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,5354693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029650, endtime: 41029922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,5354762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029650, endtime: 41029922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:26,5354821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029651, endtime: 41029922, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:27,0282722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029219, endtime: 41029971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:27,0282883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029220, endtime: 41029971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:27,0282955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029222, endtime: 41029971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:27,0283033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029223, endtime: 41029971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:27,0283091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029225, endtime: 41029971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:27,0283160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029226, endtime: 41029971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:27,0283215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029228, endtime: 41029971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:27,0283285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029230, endtime: 41029971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:27,0283340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029231, endtime: 41029971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:27,0284169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029233, endtime: 41029971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:27,0284241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029234, endtime: 41029971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:27,0284313</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029236, endtime: 41029971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:27,0286194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029237, endtime: 41029971, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:28,5468954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55942 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,4685750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55936 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,4685844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55937 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,7887138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029922, endtime: 41030347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,7887437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029925, endtime: 41030347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,7887581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029926, endtime: 41030347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,7887742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029928, endtime: 41030347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,7887866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029930, endtime: 41030347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,7888022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029933, endtime: 41030347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,7888155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029934, endtime: 41030347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,7888307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029937, endtime: 41030347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,7888448</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029940, endtime: 41030347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,7889049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029942, endtime: 41030348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,7889194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029944, endtime: 41030348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,7889343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029945, endtime: 41030348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:30,7889473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029947, endtime: 41030348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,1626153</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029900, endtime: 41030385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,1626422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029901, endtime: 41030385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,1626530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029905, endtime: 41030385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,1626616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029906, endtime: 41030385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,1626680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029908, endtime: 41030385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,1626757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029911, endtime: 41030385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,1626821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029913, endtime: 41030385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,1626896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029916, endtime: 41030385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,1626957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029917, endtime: 41030385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,1627270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029919, endtime: 41030385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,1627336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029922, endtime: 41030385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,1627414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029925, endtime: 41030385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,1627475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029926, endtime: 41030385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,2223043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029971, endtime: 41030391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,2223284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029972, endtime: 41030391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,2223414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029975, endtime: 41030391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,2223525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029976, endtime: 41030391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,2223611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029978, endtime: 41030391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,2223705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029980, endtime: 41030391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,2223782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029981, endtime: 41030391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,2223874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029983, endtime: 41030391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,2223957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029984, endtime: 41030391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,2225087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029986, endtime: 41030391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,2225204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029987, endtime: 41030391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,2225326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029989, endtime: 41030391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,2226866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41029991, endtime: 41030391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,7134670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,7134795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:31,7139918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41030440, endtime: 41030440, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,0200777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030385, endtime: 41030671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,0200955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030386, endtime: 41030671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,0201027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030387, endtime: 41030671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,0201102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030389, endtime: 41030671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,0201163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030390, endtime: 41030671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,0201232</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030391, endtime: 41030671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,0201287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030391, endtime: 41030671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,0201354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030392, endtime: 41030671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,0201409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030392, endtime: 41030671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,0201708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030393, endtime: 41030671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,0201764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030395, endtime: 41030671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,0201830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030397, endtime: 41030671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,0202819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030399, endtime: 41030671, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,5621099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55942 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,5933369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55949 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:34,5933466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55950 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,3400683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030391, endtime: 41030903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,3400836</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030392, endtime: 41030903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,3400919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030392, endtime: 41030903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,3400983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030393, endtime: 41030903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,3401052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030395, endtime: 41030903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,3401107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030397, endtime: 41030903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,3401174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030399, endtime: 41030903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,3401229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030400, endtime: 41030903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,3401298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030401, endtime: 41030903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,3401985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030404, endtime: 41030903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,3402066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030405, endtime: 41030903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,3402121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030407, endtime: 41030903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4261158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030408, endtime: 41030911, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4551051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030348, endtime: 41030914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4551247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030350, endtime: 41030914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4551336</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030351, endtime: 41030914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4551405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030353, endtime: 41030914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4551474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030355, endtime: 41030914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4551533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030358, endtime: 41030914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4551602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030361, endtime: 41030914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4551660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030362, endtime: 41030914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4551729</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030364, endtime: 41030914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4552062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030366, endtime: 41030914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4552139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030367, endtime: 41030914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4552198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030369, endtime: 41030914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:36,4552270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030374, endtime: 41030914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,5381728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030671, endtime: 41031122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,5381903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030672, endtime: 41031122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,5381978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030673, endtime: 41031122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,5382055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030674, endtime: 41031122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,5382113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030676, endtime: 41031122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,5382183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030678, endtime: 41031122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,5382241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030679, endtime: 41031122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,5382307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030679, endtime: 41031122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,5382365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030680, endtime: 41031122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,5382684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030680, endtime: 41031122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,5382742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030683, endtime: 41031122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,5382809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030684, endtime: 41031122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,5382867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030686, endtime: 41031122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,6569512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55951 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,7413081</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030903, endtime: 41031143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,7413250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030904, endtime: 41031143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,7413325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030906, endtime: 41031143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,7413397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030909, endtime: 41031143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,7413455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030912, endtime: 41031143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,7413522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030914, endtime: 41031143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,7413574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030917, endtime: 41031143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,7414995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030919, endtime: 41031143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,7415101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030921, endtime: 41031143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,7415181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030923, endtime: 41031143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,7415245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030925, endtime: 41031143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,7417486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030926, endtime: 41031143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:38,7417597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030928, endtime: 41031143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,4257945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030914, endtime: 41031311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,4258133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030917, endtime: 41031311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,4258211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030919, endtime: 41031311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,4258288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030921, endtime: 41031311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,4258346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030922, endtime: 41031311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,4258421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030923, endtime: 41031311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,4258479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030925, endtime: 41031311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,4258549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030926, endtime: 41031311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,4258610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030928, endtime: 41031311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,4258892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030930, endtime: 41031311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,4258953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030931, endtime: 41031311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,4259020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030933, endtime: 41031311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,4259078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41030934, endtime: 41031311, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,5936813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55949 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,5936899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55950 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,7889346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031122, endtime: 41031348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,7889617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031125, endtime: 41031348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,7889739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031128, endtime: 41031348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,7889861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031130, endtime: 41031348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,7889964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031133, endtime: 41031348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,7890080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031133, endtime: 41031348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,7890177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031134, endtime: 41031348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,7890296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031135, endtime: 41031348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,7890399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031135, endtime: 41031348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,7890870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031136, endtime: 41031348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,7890969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031137, endtime: 41031348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,7891083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031141, endtime: 41031348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:40,7891474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031144, endtime: 41031348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:41,8482548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:41,8482675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:41,8487554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41031453, endtime: 41031453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:43,0181830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031311, endtime: 41031570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:43,0182021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031312, endtime: 41031570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:43,0182104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031314, endtime: 41031570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:43,0182181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031317, endtime: 41031570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:43,0182240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031320, endtime: 41031570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:43,0182309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031320, endtime: 41031570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:43,0182367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031323, endtime: 41031570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:43,0183032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031326, endtime: 41031570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:43,0184282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031328, endtime: 41031570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:43,0184398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031330, endtime: 41031570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:43,0184464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031331, endtime: 41031570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:43,0184539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031334, endtime: 41031570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:43,0184600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031336, endtime: 41031570, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:44,6716640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55951 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:44,7038310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55960 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:44,7038388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55961 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,1974138</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031570, endtime: 41031788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,1974310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031572, endtime: 41031788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,1974382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031573, endtime: 41031788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,1974457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031574, endtime: 41031788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,1974515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031576, endtime: 41031788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,1974582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031580, endtime: 41031788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,1974634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031581, endtime: 41031788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,1974704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031583, endtime: 41031788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,1974759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031584, endtime: 41031788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,1975089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031586, endtime: 41031788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,1975144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031589, endtime: 41031788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,1975208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031591, endtime: 41031788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,1975263</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031594, endtime: 41031788, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:45,4456444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031788, endtime: 41031813, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,0566189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031348, endtime: 41031874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,0566378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031348, endtime: 41031874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,0566453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031350, endtime: 41031874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,0566527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031351, endtime: 41031874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,0566586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031355, endtime: 41031874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,0566652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031358, endtime: 41031874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,0566708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031359, endtime: 41031874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,0566777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031361, endtime: 41031874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,0566832</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031362, endtime: 41031874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,0568181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031364, endtime: 41031874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,0568306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031366, endtime: 41031874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,0568386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031367, endtime: 41031874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,0568453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031369, endtime: 41031874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,3391928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031874, endtime: 41031903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,3392100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031876, endtime: 41031903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,3392169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031878, endtime: 41031903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,3392241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031880, endtime: 41031903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,3392300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031881, endtime: 41031903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,3392369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031883, endtime: 41031903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,3392424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031884, endtime: 41031903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,3392491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031886, endtime: 41031903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,3392543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031887, endtime: 41031903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,3392862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031889, endtime: 41031903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,3392917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031890, endtime: 41031903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,3392984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031892, endtime: 41031903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:46,3393039</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031894, endtime: 41031903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2024995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031143, endtime: 41032089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2025172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031144, endtime: 41032089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2025264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031147, endtime: 41032089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2025330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031148, endtime: 41032089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2025402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031150, endtime: 41032089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2025460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031151, endtime: 41032089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2025668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031154, endtime: 41032089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2025787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031156, endtime: 41032089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2025915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031158, endtime: 41032089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2026383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031159, endtime: 41032089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2026499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031163, endtime: 41032089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2026599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031164, endtime: 41032089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2026715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031166, endtime: 41032089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2932356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032089, endtime: 41032098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2932528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032090, endtime: 41032098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2932600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032092, endtime: 41032098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2932675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032094, endtime: 41032098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,2932733</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032095, endtime: 41032098, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,3021842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032098, endtime: 41032099, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,3127318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032100, endtime: 41032100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,3184483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032100, endtime: 41032100, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,3445705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032103, endtime: 41032103, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,3611077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032105, endtime: 41032105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,3757393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032106, endtime: 41032106, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,3960766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032108, endtime: 41032108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7390556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031789, endtime: 41032143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7390717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031791, endtime: 41032143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7390806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031792, endtime: 41032143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7390869</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031794, endtime: 41032143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7390941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031795, endtime: 41032143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7391000</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031797, endtime: 41032143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7391069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031798, endtime: 41032143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7391124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031800, endtime: 41032143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7391194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031800, endtime: 41032143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7391944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031804, endtime: 41032143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7392030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031805, endtime: 41032143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7392091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031806, endtime: 41032143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7393357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031813, endtime: 41032143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:48,7967567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55966 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:50,7182363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55960 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:50,7182451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55961 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,0133641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,0133769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,0138021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41032470, endtime: 41032470, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,1925360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032143, endtime: 41032488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,1925554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032144, endtime: 41032488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,1925637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032145, endtime: 41032488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,1925717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032147, endtime: 41032488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,1925781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032148, endtime: 41032488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,1925856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032150, endtime: 41032488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,1925917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032151, endtime: 41032488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,1925986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032153, endtime: 41032488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,1926047</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032154, endtime: 41032488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,1926837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032156, endtime: 41032488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,1926914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032158, endtime: 41032488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,1926989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032161, endtime: 41032488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:52,1928258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032162, endtime: 41032488, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:53,8907912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031903, endtime: 41032658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:53,8908048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031905, endtime: 41032658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:53,8908131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031906, endtime: 41032658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:53,8908192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031910, endtime: 41032658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:53,8908261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031913, endtime: 41032658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:53,8908314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031914, endtime: 41032658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:53,8908380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031916, endtime: 41032658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:53,8908433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031919, endtime: 41032658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:53,8908497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031920, endtime: 41032658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:53,8908787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031922, endtime: 41032658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:53,8908854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031925, endtime: 41032658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:53,8908907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031926, endtime: 41032658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:53,8908973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41031928, endtime: 41032658, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,0339541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032488, endtime: 41032672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,0339713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032491, endtime: 41032672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,0339788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032494, endtime: 41032672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,0339860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032495, endtime: 41032672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,0339915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032497, endtime: 41032672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,0339981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032500, endtime: 41032672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,0340037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032501, endtime: 41032672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,0340103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032503, endtime: 41032672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,0340156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032505, endtime: 41032672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,0340921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032508, endtime: 41032672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,0340993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032509, endtime: 41032672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,0341059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032511, endtime: 41032672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,0342245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032514, endtime: 41032672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,8126553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55966 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,8126644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55970 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:54,8126669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55971 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:55,9488691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032658, endtime: 41032863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:55,9488901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032659, endtime: 41032863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:55,9488982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032661, endtime: 41032863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:55,9489065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032662, endtime: 41032863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:55,9489126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032664, endtime: 41032863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:55,9489198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032666, endtime: 41032863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:55,9489259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032667, endtime: 41032863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:55,9489331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032669, endtime: 41032863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:55,9489392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032672, endtime: 41032863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:55,9489694</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032673, endtime: 41032864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:55,9489757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032674, endtime: 41032864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:55,9489827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032676, endtime: 41032864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:55,9489888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032679, endtime: 41032864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:57,2585005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032672, endtime: 41032994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:57,2585208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032673, endtime: 41032994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:57,2585288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032674, endtime: 41032994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:57,2585368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032676, endtime: 41032994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:57,2585429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032679, endtime: 41032994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:57,2585499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032681, endtime: 41032994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:57,2585557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032683, endtime: 41032994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:57,2585626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032685, endtime: 41032994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:57,2585684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032686, endtime: 41032994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:57,2586524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032689, endtime: 41032994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:57,2586598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032691, endtime: 41032994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:57,2586671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032692, endtime: 41032994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:57,2587615</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032696, endtime: 41032994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:58,9216453</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55974 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,1082669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032994, endtime: 41033179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,1082860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032995, endtime: 41033179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,1082935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032997, endtime: 41033179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,1083013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032998, endtime: 41033179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,1083071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033000, endtime: 41033179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,1083140</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033001, endtime: 41033179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,1083195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033003, endtime: 41033179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,1083262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033005, endtime: 41033179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,1083320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033008, endtime: 41033179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,1083636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033009, endtime: 41033179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,1083697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033011, endtime: 41033179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,1083763</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033012, endtime: 41033179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,1083822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033015, endtime: 41033179, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,5393949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032864, endtime: 41033223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,5394193</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032866, endtime: 41033223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,5394304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032869, endtime: 41033223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,5394379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032870, endtime: 41033223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,5394440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032872, endtime: 41033223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,5394517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032874, endtime: 41033223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,5394578</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032875, endtime: 41033223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,5394650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032875, endtime: 41033223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,5394711</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032878, endtime: 41033223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,5395021</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032880, endtime: 41033223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,5395082</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032883, endtime: 41033223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,5395152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032884, endtime: 41033223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:07:59,5395207</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032887, endtime: 41033223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:00,8272345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55970 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:00,8272434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55971 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:01,7344992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55977 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,2011563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,2011688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,2015229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41033489, endtime: 41033489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,7381668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033179, endtime: 41033542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,7381837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033181, endtime: 41033542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,7381915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033183, endtime: 41033542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,7381995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033184, endtime: 41033542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,7382056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033186, endtime: 41033542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,7382126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033189, endtime: 41033542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,7382187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033190, endtime: 41033542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,7382259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033192, endtime: 41033542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,7382317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033195, endtime: 41033542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,7382605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033197, endtime: 41033542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,7382669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033200, endtime: 41033542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,7382741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033201, endtime: 41033542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:02,7382802</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033203, endtime: 41033542, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:03,8131881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032111, endtime: 41033650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:03,8132119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032114, endtime: 41033650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:03,8132205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032116, endtime: 41033650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:03,8132288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032119, endtime: 41033650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:03,8132355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032120, endtime: 41033650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:03,8132429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032123, endtime: 41033650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:03,8132490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032126, endtime: 41033650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:03,8132562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032126, endtime: 41033650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:03,8132623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032130, endtime: 41033650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:03,8133111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032131, endtime: 41033650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:03,8133244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032133, endtime: 41033650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:03,8133369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032134, endtime: 41033650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:03,8133479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41032136, endtime: 41033650, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:04,9211945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55982 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:04,9212031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55983 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:04,9212059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55974 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:06,0413376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033223, endtime: 41033873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:06,0413590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033223, endtime: 41033873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:06,0413673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033225, endtime: 41033873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:06,0413759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033228, endtime: 41033873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:06,0413822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033230, endtime: 41033873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:06,0413900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033233, endtime: 41033873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:06,0413964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033234, endtime: 41033873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:06,0414036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033236, endtime: 41033873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:06,0414094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033239, endtime: 41033873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:06,0414426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033241, endtime: 41033873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:06,0414493</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033242, endtime: 41033873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:06,0414568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033246, endtime: 41033873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:06,0414629</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033248, endtime: 41033873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,1407368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033542, endtime: 41033983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,1407570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033544, endtime: 41033983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,1407650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033547, endtime: 41033983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,1407728</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033548, endtime: 41033983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,1407786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033551, endtime: 41033983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,1407855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033553, endtime: 41033983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,1407913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033555, endtime: 41033983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,1407980</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033556, endtime: 41033983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,1408035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033558, endtime: 41033983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,1408346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033559, endtime: 41033983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,1408407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033563, endtime: 41033983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,1408473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033567, endtime: 41033983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,1408528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033569, endtime: 41033983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:07,7345069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55977 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:09,0461274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55988 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:10,9223606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55982 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:10,9223687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55983 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,2766738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033873, endtime: 41034396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,2766937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033875, endtime: 41034396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,2767034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033876, endtime: 41034396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,2767103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033878, endtime: 41034396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,2767181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033880, endtime: 41034396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,2767242</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033881, endtime: 41034396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,2767314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033883, endtime: 41034396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,2767375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033885, endtime: 41034396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,2767447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033886, endtime: 41034396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,2767508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033887, endtime: 41034396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,2767821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033889, endtime: 41034396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,2767885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033891, endtime: 41034396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,2767962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033892, endtime: 41034396, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3201256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033983, endtime: 41034401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3201441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033984, endtime: 41034401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3201516</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033985, endtime: 41034401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3201591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033985, endtime: 41034401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3201655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033987, endtime: 41034401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3201724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033989, endtime: 41034401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3201782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033990, endtime: 41034401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3201851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033992, endtime: 41034401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3222675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033995, endtime: 41034401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3222811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033997, endtime: 41034401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3222880</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41033998, endtime: 41034401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3222955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034000, endtime: 41034401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3223010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034001, endtime: 41034401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3487432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034396, endtime: 41034403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3487599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034398, endtime: 41034403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3487673</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034400, endtime: 41034403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3487748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034400, endtime: 41034403, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3536399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034403, endtime: 41034404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3601302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034405, endtime: 41034405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3825114</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034406, endtime: 41034407, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,3927007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034408, endtime: 41034408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,4070073</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034409, endtime: 41034409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,4235905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034411, endtime: 41034411, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,4382351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034412, endtime: 41034412, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,4550164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034414, endtime: 41034414, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,4706870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034416, endtime: 41034416, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:11,8741246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:12,3854429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:12,3854545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:12,3858455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41034507, endtime: 41034507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:13,6587814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034401, endtime: 41034634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:13,6587997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034403, endtime: 41034634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:13,6588072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034405, endtime: 41034634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:13,6588147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034406, endtime: 41034634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:13,6588202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034408, endtime: 41034634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:13,6588269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034409, endtime: 41034634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:13,6588321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034411, endtime: 41034634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:13,6588388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034412, endtime: 41034634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:13,6588443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034414, endtime: 41034634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:13,6588745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034416, endtime: 41034634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:13,6588803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034419, endtime: 41034634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:13,6588870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034422, endtime: 41034634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:13,6588925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034425, endtime: 41034634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:15,0464610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55994 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:15,0464709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55995 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:15,0464731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55988 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:16,9799531</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55810 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,2067681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034634, endtime: 41034989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,2067861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034636, endtime: 41034989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,2067941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034637, endtime: 41034989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,2068024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034639, endtime: 41034989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,2068091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034641, endtime: 41034989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,2068163</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034642, endtime: 41034989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,2068227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034644, endtime: 41034989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,2068299</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034645, endtime: 41034989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,2068360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034647, endtime: 41034989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,2068656</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034648, endtime: 41034989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,2068720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034650, endtime: 41034989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,2068789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034651, endtime: 41034989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,2068850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034653, endtime: 41034989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,8749350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,9455480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,9486103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035063, endtime: 41035063, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,9533397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035064, endtime: 41035064, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:17,9692801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035065, endtime: 41035066, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,0017352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035069, endtime: 41035069, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,0167583</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035070, endtime: 41035070, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,0480413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035073, endtime: 41035073, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,0554523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035074, endtime: 41035074, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,0840400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035076, endtime: 41035077, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,0947926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035078, endtime: 41035078, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,1100179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035080, endtime: 41035080, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,1260129</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035081, endtime: 41035081, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,1413618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035083, endtime: 41035083, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,1690680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035084, endtime: 41035086, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,1898472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035088, endtime: 41035088, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,2040272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035089, endtime: 41035089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,2216241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035090, endtime: 41035091, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,2358828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035092, endtime: 41035092, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,2505017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035094, endtime: 41035094, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,2672633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035095, endtime: 41035095, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,2812973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035097, endtime: 41035097, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,2991183</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035098, endtime: 41035099, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,3294111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035101, endtime: 41035102, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,3615357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035105, endtime: 41035105, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,3761233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035106, endtime: 41035106, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,3946764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035108, endtime: 41035108, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:18,4146684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035109, endtime: 41035110, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,0874921</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035112, endtime: 41035177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,0875110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035114, endtime: 41035177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,0875184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035116, endtime: 41035177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,0875262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035117, endtime: 41035177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,0875320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035119, endtime: 41035177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,0875390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035120, endtime: 41035177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,0875445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035123, endtime: 41035177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,0875633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035123, endtime: 41035177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,0875747</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035126, endtime: 41035177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,0876121</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035126, endtime: 41035177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,0876187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035128, endtime: 41035177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,0876254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035130, endtime: 41035177, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,1872752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55998 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,8149801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034989, endtime: 41035250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,8149981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034990, endtime: 41035250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,8150064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034992, endtime: 41035250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,8150144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034994, endtime: 41035250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,8150211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034997, endtime: 41035250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,8150286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034998, endtime: 41035250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,8150347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035000, endtime: 41035250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,8150421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035000, endtime: 41035250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,8150482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035005, endtime: 41035250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,8150790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035006, endtime: 41035250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,8150856</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035008, endtime: 41035250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,8150928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035009, endtime: 41035250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,8150992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035012, endtime: 41035250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:19,9020258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035250, endtime: 41035259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7754004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034419, endtime: 41035346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7754187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034422, endtime: 41035346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7754264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034425, endtime: 41035346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7754339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034426, endtime: 41035346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7754397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034428, endtime: 41035346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7754467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034430, endtime: 41035346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7754525</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034433, endtime: 41035346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7754741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034434, endtime: 41035346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7754849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034436, endtime: 41035346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7755290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034439, endtime: 41035346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7755353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034440, endtime: 41035346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7755420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034442, endtime: 41035346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7755475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41034445, endtime: 41035346, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7894793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035346, endtime: 41035348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,7965406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035348, endtime: 41035348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,8129540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035350, endtime: 41035350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,8285157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035351, endtime: 41035351, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,8439926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035353, endtime: 41035353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,8597426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035355, endtime: 41035355, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,8753500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035356, endtime: 41035356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,8983643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035358, endtime: 41035358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,9235500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035361, endtime: 41035361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,9384085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035362, endtime: 41035362, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,9534042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035364, endtime: 41035364, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,9696965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035365, endtime: 41035366, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:20,9863667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035367, endtime: 41035367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:21,0618725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55994 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:21,0618811</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55995 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,2295255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035131, endtime: 41035492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,2295435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035177, endtime: 41035492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,2295507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035178, endtime: 41035492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,2295582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035180, endtime: 41035492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,2295640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035181, endtime: 41035492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,2295709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035183, endtime: 41035492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,2295762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035184, endtime: 41035492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,2295828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035187, endtime: 41035492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,2295884</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035189, endtime: 41035492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,2296158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035191, endtime: 41035492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,2296216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035192, endtime: 41035492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,2296283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035194, endtime: 41035492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,2296338</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035195, endtime: 41035492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,6765598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,6765717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:22,6769048</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41035536, endtime: 41035536, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:23,7584343</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035251, endtime: 41035644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:23,7584507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035253, endtime: 41035644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:23,7584590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035255, endtime: 41035644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:23,7584654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035256, endtime: 41035644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:23,7584720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035259, endtime: 41035644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:23,7584775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035261, endtime: 41035644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:23,7584842</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035262, endtime: 41035644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:23,7584897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035266, endtime: 41035644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:23,7584967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035267, endtime: 41035644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:23,7585753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035269, endtime: 41035644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:23,7585834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035270, endtime: 41035644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:23,7585889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035272, endtime: 41035644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:23,7592303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035275, endtime: 41035645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:25,1559804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56007 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:25,1559892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56008 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:25,1873598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55998 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:27,2145716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035644, endtime: 41035990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:27,2145896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035645, endtime: 41035990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:27,2145974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035648, endtime: 41035990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:27,2146054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035651, endtime: 41035990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:27,2146115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035653, endtime: 41035990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:27,2146187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035655, endtime: 41035990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:27,2146248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035656, endtime: 41035990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:27,2146320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035659, endtime: 41035990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:27,2146379</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035661, endtime: 41035990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:27,2147176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035663, endtime: 41035990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:27,2147260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035666, endtime: 41035990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:27,2147332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035667, endtime: 41035990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:27,2150593</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035669, endtime: 41035990, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:28,5633714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035369, endtime: 41036125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:28,5633874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035370, endtime: 41036125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:28,5633963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035372, endtime: 41036125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:28,5634157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035375, endtime: 41036125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:28,5634237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035376, endtime: 41036125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:28,5634298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035378, endtime: 41036125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:28,5634370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035379, endtime: 41036125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:28,5634428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035381, endtime: 41036125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:28,5634500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035383, endtime: 41036125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:28,5635279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035384, endtime: 41036125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:28,5635359</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035386, endtime: 41036125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:28,5635415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035389, endtime: 41036125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:28,5636523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035390, endtime: 41036125, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:29,3188151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56013 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,1720635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56007 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,1720721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56008 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,4642706</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035990, endtime: 41036415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,4642994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035992, endtime: 41036415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,4643111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035994, endtime: 41036415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,4643194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035995, endtime: 41036415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,4643258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035997, endtime: 41036415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,4643332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035998, endtime: 41036415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,4643393</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036000, endtime: 41036415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,4643468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036003, endtime: 41036415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,4643529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036005, endtime: 41036415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,4644344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036006, endtime: 41036415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,4644416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036008, endtime: 41036415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,4644485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036009, endtime: 41036415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:31,4645250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036011, endtime: 41036415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:32,7948464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:32,7948636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:32,7952335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41036548, endtime: 41036548, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:34,1747648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036125, endtime: 41036686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:34,1747828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036126, endtime: 41036686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:34,1747900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036128, endtime: 41036686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:34,1747972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036130, endtime: 41036686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:34,1748030</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036131, endtime: 41036686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:34,1748094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036133, endtime: 41036686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:34,1748149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036134, endtime: 41036686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:34,1748216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036136, endtime: 41036686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:34,1748271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036137, endtime: 41036686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:34,1748573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036139, endtime: 41036686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:34,1748631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036141, endtime: 41036686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:34,1748698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036142, endtime: 41036686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:34,1748753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036144, endtime: 41036686, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,2974579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56017 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,2974660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56018 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,3276116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56013 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,4582776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035492, endtime: 41036814, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,4582942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035494, endtime: 41036814, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,4583034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035497, endtime: 41036814, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,4583267</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035500, endtime: 41036814, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,4583397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035503, endtime: 41036814, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,4583502</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035506, endtime: 41036814, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,4583624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035510, endtime: 41036814, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,4583721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035513, endtime: 41036814, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,4583799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035514, endtime: 41036814, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,4584563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035517, endtime: 41036814, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,4584657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035519, endtime: 41036814, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,4584718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035520, endtime: 41036814, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,4585680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41035522, endtime: 41036814, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:35,5628890</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56019 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:36,5389278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036415, endtime: 41036923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:36,5389497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036417, endtime: 41036923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:36,5389599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036420, endtime: 41036923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:36,5389666</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036422, endtime: 41036923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:36,5389743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036423, endtime: 41036923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:36,5389804</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036425, endtime: 41036923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:36,5389879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036428, endtime: 41036923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:36,5389937</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036429, endtime: 41036923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:36,5390009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036431, endtime: 41036923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:36,5390702</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036433, endtime: 41036923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:36,5390788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036436, endtime: 41036923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:36,5390843</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036437, endtime: 41036923, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:37,0972916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036440, endtime: 41036978, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:38,9722662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036686, endtime: 41037166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:38,9722853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036687, endtime: 41037166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:38,9722936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036689, endtime: 41037166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:38,9723016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036690, endtime: 41037166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:38,9723080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036692, endtime: 41037166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:38,9723149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036694, endtime: 41037166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:38,9723210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036697, endtime: 41037166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:38,9723280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036698, endtime: 41037166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:38,9723341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036700, endtime: 41037166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:38,9724094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036701, endtime: 41037166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:38,9724172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036703, endtime: 41037166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:38,9724244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036705, endtime: 41037166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:38,9725252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036706, endtime: 41037166, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:39,4213172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56025 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:40,5444166</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036923, endtime: 41037323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:40,5444296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036923, endtime: 41037323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:40,5444368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036925, endtime: 41037323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:40,5444440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036926, endtime: 41037323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:40,5444498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036928, endtime: 41037323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:40,5444565</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036930, endtime: 41037323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:40,5444620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036931, endtime: 41037323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:40,5444686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036933, endtime: 41037323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:40,5444742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036934, endtime: 41037323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:40,5445019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036936, endtime: 41037323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:40,5445077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036937, endtime: 41037323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:40,5445144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036940, endtime: 41037323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:40,5445199</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41036978, endtime: 41037323, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:41,3271969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56017 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:41,3272052</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56018 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:41,5623881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56019 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,4827572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037166, endtime: 41037517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,4827746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037167, endtime: 41037517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,4827824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037170, endtime: 41037517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,4827902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037172, endtime: 41037517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,4827965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037173, endtime: 41037517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,4828037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037174, endtime: 41037517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,4828098</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037176, endtime: 41037517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,4828168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037178, endtime: 41037517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,4828223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037180, endtime: 41037517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,4829004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037183, endtime: 41037517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,4829079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037184, endtime: 41037517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,4829151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037186, endtime: 41037517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,4831428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037188, endtime: 41037517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9095526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9095640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9099496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41037560, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9130363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037323, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9130485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037326, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9130560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037328, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9130632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037330, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9130690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037331, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9130756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037333, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9130809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037334, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9130876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037336, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9130931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037337, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9131640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037339, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9131710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037341, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9131776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037342, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:42,9132616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037344, endtime: 41037560, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:45,4367218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:45,4367304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:45,4367329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56025 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:45,7335710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56037 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:47,3098479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037517, endtime: 41038000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:47,3098665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037519, endtime: 41038000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:47,3098745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037520, endtime: 41038000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:47,3098825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037522, endtime: 41038000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:47,3098889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037523, endtime: 41038000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:47,3098964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037525, endtime: 41038000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:47,3099025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037526, endtime: 41038000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:47,3099100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037528, endtime: 41038000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:47,3099160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037531, endtime: 41038000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:47,3099961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037533, endtime: 41038000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:47,3100044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037534, endtime: 41038000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:47,3120519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037536, endtime: 41038000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:47,3120627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037539, endtime: 41038000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,3678828</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037560, endtime: 41038205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,3678994</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037561, endtime: 41038205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,3679080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037564, endtime: 41038205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,3679147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037566, endtime: 41038205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,3679219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037567, endtime: 41038205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,3679277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037569, endtime: 41038205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,3679346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037570, endtime: 41038205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,3679402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037572, endtime: 41038205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,3679468</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037575, endtime: 41038205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,3680139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037576, endtime: 41038205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,3680225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037579, endtime: 41038205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,3680280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41037580, endtime: 41038205, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,4530318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55915 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,5310137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,5463072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,5469001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038223, endtime: 41038223, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,5632539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038225, endtime: 41038225, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,5917563</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,5921001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038228, endtime: 41038228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,5941556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038228, endtime: 41038228, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,6113320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038230, endtime: 41038230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,6114605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038230, endtime: 41038230, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,6253757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038231, endtime: 41038231, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,6254422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038231, endtime: 41038231, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,6411471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038233, endtime: 41038233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,6412754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038233, endtime: 41038233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,6565483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038234, endtime: 41038234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,6566110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038234, endtime: 41038234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,6724785</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038236, endtime: 41038236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,6726010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038236, endtime: 41038236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,6879050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038237, endtime: 41038237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,6880585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038237, endtime: 41038237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,7110962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038239, endtime: 41038240, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,7112342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038239, endtime: 41038240, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,7349200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038242, endtime: 41038242, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,7350610</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038242, endtime: 41038242, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,7513772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038244, endtime: 41038244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,7515035</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038244, endtime: 41038244, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,7663216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038245, endtime: 41038245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,7664573</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038245, endtime: 41038245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,7846302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038247, endtime: 41038247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,7850519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038247, endtime: 41038247, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,7991272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038248, endtime: 41038249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,7992164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038248, endtime: 41038249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,8131091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038250, endtime: 41038250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,8132479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038250, endtime: 41038250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,8458325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038253, endtime: 41038253, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,8459400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038253, endtime: 41038253, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,8602796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038255, endtime: 41038255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,8603397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038255, endtime: 41038255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,8757562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038256, endtime: 41038256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,8758474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038256, endtime: 41038256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,8983318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038258, endtime: 41038258, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,8984404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038258, endtime: 41038258, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,9070558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038259, endtime: 41038259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,9076146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038259, endtime: 41038259, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,9238362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038261, endtime: 41038261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,9239482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038261, endtime: 41038261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,9385643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038262, endtime: 41038262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,9386898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038262, endtime: 41038262, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,9547668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038264, endtime: 41038264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,9550397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038264, endtime: 41038264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,9698899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038265, endtime: 41038266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,9700461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038265, endtime: 41038266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,9845475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038267, endtime: 41038267, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:49,9846290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038267, endtime: 41038267, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,0069145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038269, endtime: 41038269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,0070423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038269, endtime: 41038269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,0158116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038270, endtime: 41038270, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,0359212</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038272, endtime: 41038272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,0471600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038273, endtime: 41038273, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,0550810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038274, endtime: 41038274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,0788100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038276, endtime: 41038276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,0939550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038278, endtime: 41038278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,1101146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038279, endtime: 41038280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,1261786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038281, endtime: 41038281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,1416070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038283, endtime: 41038283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,1685366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55992 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,1735942</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038286, endtime: 41038286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,1886575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038287, endtime: 41038287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,2194143</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038290, endtime: 41038291, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,2343005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038292, endtime: 41038292, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,2510599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038294, endtime: 41038294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,2664922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038295, endtime: 41038295, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,2838124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038297, endtime: 41038297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,3232571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038300, endtime: 41038301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,8807008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038000, endtime: 41038357, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,8807208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038000, endtime: 41038357, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,8807294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038003, endtime: 41038357, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,8807377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038004, endtime: 41038357, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,8807443</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038006, endtime: 41038357, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,8807515</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038008, endtime: 41038357, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,8807576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038011, endtime: 41038357, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,8807648</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038013, endtime: 41038357, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,8807709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038014, endtime: 41038357, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,8808003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038016, endtime: 41038357, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,8808067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038017, endtime: 41038357, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,8808136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038019, endtime: 41038357, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:50,8808197</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038020, endtime: 41038357, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,4377616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,4377699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,4957542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,4963365</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038418, endtime: 41038418, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,5169099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038420, endtime: 41038420, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,5385247</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,5391988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038422, endtime: 41038423, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,5484225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038423, endtime: 41038423, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,5556307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038423, endtime: 41038424, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,5780417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038426, endtime: 41038426, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,5797617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038426, endtime: 41038427, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,5946147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038428, endtime: 41038428, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,5949170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038428, endtime: 41038428, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,6258314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038431, endtime: 41038431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,6259342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038431, endtime: 41038431, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,6564447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038434, endtime: 41038434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,6565569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038434, endtime: 41038434, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,6729936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038436, endtime: 41038436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,6732504</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038436, endtime: 41038436, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,6896732</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038437, endtime: 41038438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,6898258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038437, endtime: 41038438, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,7199892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038441, endtime: 41038441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,7200748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038441, endtime: 41038441, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,7345435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56037 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,7376294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038442, endtime: 41038442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,7377867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038442, endtime: 41038442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,7785079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038445, endtime: 41038446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,7786278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038445, endtime: 41038446, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,7976220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038448, endtime: 41038448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,7977486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038448, endtime: 41038448, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8125024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038450, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8126672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038450, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8168231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038303, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8168408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038305, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8168483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038308, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8168555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038309, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8168613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038311, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8168682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038312, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8168738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038314, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8168810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038315, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8168865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038317, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8169161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038319, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8169220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038322, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8169286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038325, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8169342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038326, endtime: 41038450, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8291609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038451, endtime: 41038452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8292701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038451, endtime: 41038452, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8449517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038453, endtime: 41038453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8450855</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038453, endtime: 41038453, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8765278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038456, endtime: 41038456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8766447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038456, endtime: 41038456, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8907898</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038458, endtime: 41038458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,8909480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038458, endtime: 41038458, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,9074218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038459, endtime: 41038459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,9075243</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038459, endtime: 41038459, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,9392743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038462, endtime: 41038463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,9393910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038462, endtime: 41038463, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,9542927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038464, endtime: 41038464, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,9546601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038464, endtime: 41038464, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,9932557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038467, endtime: 41038468, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:51,9933754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038467, endtime: 41038468, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:52,0021519</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038469, endtime: 41038469, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:52,0022581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038469, endtime: 41038469, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:52,0343913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038472, endtime: 41038472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:52,0348160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038472, endtime: 41038472, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:52,0657704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038475, endtime: 41038475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:52,0658748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038475, endtime: 41038475, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:52,0738554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038476, endtime: 41038476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:52,6314978</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038450, endtime: 41038532, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:53,1831892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:53,1832034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:53,1835455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41038587, endtime: 41038587, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:54,6862670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038451, endtime: 41038737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:54,6862845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038453, endtime: 41038737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:54,6862936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038456, endtime: 41038737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:54,6863006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038458, endtime: 41038737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:54,6863083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038459, endtime: 41038737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:54,6863147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038463, endtime: 41038737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:54,6863222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038464, endtime: 41038737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:54,6863283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038468, endtime: 41038737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:54,6863355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038469, endtime: 41038737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:54,6864103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038472, endtime: 41038737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:54,6864194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038475, endtime: 41038737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:54,6864258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038476, endtime: 41038737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:54,6868968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038532, endtime: 41038737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,6598506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038357, endtime: 41038835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,6598678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038358, endtime: 41038835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,6598750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038359, endtime: 41038835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,6598824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038361, endtime: 41038835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,6598883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038362, endtime: 41038835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,6598952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038364, endtime: 41038835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,6599007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038365, endtime: 41038835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,6599074</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038367, endtime: 41038835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,6599126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038369, endtime: 41038835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,6599412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038370, endtime: 41038835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,6599470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038373, endtime: 41038835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,6599536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038374, endtime: 41038835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,6599592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038376, endtime: 41038835, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:55,8433412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56044 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:58,8948492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038737, endtime: 41039158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:58,8948742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038739, endtime: 41039158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:58,8948830</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038740, endtime: 41039158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:58,8948922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038742, endtime: 41039158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:58,8948991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038745, endtime: 41039158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:58,8949069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038747, endtime: 41039158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:58,8949135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038749, endtime: 41039158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:58,8949213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038750, endtime: 41039158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:58,8949274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038751, endtime: 41039158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:58,8949933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038753, endtime: 41039158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:58,8950011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038755, endtime: 41039158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:58,8950083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038756, endtime: 41039158, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,1179223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038758, endtime: 41039180, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,2008092</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56039 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,9564394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038835, endtime: 41039264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,9564587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038837, endtime: 41039264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,9564668</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038839, endtime: 41039264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,9564748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038840, endtime: 41039264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,9564812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038842, endtime: 41039264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,9565006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038846, endtime: 41039264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,9565097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038847, endtime: 41039264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,9565175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038849, endtime: 41039264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,9565239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038852, endtime: 41039264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,9565582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038853, endtime: 41039264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,9565643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038855, endtime: 41039264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,9565712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038856, endtime: 41039264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:08:59,9565771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41038858, endtime: 41039264, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:01,0979973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56036 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:01,1401295</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56035 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:01,8436512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56044 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:02,2027394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56049 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,2277157</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,2277282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,2281222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41039591, endtime: 41039591, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,6927906</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039158, endtime: 41039638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,6928094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039159, endtime: 41039638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,6928286</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039161, endtime: 41039638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,6928369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039164, endtime: 41039638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,6928446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039168, endtime: 41039638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,6928510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039170, endtime: 41039638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,6928582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039175, endtime: 41039638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,6928643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039178, endtime: 41039638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,6928718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039179, endtime: 41039638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,6929463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039181, endtime: 41039638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,6959424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039183, endtime: 41039638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,6959540</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039185, endtime: 41039638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:03,6969024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039187, endtime: 41039638, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:04,1242760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56051 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:04,1565370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56052 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,7234953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039264, endtime: 41039841, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,7235139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039265, endtime: 41039841, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,7235214</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039267, endtime: 41039841, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,7235291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039269, endtime: 41039841, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,7235347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039272, endtime: 41039841, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,7235416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039273, endtime: 41039841, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,7235474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039274, endtime: 41039841, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,7235541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039277, endtime: 41039841, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,7235596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039278, endtime: 41039841, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,7235887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039280, endtime: 41039841, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,7235945</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039283, endtime: 41039841, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,7236015</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039284, endtime: 41039841, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,7236070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039286, endtime: 41039841, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:05,9685874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,0301063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,0303981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039872, endtime: 41039872, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,0472229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039873, endtime: 41039873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,0538725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039874, endtime: 41039874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,0785122</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039876, endtime: 41039876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,0939079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039878, endtime: 41039878, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,1095477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039880, endtime: 41039880, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,1251537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039881, endtime: 41039881, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,1490681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039883, endtime: 41039884, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,1593150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039884, endtime: 41039885, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,1742655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039886, endtime: 41039886, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,2035260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039889, endtime: 41039889, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,2189585</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039890, endtime: 41039891, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,2350982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039892, endtime: 41039892, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,2517720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039894, endtime: 41039894, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,2675195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039895, endtime: 41039895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,2827931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039897, endtime: 41039897, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,3152003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039900, endtime: 41039900, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,3449085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039903, endtime: 41039903, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,3597227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039905, endtime: 41039905, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,3752389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039906, endtime: 41039906, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,3943849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039908, endtime: 41039908, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,4088744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039909, endtime: 41039909, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,4457062</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039912, endtime: 41039913, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,4533097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039914, endtime: 41039914, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,4714026</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039915, endtime: 41039916, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,8645316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039917, endtime: 41039955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,8645509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039919, endtime: 41039955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,8645587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039920, endtime: 41039955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,8645770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039922, endtime: 41039955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,8645850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039923, endtime: 41039955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,8645925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039925, endtime: 41039955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,8645983</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039928, endtime: 41039955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,8646058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039930, endtime: 41039955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,8646119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039931, endtime: 41039955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,8646449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039934, endtime: 41039955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,8646510</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039936, endtime: 41039955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,8646579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039938, endtime: 41039955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:06,8646634</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039941, endtime: 41039955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:07,4825929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039638, endtime: 41040017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:07,4826292</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039639, endtime: 41040017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:07,4826381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039640, endtime: 41040017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:07,4826466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039642, endtime: 41040017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:07,4826536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039644, endtime: 41040017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:07,4826613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039645, endtime: 41040017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:07,4826680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039647, endtime: 41040017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:07,4826757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039648, endtime: 41040017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:07,4826821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039651, endtime: 41040017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:07,4827611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039653, endtime: 41040017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:07,4827683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039655, endtime: 41040017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:07,4827752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039656, endtime: 41040017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:07,4833282</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039658, endtime: 41040017, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:08,2029458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56049 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,1255596</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56051 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,1782626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56052 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,2924513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039841, endtime: 41040298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,2924712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039842, endtime: 41040298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,2924795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039844, endtime: 41040298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,2924881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039845, endtime: 41040298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,2924948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039848, endtime: 41040298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,2925020</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039850, endtime: 41040298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,2925083</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039851, endtime: 41040298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,2925155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039853, endtime: 41040298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,2925216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039855, endtime: 41040298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,2925560</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039856, endtime: 41040298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,2925624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039858, endtime: 41040298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,2925696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039859, endtime: 41040298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:10,2925757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039861, endtime: 41040298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:11,2435093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040017, endtime: 41040393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:11,2435268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040019, endtime: 41040393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:11,2435342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040020, endtime: 41040393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:11,2435417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040022, endtime: 41040393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:11,2435475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040023, endtime: 41040393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:11,2435545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040027, endtime: 41040393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:11,2435600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040028, endtime: 41040393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:11,2435667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040030, endtime: 41040393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:11,2435722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040031, endtime: 41040393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:11,2436722</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040033, endtime: 41040393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:11,2436797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040035, endtime: 41040393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:11,2436866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040037, endtime: 41040393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:11,2437664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040039, endtime: 41040393, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,3128576</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56064 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,9379664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040393, endtime: 41040562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,9379852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040394, endtime: 41040562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,9379927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040395, endtime: 41040562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,9380004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040397, endtime: 41040562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,9380063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040398, endtime: 41040562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,9380135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040400, endtime: 41040562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,9380190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040400, endtime: 41040562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,9380259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040403, endtime: 41040562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,9380315</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040404, endtime: 41040562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,9380625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040404, endtime: 41040562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,9380683</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040405, endtime: 41040562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,9380750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040408, endtime: 41040562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:12,9380805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040411, endtime: 41040562, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:13,3268057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:13,3268201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:13,3272387</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41040601, endtime: 41040601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,2341559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,2653815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,2973416</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,2986501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040698, endtime: 41040698, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,3127703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040700, endtime: 41040700, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,3186846</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040700, endtime: 41040700, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,3437956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040703, endtime: 41040703, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,3592611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040704, endtime: 41040705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,3676905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,3680177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040705, endtime: 41040705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,3751270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040706, endtime: 41040706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,3753769</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040706, endtime: 41040706, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,3905369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040708, endtime: 41040708, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,3907549</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040708, endtime: 41040708, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,4063523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040709, endtime: 41040709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,4064584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040709, endtime: 41040709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,4217780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040711, endtime: 41040711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,4218533</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040711, endtime: 41040711, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,4371743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040712, endtime: 41040712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,4374671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040712, endtime: 41040712, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,4528606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040714, endtime: 41040714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,4533272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040714, endtime: 41040714, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,4695109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040716, endtime: 41040716, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,4698674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040716, endtime: 41040716, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,5038822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040719, endtime: 41040719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,5071974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040719, endtime: 41040719, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,5431654</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040722, endtime: 41040723, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,5432651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040722, endtime: 41040723, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,5783623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040726, endtime: 41040726, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,5789544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040726, endtime: 41040727, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,5947696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040728, endtime: 41040728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,5948660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040728, endtime: 41040728, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6249429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040731, endtime: 41040731, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6251809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040731, endtime: 41040731, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6431798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040733, endtime: 41040733, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6432513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040733, endtime: 41040733, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6649947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040298, endtime: 41040735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6650155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040300, endtime: 41040735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6650246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040300, endtime: 41040735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6650329</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040303, endtime: 41040735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6650390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040305, endtime: 41040735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6650462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040306, endtime: 41040735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6650520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040309, endtime: 41040735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6650592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040311, endtime: 41040735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6650653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040314, endtime: 41040735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6650969</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040316, endtime: 41040735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6651027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040318, endtime: 41040735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6651094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040319, endtime: 41040735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6651149</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040320, endtime: 41040735, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6734557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040736, endtime: 41040736, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6738103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040736, endtime: 41040736, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6876171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040737, endtime: 41040737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,6877055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040737, endtime: 41040737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,7043909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040739, endtime: 41040739, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,7044862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040739, endtime: 41040739, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,7360928</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040742, endtime: 41040742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,7361809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040742, endtime: 41040742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,7513470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040744, endtime: 41040744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,7514478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040744, endtime: 41040744, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,7669773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040745, endtime: 41040745, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,7670544</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040745, endtime: 41040745, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,7831715</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040747, endtime: 41040747, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,7834420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040747, endtime: 41040747, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,8004806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040748, endtime: 41040749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,8006178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040748, endtime: 41040749, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,8135499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040750, endtime: 41040750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,8136535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040750, endtime: 41040750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,8288697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040751, endtime: 41040751, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:14,8445475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040753, endtime: 41040753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:15,2399422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040751, endtime: 41040793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:15,2399597</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040753, endtime: 41040793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:15,2399674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040755, endtime: 41040793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:15,2399757</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040756, endtime: 41040793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:15,2399821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040758, endtime: 41040793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:15,2399896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040759, endtime: 41040793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:15,2399957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040761, endtime: 41040793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:15,2400029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040763, endtime: 41040793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:15,2400090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040766, endtime: 41040793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:15,2400381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040767, endtime: 41040793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:15,2400447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040770, endtime: 41040793, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,1369408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040772, endtime: 41040882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,1369591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040773, endtime: 41040882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,1369688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040793, endtime: 41040882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,1369760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040794, endtime: 41040882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,1369840</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040795, endtime: 41040882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,1369907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040798, endtime: 41040882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,1369984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040800, endtime: 41040882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,1370087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040800, endtime: 41040882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,1370173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040803, endtime: 41040882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,1370472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040805, endtime: 41040882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,1370547</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040808, endtime: 41040882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,1370605</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040809, endtime: 41040882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,1370677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040813, endtime: 41040882, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,5204119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040562, endtime: 41040921, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,5204285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040564, endtime: 41040921, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,5204357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040566, endtime: 41040921, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,5204429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040569, endtime: 41040921, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,5204487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040572, endtime: 41040921, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,5204556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040573, endtime: 41040921, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,5204609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040574, endtime: 41040921, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,5204781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040577, endtime: 41040921, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,5204850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040578, endtime: 41040921, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,5205144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040580, endtime: 41040921, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,5205202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040583, endtime: 41040921, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,5205268</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040584, endtime: 41040921, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:16,5205324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040587, endtime: 41040921, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:17,5920868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039955, endtime: 41041028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:17,5921040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039956, endtime: 41041028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:17,5921134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039958, endtime: 41041028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:17,5921201</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039959, endtime: 41041028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:17,5921273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039961, endtime: 41041028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:17,5921331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039964, endtime: 41041028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:17,5921403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039965, endtime: 41041028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:17,5921461</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039967, endtime: 41041028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:17,5921530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039969, endtime: 41041028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:17,5921927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039972, endtime: 41041028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:17,5922024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039973, endtime: 41041028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:17,5922090</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039974, endtime: 41041028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:17,5922173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41039977, endtime: 41041028, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,1991646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040921, endtime: 41041089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,1991837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040923, endtime: 41041089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,1991917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040925, endtime: 41041089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,1991997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040928, endtime: 41041089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,1992058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040930, endtime: 41041089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,1992130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040931, endtime: 41041089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,1992186</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040933, endtime: 41041089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,1992258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040934, endtime: 41041089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,1992319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040936, endtime: 41041089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,1992837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040938, endtime: 41041089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,1992912</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040939, endtime: 41041089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,1992981</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040941, endtime: 41041089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,1993042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040942, endtime: 41041089, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:18,3135006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56064 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:19,4366182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040735, endtime: 41041212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:19,4366362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040736, endtime: 41041212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:19,4366437</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040737, endtime: 41041212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:19,4366512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040739, endtime: 41041212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:19,4366567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040742, endtime: 41041212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:19,4366636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040744, endtime: 41041212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:19,4366692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040745, endtime: 41041212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:19,4366761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040747, endtime: 41041212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:19,4366817</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040748, endtime: 41041212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:19,4367146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040750, endtime: 41041212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:19,4367204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040751, endtime: 41041212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:19,4367271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040753, endtime: 41041212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:19,4367324</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040755, endtime: 41041212, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1249279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56069 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1841927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041089, endtime: 41041287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1842124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041090, endtime: 41041287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1842202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041094, endtime: 41041287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1842279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041095, endtime: 41041287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1842340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041097, endtime: 41041287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1842407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041099, endtime: 41041287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1842465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041100, endtime: 41041287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1842534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041100, endtime: 41041287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1842589</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041103, endtime: 41041287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1842875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041105, endtime: 41041287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1842933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041106, endtime: 41041287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1842999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041108, endtime: 41041287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:20,1843058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041109, endtime: 41041287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:21,7809446</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041287, endtime: 41041447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:21,7809775</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041289, endtime: 41041447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:21,7809897</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041291, endtime: 41041447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:21,7810016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041292, endtime: 41041447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:21,7810102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041294, endtime: 41041447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:21,7810216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041295, endtime: 41041447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:21,7810316</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041297, endtime: 41041447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:21,7810427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041298, endtime: 41041447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:21,7810523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041301, endtime: 41041447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:21,7811236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041305, endtime: 41041447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:21,7811344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041306, endtime: 41041447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:21,7811449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041308, endtime: 41041447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:21,7811546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041309, endtime: 41041447, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,2112226</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041212, endtime: 41041490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,2112400</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041214, endtime: 41041490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,2112481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041216, endtime: 41041490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,2112558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041219, endtime: 41041490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,2112619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041222, endtime: 41041490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,2112691</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041223, endtime: 41041490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,2112750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041225, endtime: 41041490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,2112819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041227, endtime: 41041490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,2112874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041230, endtime: 41041490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,2113187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041231, endtime: 41041490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,2113373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041233, endtime: 41041490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,2113517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041236, endtime: 41041490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,2113622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041237, endtime: 41041490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:22,4218206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56072 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:23,5513649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:23,5513773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:23,5517616</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41041624, endtime: 41041624, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:23,9703700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56067 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,5507866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:55925 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,6798033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,6801217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041737, endtime: 41041737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,6868433</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041737, endtime: 41041737, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,7029918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041739, endtime: 41041739, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,7184258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041740, endtime: 41041740, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,7349297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041742, endtime: 41041742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,7654269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041745, endtime: 41041745, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,7820966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041747, endtime: 41041747, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,7977051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041748, endtime: 41041748, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,8281408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041751, endtime: 41041751, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,8451567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041753, endtime: 41041753, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,8605810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041755, endtime: 41041755, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,8910378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041758, endtime: 41041758, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,9071641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041759, endtime: 41041759, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,9237345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041761, endtime: 41041761, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,9378168</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041762, endtime: 41041762, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,9576385</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041764, endtime: 41041764, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,9695943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041765, endtime: 41041766, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:24,9848254</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041767, endtime: 41041767, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,0082283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041769, endtime: 41041769, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,0160117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041770, endtime: 41041770, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,0487907</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041773, endtime: 41041773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,0548283</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041774, endtime: 41041774, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,0828595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041776, endtime: 41041777, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,0952760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041778, endtime: 41041778, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,1102609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041780, endtime: 41041780, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,1273669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041781, endtime: 41041781, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,2837210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041784, endtime: 41041797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,2837392</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041786, endtime: 41041797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,2837475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041787, endtime: 41041797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,2837553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041790, endtime: 41041797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,2837617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041792, endtime: 41041797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,2837686</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041794, endtime: 41041797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,2837744</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041795, endtime: 41041797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,2837816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041797, endtime: 41041797, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,3049473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041798, endtime: 41041799, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,3125708</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041800, endtime: 41041800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,3183621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041800, endtime: 41041800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,3466866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041803, endtime: 41041803, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,3684918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041805, endtime: 41041805, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,8811017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041447, endtime: 41041857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,8811217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041448, endtime: 41041857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,8811297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041450, endtime: 41041857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,8811377</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041451, endtime: 41041857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,8811441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041453, endtime: 41041857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,8811513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041455, endtime: 41041857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,8811571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041456, endtime: 41041857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,8811646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041458, endtime: 41041857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,8811704</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041459, endtime: 41041857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,8812156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041461, endtime: 41041857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,8812231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041462, endtime: 41041857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,8812303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041464, endtime: 41041857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:25,8812364</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041465, endtime: 41041857, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:26,1401777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56069 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:26,9837308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56074 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:28,4221509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56072 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:29,4381703</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56079 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,2346396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56080 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,3288764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041806, endtime: 41042301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,3288958</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041808, endtime: 41042301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,3289038</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041809, endtime: 41042301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,3289116</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041811, endtime: 41042301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,3289179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041812, endtime: 41042301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,3289249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041814, endtime: 41042301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,3289307</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041816, endtime: 41042301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,3289376</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041819, endtime: 41042301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,3289434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041820, endtime: 41042301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,3289736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041822, endtime: 41042302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,3289797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041823, endtime: 41042302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,3289866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041825, endtime: 41042302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,3289925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041826, endtime: 41042302, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:30,5670473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56054 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:31,1798213</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041857, endtime: 41042387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:31,1798396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041858, endtime: 41042387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:31,1798485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041859, endtime: 41042387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:31,1798551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041862, endtime: 41042387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:31,1798626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041864, endtime: 41042387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:31,1798684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041865, endtime: 41042387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:31,1798759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041867, endtime: 41042387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:31,1798820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041869, endtime: 41042387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:31,1798889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041872, endtime: 41042387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:31,1799180</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041873, endtime: 41042387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:31,1799255</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041874, endtime: 41042387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:31,1799310</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041875, endtime: 41042387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:31,1799382</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41041878, endtime: 41042387, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:32,5308095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56082 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:32,9843874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56074 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:33,7109779</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:33,7109899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:33,7113619</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41042640, endtime: 41042640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:34,3652876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042302, endtime: 41042705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:34,3653037</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042305, endtime: 41042705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:34,3653112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042308, endtime: 41042705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:34,3653192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042309, endtime: 41042705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:34,3653250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042311, endtime: 41042705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:34,3653320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042315, endtime: 41042705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:34,3653378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042317, endtime: 41042705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:34,3653442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042320, endtime: 41042705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:34,3653500</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042323, endtime: 41042705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:34,3653796</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042325, endtime: 41042705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:34,3653857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042326, endtime: 41042705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:34,3653924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042328, endtime: 41042705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:34,3653979</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042330, endtime: 41042705, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:35,4528099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56079 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:36,2344396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56080 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,0935023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56088 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,1698481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040882, endtime: 41042986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,1698639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040884, endtime: 41042986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,1698714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040886, endtime: 41042986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,1698786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040887, endtime: 41042986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,1698844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040889, endtime: 41042986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,1698911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040892, endtime: 41042986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,1699781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040896, endtime: 41042986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,1699867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040897, endtime: 41042986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,1699922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040900, endtime: 41042986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,1699991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040901, endtime: 41042986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,1700044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040903, endtime: 41042986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,1700113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040906, endtime: 41042986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,1700169</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41040908, endtime: 41042986, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,8276917</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042705, endtime: 41043051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,8277111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042708, endtime: 41043051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,8277191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042709, endtime: 41043051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,8277271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042711, endtime: 41043051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,8277335</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042715, endtime: 41043051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,8277404</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042717, endtime: 41043051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,8277463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042720, endtime: 41043051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,8277532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042722, endtime: 41043051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,8277590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042723, endtime: 41043051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,8277923</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042727, endtime: 41043051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,8277984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042729, endtime: 41043051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,8278050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042731, endtime: 41043051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:37,8278111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042734, endtime: 41043051, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:38,5313093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56082 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,0776342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042387, endtime: 41043176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,0776517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042387, endtime: 41043176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,0776586</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042389, endtime: 41043176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,0776658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042390, endtime: 41043176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,0776710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042392, endtime: 41043176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,0776777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042394, endtime: 41043176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,0776827</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042395, endtime: 41043176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,0776891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042397, endtime: 41043176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,0776943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042398, endtime: 41043176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,0777229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042400, endtime: 41043176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,0777287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042400, endtime: 41043176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,0777350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042403, endtime: 41043176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,0777403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41042405, endtime: 41043176, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,5619850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,6414765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,6418588</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043233, endtime: 41043233, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,6562156</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043234, endtime: 41043234, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,6718136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043236, endtime: 41043236, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,6872284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043237, endtime: 41043237, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,7030738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043239, endtime: 41043239, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,7194608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043240, endtime: 41043241, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,7353290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043242, endtime: 41043242, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,7659927</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043245, endtime: 41043245, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,8015647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043249, endtime: 41043249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,8125032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043250, endtime: 41043250, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,8294773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043251, endtime: 41043252, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,8596218</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043254, endtime: 41043255, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,8773604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043256, endtime: 41043256, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,9089176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043259, endtime: 41043260, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,9400997</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043262, endtime: 41043263, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:39,9717932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043265, endtime: 41043266, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,0028595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043269, endtime: 41043269, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,0159909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043270, endtime: 41043270, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,0384956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043272, endtime: 41043272, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,0468965</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043273, endtime: 41043273, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,0549982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043274, endtime: 41043274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,0783407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043276, endtime: 41043276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,0955284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043278, endtime: 41043278, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,1114068</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043280, endtime: 41043280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,1486290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043283, endtime: 41043283, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,1721322</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043286, endtime: 41043286, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,1879454</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043287, endtime: 41043287, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,2048301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043289, endtime: 41043289, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,2394413</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043292, endtime: 41043293, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,2518445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043294, endtime: 41043294, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,2826352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043297, endtime: 41043297, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,2985127</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043298, endtime: 41043298, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,3136100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043300, endtime: 41043300, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,3201178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043301, endtime: 41043301, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,3431564</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56093 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,3454859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043303, endtime: 41043303, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,3597490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043304, endtime: 41043305, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,3752326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043306, endtime: 41043306, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,3921205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043308, endtime: 41043308, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,4074966</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043309, endtime: 41043309, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,7181717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043051, endtime: 41043340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,7181911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043053, endtime: 41043340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,7181989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043055, endtime: 41043340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,7182063</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043056, endtime: 41043340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,7182124</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043058, endtime: 41043340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,7182194</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043059, endtime: 41043340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,7182252</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043061, endtime: 41043340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,7182318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043062, endtime: 41043340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,7182374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043064, endtime: 41043340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,7182678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043066, endtime: 41043340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,7182739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043067, endtime: 41043340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,7182806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043069, endtime: 41043340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:40,7182864</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043070, endtime: 41043340, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:41,1911430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043312, endtime: 41043388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:41,1911635</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043314, endtime: 41043388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:41,1911718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043316, endtime: 41043388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:41,1911798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043317, endtime: 41043388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:41,1911859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043319, endtime: 41043388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:41,1911931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043321, endtime: 41043388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:41,1911986</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043322, endtime: 41043388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:41,1912058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043323, endtime: 41043388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:41,1912117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043325, endtime: 41043388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:41,1961948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043326, endtime: 41043388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:41,1962111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043328, endtime: 41043388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:41,1962200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043330, endtime: 41043388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:41,1962269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043331, endtime: 41043388, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,1033444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043176, endtime: 41043479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,1033655</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043178, endtime: 41043479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,1033735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043180, endtime: 41043479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,1033813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043183, endtime: 41043479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,1033874</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043184, endtime: 41043479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,1033940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043186, endtime: 41043479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,1033999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043187, endtime: 41043479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,1034071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043189, endtime: 41043479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,1034126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043190, endtime: 41043479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,1034420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043192, endtime: 41043479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,1034481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043194, endtime: 41043479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,1034550</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043195, endtime: 41043479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,1034608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043197, endtime: 41043479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,6401289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56094 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,8534108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043340, endtime: 41043554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,8534291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043342, endtime: 41043554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,8534366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043345, endtime: 41043554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,8534440</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043347, endtime: 41043554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,8534499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043350, endtime: 41043554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,8534568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043351, endtime: 41043554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,8534621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043353, endtime: 41043554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,8534690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043356, endtime: 41043554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,8534742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043358, endtime: 41043554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,8535031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043361, endtime: 41043554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,8535089</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043364, endtime: 41043554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,8535155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043365, endtime: 41043554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,8535208</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043367, endtime: 41043554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:42,9254354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043554, endtime: 41043561, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,0940913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56088 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,3216837</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043479, endtime: 41043601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,3217042</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043480, endtime: 41043601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,3217120</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043481, endtime: 41043601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,3217200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043483, endtime: 41043601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,3217261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043484, endtime: 41043601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,3217330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043486, endtime: 41043601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,3217389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043487, endtime: 41043601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,3217458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043489, endtime: 41043601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,3217513</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043490, endtime: 41043601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,3217810</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043492, endtime: 41043601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,3217871</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043494, endtime: 41043601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,3217940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043495, endtime: 41043601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,3217995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043497, endtime: 41043601, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,8675803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,8675922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:43,8679712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41043655, endtime: 41043655, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2086302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043555, endtime: 41043789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2086465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043556, endtime: 41043789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2086548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043558, endtime: 41043789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2086612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043559, endtime: 41043789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2086681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043561, endtime: 41043789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2086739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043564, endtime: 41043789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2086812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043565, endtime: 41043789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2086867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043567, endtime: 41043789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2086939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043569, endtime: 41043789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2087598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043570, endtime: 41043789, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2107721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043572, endtime: 41043790, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2107868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043573, endtime: 41043790, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2911879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043574, endtime: 41043798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2912070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043789, endtime: 41043798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2912161</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043790, endtime: 41043798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2912225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043792, endtime: 41043798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2912300</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043794, endtime: 41043798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2912355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043795, endtime: 41043798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2912425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043797, endtime: 41043798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,2976776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043798, endtime: 41043798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,3139353</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043800, endtime: 41043800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,3191304</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043801, endtime: 41043801, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,3445190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043803, endtime: 41043803, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,3595215</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043804, endtime: 41043805, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:45,3751323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043806, endtime: 41043806, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,3432717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56093 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,7403390</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043808, endtime: 41043943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,7403592</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043811, endtime: 41043943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,7403675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043814, endtime: 41043943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,7403753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043816, endtime: 41043943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,7403814</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043817, endtime: 41043943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,7403886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043819, endtime: 41043943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,7403944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043820, endtime: 41043943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,7404013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043822, endtime: 41043943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,7404071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043823, endtime: 41043943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,7404373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043825, endtime: 41043943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,7404434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043827, endtime: 41043943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,7404503</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043828, endtime: 41043943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:46,7404562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043831, endtime: 41043943, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,2189356</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56097 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,5811545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043601, endtime: 41044027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,5811755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043603, endtime: 41044027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,5811838</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043606, endtime: 41044027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,5811922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043608, endtime: 41044027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,5811985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043611, endtime: 41044027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,5812057</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043612, endtime: 41044027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,5812115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043617, endtime: 41044027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,5812187</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043620, endtime: 41044027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,5812248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043624, endtime: 41044027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,5812537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043625, endtime: 41044027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,5812600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043627, endtime: 41044027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,5812672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043628, endtime: 41044027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:47,5812731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043631, endtime: 41044027, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:48,6558931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56094 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,0514374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044027, endtime: 41044274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,0514568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044028, endtime: 41044274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,0514646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044031, endtime: 41044274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,0514718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044033, endtime: 41044274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,0514776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044034, endtime: 41044274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,0514848</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044036, endtime: 41044274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,0514904</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044039, endtime: 41044274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,0514973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044040, endtime: 41044274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,0515028</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044042, endtime: 41044274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,0515571</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044046, endtime: 41044274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,0515638</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044048, endtime: 41044274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,0515713</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044050, endtime: 41044274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,0515771</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044053, endtime: 41044274, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1119240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043943, endtime: 41044280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1119415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043944, endtime: 41044280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1119490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043945, endtime: 41044280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1119567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043947, endtime: 41044280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1119625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043948, endtime: 41044280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1119695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043951, endtime: 41044280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1119750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043954, endtime: 41044280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1119819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043955, endtime: 41044280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1119875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043956, endtime: 41044280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1120279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043960, endtime: 41044280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1120354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043961, endtime: 41044280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1120429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043963, endtime: 41044280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1120490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043966, endtime: 41044280, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,1259572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044274, endtime: 41044281, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:50,4683287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56101 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:51,8601103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044280, endtime: 41044455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:51,8601294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044283, endtime: 41044455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:51,8601374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044287, endtime: 41044455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:51,8601455</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044288, endtime: 41044455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:51,8601518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044289, endtime: 41044455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:51,8601591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044291, endtime: 41044455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:51,8601649</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044292, endtime: 41044455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:51,8601718</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044294, endtime: 41044455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:51,8601776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044295, endtime: 41044455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:51,8602078</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044298, endtime: 41044455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:51,8602142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044300, endtime: 41044455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:51,8602211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044301, endtime: 41044455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:51,8602269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044303, endtime: 41044455, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:52,7816746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56103 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,2336893</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56097 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,2647850</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044274, endtime: 41044595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,2648019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044276, endtime: 41044595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,2648110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044278, endtime: 41044595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,2648293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044280, endtime: 41044595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,2648432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044283, endtime: 41044595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,2648537</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044287, endtime: 41044595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,2648626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044288, endtime: 41044595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,2648687</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044289, endtime: 41044595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,2648764</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044291, endtime: 41044595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,2649535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044292, endtime: 41044595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,2649618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044294, endtime: 41044595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,2649676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044295, endtime: 41044595, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,4481482</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56066 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,9443245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,9443367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:53,9447099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41044663, endtime: 41044663, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,3386019</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044455, endtime: 41044702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,3386290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044456, endtime: 41044702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,3386401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044459, endtime: 41044702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,3386523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044463, endtime: 41044702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,3386623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044465, endtime: 41044702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,3386731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044467, endtime: 41044702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,3386797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044469, endtime: 41044702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,3386875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044472, endtime: 41044702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,3386936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044473, endtime: 41044702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,3387302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044474, endtime: 41044702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,3387362</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044477, endtime: 41044702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,3387435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044478, endtime: 41044702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,3387495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044481, endtime: 41044702, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:54,4214380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:55,1314086</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043388, endtime: 41044782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:55,1314274</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043389, endtime: 41044782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:55,1314374</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043391, endtime: 41044782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:55,1314449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043392, endtime: 41044782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:55,1314529</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043394, endtime: 41044782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:55,1314598</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043395, endtime: 41044782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:55,1336184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043397, endtime: 41044782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:55,1336289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043400, endtime: 41044782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:55,1336369</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043401, endtime: 41044782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:55,1336430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043404, endtime: 41044782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:55,1336499</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043405, endtime: 41044782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:55,1336555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043406, endtime: 41044782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:55,1336624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41043408, endtime: 41044782, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:56,4842056</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56101 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2820974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044298, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2821154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044595, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2821237</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044597, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2821301</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044598, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2821370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044600, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2821426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044600, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2821492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044603, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2821548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044605, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2821614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044606, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2821669</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044608, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2821988</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044611, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2822046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044614, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2822113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044616, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,2835658</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044997, endtime: 41044997, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:57,3208013</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56108 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,6383995</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044702, endtime: 41045132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,6384184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044705, endtime: 41045132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,6384261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044706, endtime: 41045132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,6384339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044709, endtime: 41045132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,6384397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044711, endtime: 41045132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,6384466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044712, endtime: 41045132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,6384522</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044715, endtime: 41045132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,6384591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044717, endtime: 41045132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,6384646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044719, endtime: 41045132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,6385095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044727, endtime: 41045132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,6385164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044730, endtime: 41045132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,6385234</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044731, endtime: 41045132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,6385289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044735, endtime: 41045132, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,7138881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045132, endtime: 41045140, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:09:58,7966714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56103 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0697265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0697492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0697791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0698029</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0698284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0698442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0698672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0698752</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0698833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0698977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0699041</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\Control Panel\Desktop\PreferredUILanguages</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0699284</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0699337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0699459</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings</Path>
<Result>REPARSE</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0699534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0699681</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Maximum Allowed, Granted Access: All Access</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0699819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0699888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0699963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Policies\Microsoft\Control Panel\Desktop</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0700091</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0700160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: Name</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0700229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0700348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegSetInfoKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail>KeySetInformationClass: KeySetHandleTagsInformation, Length: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0700401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegEnumValue</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>NO MORE ENTRIES</Result>
<Detail>Index: 0, Length: 512</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0700465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\Control Panel\Desktop\LanguageConfiguration</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,0700509</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,4379040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5030333</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41044998, endtime: 41045319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5030496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045000, endtime: 41045319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5030568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045000, endtime: 41045319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5030643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045003, endtime: 41045319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5030701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045005, endtime: 41045319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5030770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045006, endtime: 41045319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5030826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045009, endtime: 41045319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5030892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045013, endtime: 41045319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5030948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045014, endtime: 41045319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5031790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045016, endtime: 41045319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5031892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045017, endtime: 41045319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5032003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045019, endtime: 41045319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5138551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5144532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045320, endtime: 41045320, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5324428</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045322, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5324641</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045136, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5324716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045137, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5324790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045139, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5324849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045142, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5324918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045144, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5324973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045147, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5325040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045148, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5325095</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045150, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5325805</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045151, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5325877</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045153, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5325946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045155, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5326004</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045158, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5355932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045160, endtime: 41045322, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5504774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045323, endtime: 41045324, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5773993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56109 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5787308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045326, endtime: 41045326, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5932144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045020, endtime: 41045328, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,5934497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045328, endtime: 41045328, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,6111909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045329, endtime: 41045330, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,6280445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045331, endtime: 41045331, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,6416674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045333, endtime: 41045333, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,6744240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045336, endtime: 41045336, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,7071765</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045339, endtime: 41045339, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,7215911</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045340, endtime: 41045341, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,7344875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045342, endtime: 41045342, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,7524236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045344, endtime: 41045344, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,7832101</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045347, endtime: 41045347, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,7969739</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045348, endtime: 41045348, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,8143066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045350, endtime: 41045350, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,8281707</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045351, endtime: 41045351, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,8447539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045353, endtime: 41045353, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,8774518</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045356, endtime: 41045356, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,8916445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045358, endtime: 41045358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,9297677</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045361, endtime: 41045362, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,9421435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045362, endtime: 41045363, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,9700506</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045365, endtime: 41045366, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:00,9841192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045367, endtime: 41045367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,0004807</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045369, endtime: 41045369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,0166093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045370, endtime: 41045370, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,0343367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045372, endtime: 41045372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,0483951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045373, endtime: 41045373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,4897346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045374, endtime: 41045418, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,4897534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045376, endtime: 41045418, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,4897614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045378, endtime: 41045418, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,4897689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045380, endtime: 41045418, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,4897750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045381, endtime: 41045418, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,4897819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045383, endtime: 41045418, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,4897875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045384, endtime: 41045418, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,4897944</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045387, endtime: 41045418, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,4897999</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045389, endtime: 41045418, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:01,4900158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045391, endtime: 41045418, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,5064555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045322, endtime: 41045519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,5064782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045323, endtime: 41045519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,5064870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045326, endtime: 41045519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,5064962</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045328, endtime: 41045519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,5065031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045329, endtime: 41045519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,5065111</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045331, endtime: 41045519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,5065178</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045333, endtime: 41045519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,5065258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045336, endtime: 41045519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,5065325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045339, endtime: 41045519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,5066231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045340, endtime: 41045519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,5066314</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045342, endtime: 41045519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,5066389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045344, endtime: 41045519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,5067270</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045347, endtime: 41045519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:02,9055599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56110 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:03,3441485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56108 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,1206527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,1206652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,1210181</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41045681, endtime: 41045681, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,3194523</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045392, endtime: 41045701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,3194717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045395, endtime: 41045701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,3194797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045397, endtime: 41045701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,3194875</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045418, endtime: 41045701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,3194936</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045419, endtime: 41045701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,3195008</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045420, endtime: 41045701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,3195066</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045422, endtime: 41045701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,3195135</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045423, endtime: 41045701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,3195191</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045425, endtime: 41045701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,3195498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045426, endtime: 41045701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,3195559</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045428, endtime: 41045701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,3195626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045430, endtime: 41045701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,3195684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045431, endtime: 41045701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,7351539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045519, endtime: 41045742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,7351741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045520, endtime: 41045742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,7351943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045522, endtime: 41045742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,7352071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045523, endtime: 41045742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,7352165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045526, endtime: 41045742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,7352248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045528, endtime: 41045742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,7352350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045530, endtime: 41045742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,7352436</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045531, endtime: 41045742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,7352497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045533, endtime: 41045742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,7353256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045534, endtime: 41045742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,7353334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045536, endtime: 41045742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,7353409</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045537, endtime: 41045742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:04,7354317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045539, endtime: 41045742, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,4819690</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045319, endtime: 41045917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,4819867</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045322, endtime: 41045917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,4819956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045323, endtime: 41045917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,4820022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045326, endtime: 41045917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,4820094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045328, endtime: 41045917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,4820155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045329, endtime: 41045917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,4820224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045331, endtime: 41045917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,4820285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045333, endtime: 41045917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,4820355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045336, endtime: 41045917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,4821147</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045339, endtime: 41045917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,4821233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045340, endtime: 41045917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,4821294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045342, endtime: 41045917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,4822144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045344, endtime: 41045917, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5697154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045742, endtime: 41045926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5697337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045745, endtime: 41045926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5697417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045747, endtime: 41045926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5697497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045748, endtime: 41045926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5697558</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045750, endtime: 41045926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5697630</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045753, endtime: 41045926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5697689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045755, endtime: 41045926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5697758</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045756, endtime: 41045926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5697816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045758, endtime: 41045926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5698667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045759, endtime: 41045926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5698741</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045761, endtime: 41045926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5698813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045763, endtime: 41045926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5699797</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045765, endtime: 41045926, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:06,5776403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56109 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:07,4680458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56116 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,5371724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045917, endtime: 41046122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,5371926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045919, endtime: 41046122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,5372006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045920, endtime: 41046122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,5372084</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045922, endtime: 41046122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,5372148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045923, endtime: 41046122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,5372220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045925, endtime: 41046122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,5372278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045926, endtime: 41046122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,5372347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045928, endtime: 41046122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,5372403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045931, endtime: 41046122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,5373164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045933, endtime: 41046122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,5373239</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045934, endtime: 41046122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,5373309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045936, endtime: 41046122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,5374273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045937, endtime: 41046122, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:08,9061581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56110 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:09,2683887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045926, endtime: 41046195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:09,2684064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045926, endtime: 41046195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:09,2684136</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045928, endtime: 41046195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:09,2684211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045931, endtime: 41046195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:09,2684269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045933, endtime: 41046195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:09,2684341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045934, endtime: 41046195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:09,2684399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045936, endtime: 41046195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:09,2684466</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045937, endtime: 41046195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:09,2684521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045939, endtime: 41046195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:09,2684831</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045940, endtime: 41046195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:09,2684887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045942, endtime: 41046195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:09,2684953</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045944, endtime: 41046195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:09,2685009</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045945, endtime: 41046195, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:10,4717115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56091 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:10,6877806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:10,8963110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:10,8978755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046358, endtime: 41046358, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:10,9059370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046359, endtime: 41046359, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:10,9216367</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046361, endtime: 41046361, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:10,9374452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046362, endtime: 41046362, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:10,9539176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046364, endtime: 41046364, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:10,9843137</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046367, endtime: 41046367, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,0008841</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046369, endtime: 41046369, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,0315642</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046372, endtime: 41046372, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,0478612</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046373, endtime: 41046373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,0542579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046374, endtime: 41046374, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,0644951</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046375, endtime: 41046375, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,0948397</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046378, endtime: 41046378, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,1105219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046380, endtime: 41046380, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,1354486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046381, endtime: 41046382, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,1612018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046384, endtime: 41046385, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,1740032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046386, endtime: 41046386, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,2045248</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046389, endtime: 41046389, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,2197858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046390, endtime: 41046391, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,2502858</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046394, endtime: 41046394, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,2677731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046395, endtime: 41046395, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,2832225</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046397, endtime: 41046397, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,2990582</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046398, endtime: 41046399, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,3292720</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046401, endtime: 41046402, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,3497803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046403, endtime: 41046404, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,3604148</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046405, endtime: 41046405, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,3756429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046406, endtime: 41046406, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4087198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046409, endtime: 41046409, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4398484</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046412, endtime: 41046413, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4654065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046122, endtime: 41046415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4654257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046123, endtime: 41046415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4654334</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046126, endtime: 41046415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4654412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046130, endtime: 41046415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4654473</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046131, endtime: 41046415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4654542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046134, endtime: 41046415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4654603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046136, endtime: 41046415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4654672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046137, endtime: 41046415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4654730</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046139, endtime: 41046415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4655528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046141, endtime: 41046415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4655603</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046142, endtime: 41046415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4655672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046144, endtime: 41046415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:11,4662621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046146, endtime: 41046415, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,4646530</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046414, endtime: 41046515, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,4646721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046415, endtime: 41046515, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,4646798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046417, endtime: 41046515, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,4646873</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046419, endtime: 41046515, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,4646934</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046420, endtime: 41046515, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,4647031</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046422, endtime: 41046515, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,4647117</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046425, endtime: 41046515, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,4647219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046428, endtime: 41046515, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,4647305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046430, endtime: 41046515, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,4647696</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046431, endtime: 41046515, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,5953228</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046195, endtime: 41046528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,5953414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046197, endtime: 41046528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,5953492</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046198, endtime: 41046528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,5953569</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046200, endtime: 41046528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,5953627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046200, endtime: 41046528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,5953699</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046203, endtime: 41046528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,5953755</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046205, endtime: 41046528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,5953932</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046206, endtime: 41046528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,5954007</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046208, endtime: 41046528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,5954309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046211, endtime: 41046528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,5954370</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046212, endtime: 41046528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,5954439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046214, endtime: 41046528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:12,5954497</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046216, endtime: 41046528, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,0151475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56118 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,3906798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045701, endtime: 41046608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,3907097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045701, endtime: 41046608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,3907250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045705, endtime: 41046608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,3907325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045706, endtime: 41046608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,3907405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045709, endtime: 41046608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,3907463</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045711, endtime: 41046608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,3907538</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045712, endtime: 41046608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,3907599</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045714, endtime: 41046608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,3907674</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045717, endtime: 41046608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,3908350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045719, endtime: 41046608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,3908430</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045720, endtime: 41046608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,3908486</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045724, endtime: 41046608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,4839909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56116 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,8996049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046433, endtime: 41046659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,8996224</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046434, endtime: 41046659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,8996298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046436, endtime: 41046659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,8996373</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046515, endtime: 41046659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,8996429</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046517, endtime: 41046659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,8996498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046519, endtime: 41046659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,8996553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046520, endtime: 41046659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,8996620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046522, endtime: 41046659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,8996675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046526, endtime: 41046659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,8996974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046526, endtime: 41046659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,8997033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046528, endtime: 41046659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,8997099</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046530, endtime: 41046659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,8997155</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046531, endtime: 41046659, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,9142792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046415, endtime: 41046660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,9142952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046417, endtime: 41046660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,9143025</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046419, endtime: 41046660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,9143102</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046420, endtime: 41046660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,9143160</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046422, endtime: 41046660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,9143227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046425, endtime: 41046660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,9143285</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046428, endtime: 41046660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,9143351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046430, endtime: 41046660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,9143407</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046431, endtime: 41046660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,9143701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046433, endtime: 41046660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,9143759</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046434, endtime: 41046660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,9143825</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046436, endtime: 41046660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:13,9143883</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046438, endtime: 41046660, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:14,4004344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:14,4004449</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:14,4007987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41046709, endtime: 41046709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:15,7326346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046528, endtime: 41046842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:15,7326526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046530, endtime: 41046842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:15,7326609</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046531, endtime: 41046842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:15,7326689</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046533, endtime: 41046842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:15,7326750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046534, endtime: 41046842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:15,7326822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046536, endtime: 41046842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:15,7326881</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046537, endtime: 41046842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:15,7326950</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046539, endtime: 41046842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:15,7327011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046540, endtime: 41046842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:15,7327296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046542, endtime: 41046842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:15,7327357</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046544, endtime: 41046842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:15,7327426</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046545, endtime: 41046842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:15,7327485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046547, endtime: 41046842, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:16,9644815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046660, endtime: 41046965, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:16,9645017</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046661, endtime: 41046965, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:16,9645097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046662, endtime: 41046965, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:16,9645175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046664, endtime: 41046965, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:16,9645233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046667, endtime: 41046965, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:16,9645305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046669, endtime: 41046965, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:16,9645363</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046670, endtime: 41046965, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:16,9645435</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046673, endtime: 41046965, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:16,9645491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046674, endtime: 41046965, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:16,9645798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046677, endtime: 41046965, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:16,9645859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046678, endtime: 41046965, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:16,9645926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046681, endtime: 41046965, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:16,9645984</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046683, endtime: 41046965, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:17,5782465</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56121 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:18,7475158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046842, endtime: 41047143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:18,7475383</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046844, endtime: 41047143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:18,7475471</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046845, endtime: 41047143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:18,7475557</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046848, endtime: 41047143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:18,7475618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046852, endtime: 41047143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:18,7475693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046855, endtime: 41047143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:18,7475754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046856, endtime: 41047143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:18,7475829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046858, endtime: 41047143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:18,7475887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046859, endtime: 41047143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:18,7476189</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046862, endtime: 41047143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:18,7476253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046864, endtime: 41047143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:18,7476325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046866, endtime: 41047143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:18,7476386</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046867, endtime: 41047143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:19,0163987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56118 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,7296621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41045727, endtime: 41047442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,7296809</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046608, endtime: 41047442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,7296900</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046609, endtime: 41047442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,7296964</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046611, endtime: 41047442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,7297036</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046614, endtime: 41047442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,7297097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046616, endtime: 41047442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,7297164</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046617, endtime: 41047442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,7297222</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046619, endtime: 41047442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,7297288</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046620, endtime: 41047442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,7297346</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046622, endtime: 41047442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,7297665</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046623, endtime: 41047442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,7297887</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046625, endtime: 41047442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,7298006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046626, endtime: 41047442, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:21,8190245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047442, endtime: 41047451, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,1249534</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56128 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2776094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047143, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2776290</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047145, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2776371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047149, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2776451</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047150, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2776512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047152, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2776581</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047153, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2776640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047155, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2776712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047156, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2776770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047159, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2777113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047162, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2777174</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047167, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2777244</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047169, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2777302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047169, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2777424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046965, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2777487</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046967, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2777562</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046969, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2777620</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046972, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2777695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046974, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2777756</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046975, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2778349</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046975, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2778421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046978, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2778490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046981, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2778548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046983, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2778618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046984, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2778676</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046987, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,2778745</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046989, endtime: 41047596, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:23,5932685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56121 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:24,3986851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:24,3986967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:24,3990633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41047708, endtime: 41047709, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:25,9451211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046659, endtime: 41047863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:25,9451371</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046659, endtime: 41047863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:25,9451457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046661, endtime: 41047863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:25,9451521</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046662, endtime: 41047863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:25,9451590</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046664, endtime: 41047863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:25,9451646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046667, endtime: 41047863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:25,9451712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046669, endtime: 41047863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:25,9451767</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046670, endtime: 41047863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:25,9451939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046673, endtime: 41047863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:25,9452770</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046674, endtime: 41047863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:25,9452859</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046677, endtime: 41047863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:25,9452920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046678, endtime: 41047863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:25,9453543</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41046681, endtime: 41047863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,1564580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56131 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,5433698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047596, endtime: 41048023, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,5433870</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047598, endtime: 41048023, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,5433939</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047600, endtime: 41048023, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,5434012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047600, endtime: 41048023, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,5434070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047603, endtime: 41048023, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,5434139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047605, endtime: 41048023, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,5434192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047608, endtime: 41048023, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,5434258</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047609, endtime: 41048023, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,5434311</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047611, endtime: 41048023, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,5435233</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047612, endtime: 41048023, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,5435325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047614, endtime: 41048023, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,5435419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047616, endtime: 41048023, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,5441952</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047617, endtime: 41048023, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7026604</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56132 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7827826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047444, endtime: 41048047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7828058</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047445, endtime: 41048047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7828200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047449, endtime: 41048047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7828305</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047450, endtime: 41048047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7828427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047451, endtime: 41048047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7828524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047453, endtime: 41048047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7828640</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047455, endtime: 41048047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7828737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047456, endtime: 41048047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7828862</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047459, endtime: 41048047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7830682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047461, endtime: 41048047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7830815</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047464, endtime: 41048047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7830940</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047467, endtime: 41048047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:27,7832826</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047469, endtime: 41048047, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:28,4332650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047596, endtime: 41048112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:28,4332813</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047598, endtime: 41048112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:28,4332905</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047600, endtime: 41048112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:28,4332974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047600, endtime: 41048112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:28,4333049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047603, endtime: 41048112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:28,4333110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047605, endtime: 41048112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:28,4333182</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047608, endtime: 41048112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:28,4333240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047609, endtime: 41048112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:28,4333309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047611, endtime: 41048112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:28,4333595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047612, endtime: 41048112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:28,4333672</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047614, endtime: 41048112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:28,4333731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047616, endtime: 41048112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:28,4333803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41047617, endtime: 41048112, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,1560150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56128 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,6973748</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048023, endtime: 41048238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,6974011</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048025, endtime: 41048238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,6974130</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048026, endtime: 41048238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,6974227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048028, endtime: 41048238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,6974291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048030, endtime: 41048238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,6974368</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048031, endtime: 41048238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,6974432</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048033, endtime: 41048238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,6974507</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048034, endtime: 41048238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,6974568</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048036, endtime: 41048238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,6975698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048037, endtime: 41048238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,6975812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048039, endtime: 41048238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,6975931</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048040, endtime: 41048238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:29,6983339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048042, endtime: 41048238, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,4806344</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048112, endtime: 41048417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,4806541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048114, endtime: 41048417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,4806626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048115, endtime: 41048417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,4806710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048117, endtime: 41048417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,4806776</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048119, endtime: 41048417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,4806851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048120, endtime: 41048417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,4806915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048122, endtime: 41048417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,4806987</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048123, endtime: 41048417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,4807050</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048125, endtime: 41048417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,4807352</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048126, endtime: 41048417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,4807419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048128, endtime: 41048417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,4807491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048130, endtime: 41048417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,4807552</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048131, endtime: 41048417, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:31,9588309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56041 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,0712976</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,0716955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048476, endtime: 41048476, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,1006833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048478, endtime: 41048479, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,1094200</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048480, endtime: 41048480, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,1258142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048481, endtime: 41048481, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,1406902</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048483, endtime: 41048483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,1568930</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048484, endtime: 41048484, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,1715271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048486, endtime: 41048486, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,1874584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048487, endtime: 41048487, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,2027790</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048489, endtime: 41048489, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,2185632</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048490, endtime: 41048490, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,2343108</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048492, endtime: 41048492, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,2508266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048494, endtime: 41048494, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,2828496</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048497, endtime: 41048497, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,2977799</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048498, endtime: 41048498, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,3124960</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048500, endtime: 41048500, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,3179795</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048500, endtime: 41048500, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,3454670</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048503, endtime: 41048503, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,3594077</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048504, endtime: 41048505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,3813982</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048506, endtime: 41048507, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,4063293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048509, endtime: 41048509, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,4229253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048511, endtime: 41048511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,4534876</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048514, endtime: 41048514, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,4706271</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048515, endtime: 41048516, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,4861384</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048517, endtime: 41048517, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,5018901</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048519, endtime: 41048519, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,5422929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048522, endtime: 41048523, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,9731993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048525, endtime: 41048566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,9732184</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048526, endtime: 41048566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,9732265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048528, endtime: 41048566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,9732348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048530, endtime: 41048566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,9732414</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048531, endtime: 41048566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,9732489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048533, endtime: 41048566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,9732553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048536, endtime: 41048566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,9732628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048537, endtime: 41048566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,9732688</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048539, endtime: 41048566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,9732974</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048541, endtime: 41048566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,9733040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048542, endtime: 41048566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,9733112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048544, endtime: 41048566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:32,9733176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048545, endtime: 41048566, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:33,1566783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56131 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:33,2494452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56136 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:33,7178517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56132 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:34,5487325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:34,5487442</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:34,5491024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41048723, endtime: 41048724, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9412173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048047, endtime: 41048863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9412309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048048, endtime: 41048863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9412398</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048051, endtime: 41048863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9412464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048053, endtime: 41048863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9412536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048054, endtime: 41048863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9412595</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048056, endtime: 41048863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9412661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048058, endtime: 41048863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9412852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048059, endtime: 41048863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9412933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048063, endtime: 41048863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9413553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048066, endtime: 41048863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9413639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048069, endtime: 41048863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9413697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048070, endtime: 41048863, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9554913</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048072, endtime: 41048864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9555079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048863, endtime: 41048864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9555162</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048864, endtime: 41048864, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9680624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048865, endtime: 41048865, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:35,9848692</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048867, endtime: 41048867, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,0000643</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048869, endtime: 41048869, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,0158851</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048870, endtime: 41048870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,0312520</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048872, endtime: 41048872, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,0472309</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048873, endtime: 41048873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,0547045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048874, endtime: 41048874, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,0783293</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048876, endtime: 41048876, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,0944623</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048878, endtime: 41048878, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,1096358</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048880, endtime: 41048880, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,2600340</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048417, endtime: 41048895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,2600526</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048419, endtime: 41048895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,2600601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048422, endtime: 41048895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,2600678</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048425, endtime: 41048895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,2600737</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048426, endtime: 41048895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,2600803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048428, endtime: 41048895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,2600861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048431, endtime: 41048895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,2600933</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048435, endtime: 41048895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,2600992</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048437, endtime: 41048895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,2601302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048439, endtime: 41048895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,2601360</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048441, endtime: 41048895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,2601427</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048442, endtime: 41048895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:36,2601485</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048445, endtime: 41048895, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,0047618</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048566, endtime: 41048969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,0047801</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048567, endtime: 41048969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,0048133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048569, endtime: 41048969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,0048294</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048570, endtime: 41048969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,0048391</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048572, endtime: 41048969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,0048477</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048573, endtime: 41048969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,0048546</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048574, endtime: 41048969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,0048627</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048576, endtime: 41048969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,0048693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048578, endtime: 41048969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,0049034</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048580, endtime: 41048969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,0049100</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048581, endtime: 41048969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,0049172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048583, endtime: 41048969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,0049236</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048584, endtime: 41048969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,2655380</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:37,8276302</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56142 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:39,2648551</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56136 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:41,0203700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048969, endtime: 41049371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:41,0203872</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048970, endtime: 41049371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:41,0203947</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048972, endtime: 41049371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:41,0204022</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048975, endtime: 41049371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:41,0204080</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048976, endtime: 41049371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:41,0204146</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048978, endtime: 41049371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:41,0204202</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048981, endtime: 41049371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:41,0204266</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048983, endtime: 41049371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:41,0204321</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048986, endtime: 41049371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:41,0204626</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048987, endtime: 41049371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:41,0204684</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048990, endtime: 41049371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:41,0204750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048992, endtime: 41049371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:41,0204803</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048994, endtime: 41049371, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,1434142</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048895, endtime: 41049483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,1434345</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048897, endtime: 41049483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,1434439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048900, endtime: 41049483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,1434508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048901, endtime: 41049483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,1434580</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048903, endtime: 41049483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,1434644</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048906, endtime: 41049483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,1434719</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048908, endtime: 41049483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,1434777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048909, endtime: 41049483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,1434852</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048911, endtime: 41049483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,1435478</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048912, endtime: 41049483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,1435566</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048914, endtime: 41049483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,1435625</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048916, endtime: 41049483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,1435697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048919, endtime: 41049483, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,8510910</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048881, endtime: 41049554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,8511096</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048883, endtime: 41049554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,8511287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048886, endtime: 41049554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,8511378</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048890, endtime: 41049554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,8511445</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048890, endtime: 41049554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,8511517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048892, endtime: 41049554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,8511575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048894, endtime: 41049554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,8511647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048895, endtime: 41049554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,8511705</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048897, endtime: 41049554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,8512024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048900, endtime: 41049554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,8512085</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048901, endtime: 41049554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,8512151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048903, endtime: 41049554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,8512209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41048906, endtime: 41049554, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:42,9506275</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56117 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,2650235</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,3322498</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,3327319</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049602, endtime: 41049602, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,3445087</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049603, endtime: 41049603, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,3742920</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56147 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,3752425</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049606, endtime: 41049606, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,3908646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049608, endtime: 41049608, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,4058417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049609, endtime: 41049609, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,4216710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049611, endtime: 41049611, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,4380991</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049612, endtime: 41049612, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,4569721</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049614, endtime: 41049614, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,4850972</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049617, endtime: 41049617, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,4994631</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049619, endtime: 41049619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,5163849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049620, endtime: 41049620, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,5466341</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049623, endtime: 41049623, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,5633204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049625, endtime: 41049625, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,6006919</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049628, endtime: 41049629, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,6101955</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049629, endtime: 41049630, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,6265490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049631, endtime: 41049631, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,6401660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049633, endtime: 41049633, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,6586044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049634, endtime: 41049634, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,6726434</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049636, endtime: 41049636, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,7047647</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049639, endtime: 41049639, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,7188879</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049640, endtime: 41049640, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,7357717</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049642, endtime: 41049642, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,7579628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049644, endtime: 41049644, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,7655957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049645, endtime: 41049645, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,7820570</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049647, endtime: 41049647, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:43,8282198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56142 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,3223005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049371, endtime: 41049701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,3223196</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049372, endtime: 41049701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,3223273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049373, endtime: 41049701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,3223351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049374, endtime: 41049701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,3223412</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049375, endtime: 41049701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,3223481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049378, endtime: 41049701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,3223536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049380, endtime: 41049701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,3223606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049381, endtime: 41049701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,3223664</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049383, endtime: 41049701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,3223963</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049384, endtime: 41049701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,3224024</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049386, endtime: 41049701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,3224093</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049387, endtime: 41049701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,3224152</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049389, endtime: 41049701, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,8139993</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,8140123</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:44,8145639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41049750, endtime: 41049750, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:46,0437572</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049648, endtime: 41049873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:46,0437774</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049650, endtime: 41049873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:46,0437854</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049651, endtime: 41049873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:46,0438051</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049655, endtime: 41049873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:46,0438176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049656, endtime: 41049873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:46,0438259</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049659, endtime: 41049873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:46,0438323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049661, endtime: 41049873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:46,0438403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049662, endtime: 41049873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:46,0438467</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049664, endtime: 41049873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:46,0438824</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049666, endtime: 41049873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:46,0438888</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049667, endtime: 41049873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:46,0438957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049669, endtime: 41049873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:46,0439018</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049672, endtime: 41049873, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,4395151</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049483, endtime: 41050013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,4395331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049486, endtime: 41050013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,4395403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049487, endtime: 41050013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,4395475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049489, endtime: 41050013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,4395528</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049492, endtime: 41050013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,4395594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049494, endtime: 41050013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,4395650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049495, endtime: 41050013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,4395714</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049497, endtime: 41050013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,4395766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049498, endtime: 41050013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,4396049</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049501, endtime: 41050013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,4396107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049505, endtime: 41050013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,4396171</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049508, endtime: 41050013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,4396223</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049509, endtime: 41050013, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:47,9214269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56149 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3551646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049554, endtime: 41050204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3551820</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049555, endtime: 41050204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3551909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049556, endtime: 41050204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3551973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049558, endtime: 41050204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3552045</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049559, endtime: 41050204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3552103</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049562, endtime: 41050204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3552172</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049564, endtime: 41050204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3552227</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049566, endtime: 41050204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3552297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049567, endtime: 41050204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3552574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049569, endtime: 41050204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3552646</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049570, endtime: 41050204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3552701</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049572, endtime: 41050204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3552773</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049573, endtime: 41050204, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,3749561</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56147 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,8083269</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049701, endtime: 41050249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,8083424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049703, endtime: 41050249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,8083512</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049705, endtime: 41050249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,8083579</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049706, endtime: 41050249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,8083651</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049709, endtime: 41050249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,8083712</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049711, endtime: 41050249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,8083781</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049712, endtime: 41050249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,8083839</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049714, endtime: 41050249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,8083909</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049716, endtime: 41050249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,8084205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049717, endtime: 41050249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,8084277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049719, endtime: 41050249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,8084332</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049723, endtime: 41050249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,8084402</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049725, endtime: 41050249, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,9232738</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050013, endtime: 41050261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,9232924</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050014, endtime: 41050261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,9233001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050015, endtime: 41050261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,9233076</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050017, endtime: 41050261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,9233131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050019, endtime: 41050261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,9233198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050020, endtime: 41050261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,9233256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050023, endtime: 41050261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,9233323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050025, endtime: 41050261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,9233375</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050026, endtime: 41050261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,9233816</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050028, endtime: 41050261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,9233885</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050030, endtime: 41050261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,9233954</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050031, endtime: 41050261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:49,9234010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050033, endtime: 41050261, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:50,7608001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050261, endtime: 41050345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:50,7608331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050262, endtime: 41050345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:50,7608422</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050264, endtime: 41050345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:50,7608508</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050265, endtime: 41050345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:50,7608577</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050267, endtime: 41050345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:50,7608652</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050270, endtime: 41050345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:50,7608716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050272, endtime: 41050345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:50,7608791</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050273, endtime: 41050345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:50,7608857</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050274, endtime: 41050345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:50,7609190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050275, endtime: 41050345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:50,7609253</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050278, endtime: 41050345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:50,7609323</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050279, endtime: 41050345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:50,7609381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050281, endtime: 41050345, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,4989265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56154 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,8483925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050345, endtime: 41050653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,8484133</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050347, endtime: 41050653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,8484210</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050348, endtime: 41050653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,8484291</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050350, endtime: 41050653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,8484354</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050353, endtime: 41050653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,8484424</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050355, endtime: 41050653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,8484479</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050356, endtime: 41050653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,8484548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050360, endtime: 41050653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,8484606</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050361, endtime: 41050653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,8484925</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050364, endtime: 41050653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,8484989</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050365, endtime: 41050653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,8485055</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050367, endtime: 41050653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,8485113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050369, endtime: 41050653, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:53,9368556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56149 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:54,0327060</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050249, endtime: 41050672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:54,0327231</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050251, endtime: 41050672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:54,0327306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050253, endtime: 41050672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:54,0327381</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050255, endtime: 41050672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:54,0327439</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050256, endtime: 41050672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:54,0327511</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050259, endtime: 41050672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:54,0327567</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050261, endtime: 41050672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:54,0327633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050262, endtime: 41050672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:54,0327849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050264, endtime: 41050672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:54,0328220</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050265, endtime: 41050672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:54,0328279</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050270, endtime: 41050672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:54,0328348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050272, endtime: 41050672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:54,0328406</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050273, endtime: 41050672, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0400044</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0400261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0403297</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41050773, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0438915</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049873, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0439065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049875, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0439154</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049876, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0439217</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049878, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0439289</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049880, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0439348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049884, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0439417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049886, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0439472</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049888, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0439542</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049889, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0439819</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049892, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0440071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049894, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0440176</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049895, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:55,0440303</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41049897, endtime: 41050773, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,0179023</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050653, endtime: 41050870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,0179256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050655, endtime: 41050870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,0179339</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050656, endtime: 41050870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,0179419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050658, endtime: 41050870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,0179483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050659, endtime: 41050870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,0179555</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050662, endtime: 41050870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,0179613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050664, endtime: 41050870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,0179685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050665, endtime: 41050870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,0179743</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050667, endtime: 41050870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,0180317</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050669, endtime: 41050870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,0180405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050670, endtime: 41050870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,0180480</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050672, endtime: 41050870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,0180541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050673, endtime: 41050870, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,6135556</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Disconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56075 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,7171438</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Connect</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, mss: 1460, sackopt: 0, tsopt: 0, wsopt: 0, rcvwin: 64240, rcvwinscale: 0, sndwinscale: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,7175417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050940, endtime: 41050940, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,7350203</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050942, endtime: 41050942, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,7692190</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050946, endtime: 41050946, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,7813457</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050947, endtime: 41050947, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,7998489</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050949, endtime: 41050949, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8286653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050951, endtime: 41050951, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8437806</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050953, endtime: 41050953, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8636865</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050955, endtime: 41050955, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8856621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050204, endtime: 41050957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8857003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050206, endtime: 41050957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8857144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050209, endtime: 41050957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8857238</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050213, endtime: 41050957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8857308</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050214, endtime: 41050957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8857388</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050218, endtime: 41050957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8857452</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050220, endtime: 41050957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8857624</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050222, endtime: 41050957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8857787</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050223, endtime: 41050957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8878195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050225, endtime: 41050957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8878306</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050227, endtime: 41050957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8878389</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050230, endtime: 41050957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8878450</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050233, endtime: 41050957, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,8905396</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050958, endtime: 41050958, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,9071591</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050959, endtime: 41050959, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,9240662</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050961, endtime: 41050961, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,9536150</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050964, endtime: 41050964, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:56,9712106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050965, endtime: 41050966, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,0016505</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050969, endtime: 41050969, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,0165245</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050970, endtime: 41050970, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,0491800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050973, endtime: 41050974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,0549408</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050974, endtime: 41050974, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,0859611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050976, endtime: 41050977, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,1101054</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050979, endtime: 41050980, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,1248914</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050981, endtime: 41050981, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,1416211</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050983, endtime: 41050983, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,1801219</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050986, endtime: 41050987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,1878216</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050987, endtime: 41050987, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,2042751</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050989, endtime: 41050989, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,2201967</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050990, endtime: 41050991, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,2351990</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050992, endtime: 41050992, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,2514079</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050994, endtime: 41050994, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,2685845</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050995, endtime: 41050995, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,2997891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050998, endtime: 41050999, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,3142786</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051000, endtime: 41051000, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,3209221</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051001, endtime: 41051001, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,3494600</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051003, endtime: 41051004, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,3755088</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051006, endtime: 41051006, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,3905726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051008, endtime: 41051008, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,4067488</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051009, endtime: 41051009, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,8670458</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051011, endtime: 41051055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,8670611</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051014, endtime: 41051055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:57,8671633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051016, endtime: 41051055, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:58,0503403</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56158 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,3345064</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050672, endtime: 41051202, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,3345264</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050673, endtime: 41051202, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,3345366</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050674, endtime: 41051202, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,3345441</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050676, endtime: 41051202, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,3345527</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050678, endtime: 41051202, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,3345594</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050680, endtime: 41051202, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,3345671</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050681, endtime: 41051202, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,3345735</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050683, endtime: 41051202, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,3345812</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050684, endtime: 41051202, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,3346109</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050686, endtime: 41051202, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,3346192</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050688, endtime: 41051202, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,3346256</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050689, endtime: 41051202, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,3346330</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050692, endtime: 41051202, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:10:59,5004622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56154 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:00,4997853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050773, endtime: 41051319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:00,4998069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050774, endtime: 41051319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:00,4998158</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050776, endtime: 41051319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:00,4998394</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050778, endtime: 41051319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:00,4998532</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050779, endtime: 41051319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:00,4998659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050781, endtime: 41051319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:00,4998768</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050783, endtime: 41051319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:00,4998889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050784, endtime: 41051319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:00,4998961</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050786, endtime: 41051319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:00,4999355</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050787, endtime: 41051319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:00,4999419</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050789, endtime: 41051319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:00,4999491</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050792, endtime: 41051319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:00,4999554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050794, endtime: 41051319, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:02,4199948</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051018, endtime: 41051511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:02,4200112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051020, endtime: 41051511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:02,4200198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051024, endtime: 41051511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:02,4200262</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051025, endtime: 41051511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:02,4200331</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051027, endtime: 41051511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:02,4200483</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051028, endtime: 41051511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:02,4200575</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051030, endtime: 41051511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:02,4200636</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051031, endtime: 41051511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:02,4200710</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051033, endtime: 41051511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:02,4201043</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051034, endtime: 41051511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:02,4201115</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051055, endtime: 41051511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:02,4201170</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051056, endtime: 41051511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:02,4201240</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051058, endtime: 41051511, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,5057326</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050957, endtime: 41051619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,5057495</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050959, endtime: 41051619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,5057587</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050961, endtime: 41051619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,5057653</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050964, endtime: 41051619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,5057725</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050965, endtime: 41051619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,5057794</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050969, endtime: 41051619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,5057853</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050970, endtime: 41051619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,5057922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050973, endtime: 41051619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,5057977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050974, endtime: 41051619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,5058287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050976, endtime: 41051619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,5058348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050979, endtime: 41051619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,5058415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050981, endtime: 41051619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,5058470</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41050983, endtime: 41051619, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,7178351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56163 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,8008746</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051202, endtime: 41051649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,8009012</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051203, endtime: 41051649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,8009134</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051205, endtime: 41051649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,8009261</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051206, endtime: 41051649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,8009328</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051208, endtime: 41051649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,8009405</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051209, endtime: 41051649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,8009464</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051211, endtime: 41051649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,8009541</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051212, endtime: 41051649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,8009608</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051214, endtime: 41051649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,8009968</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051215, endtime: 41051649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,8010032</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051217, endtime: 41051649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,8010104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051219, endtime: 41051649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:03,8010165</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051222, endtime: 41051649, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:04,0543903</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56158 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,1817798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,1817926</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,1821350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41051787, endtime: 41051787, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,6225106</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051511, endtime: 41051831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,6225447</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051512, endtime: 41051831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,6225536</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051514, endtime: 41051831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,6225622</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051517, endtime: 41051831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,6225685</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051519, endtime: 41051831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,6225760</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051520, endtime: 41051831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,6225821</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051522, endtime: 41051831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,6225896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051525, endtime: 41051831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,6225957</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051526, endtime: 41051831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,6226287</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051528, endtime: 41051831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,6226347</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051532, endtime: 41051831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,6226417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051534, endtime: 41051831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:05,6226475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051536, endtime: 41051831, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:07,6376661</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051831, endtime: 41052032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:07,6376844</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051833, endtime: 41052032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:07,6376922</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051834, endtime: 41052032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:07,6377005</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051836, endtime: 41052032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:07,6377072</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051837, endtime: 41052032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:07,6377144</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051839, endtime: 41052032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:07,6377204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051841, endtime: 41052032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:07,6377277</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051842, endtime: 41052032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:07,6377337</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051844, endtime: 41052032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:07,6377637</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051845, endtime: 41052032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:07,6377700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051847, endtime: 41052032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:07,6377772</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051848, endtime: 41052032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:07,6377833</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051850, endtime: 41052032, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,2025818</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56166 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,7418716</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051649, endtime: 41052143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,7418894</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051650, endtime: 41052143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,7418971</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051651, endtime: 41052143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,7419046</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051654, endtime: 41052143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,7419104</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051656, endtime: 41052143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,7419173</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051658, endtime: 41052143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,7419229</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051661, endtime: 41052143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,7419298</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051662, endtime: 41052143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,7419351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051664, endtime: 41052143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,7419639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051667, endtime: 41052143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,7419700</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051670, endtime: 41052143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,7419766</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051672, endtime: 41052143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:08,7420780</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051673, endtime: 41052143, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:09,7336107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56163 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:10,0778896</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051328, endtime: 41052276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:10,0779110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051329, endtime: 41052276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:10,0779204</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051333, endtime: 41052276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:10,0779273</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051334, endtime: 41052276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:10,0779351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051336, endtime: 41052276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:10,0779415</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051339, endtime: 41052276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:10,0779633</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051340, endtime: 41052276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:10,0779750</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051342, endtime: 41052276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:10,0779861</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051344, endtime: 41052276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:10,0780318</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051349, endtime: 41052276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:10,0780401</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051350, endtime: 41052276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:10,0780462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051351, endtime: 41052276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:10,0780539</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051353, endtime: 41052276, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3237475</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051619, endtime: 41052401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3237639</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051622, endtime: 41052401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3237727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051624, endtime: 41052401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3237788</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051625, endtime: 41052401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3237860</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051626, endtime: 41052401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3237916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051628, endtime: 41052401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3237985</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051630, endtime: 41052401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3238040</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051633, endtime: 41052401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3238107</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051636, endtime: 41052401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3238866</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051639, endtime: 41052401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3238949</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051640, endtime: 41052401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3239010</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051642, endtime: 41052401, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3971139</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052032, endtime: 41052408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3971325</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052034, endtime: 41052408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3971399</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052036, endtime: 41052408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3971474</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052040, endtime: 41052408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3971535</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052040, endtime: 41052408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3971602</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052042, endtime: 41052408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3971657</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052044, endtime: 41052408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3971726</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052045, endtime: 41052408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3971782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052048, endtime: 41052408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3972067</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052050, endtime: 41052408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3972128</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052051, endtime: 41052408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3972195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052053, endtime: 41052408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:11,3972250</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052055, endtime: 41052408, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:12,3626265</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052143, endtime: 41052505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:12,3626423</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052144, endtime: 41052505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:12,3626501</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052145, endtime: 41052505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:12,3626584</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052147, endtime: 41052505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:12,3626650</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052148, endtime: 41052505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:12,3627033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052150, endtime: 41052505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:12,3627110</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052151, endtime: 41052505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:12,3627188</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052153, endtime: 41052505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:12,3627249</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052155, endtime: 41052505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:12,3627601</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052156, endtime: 41052505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:12,3627659</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052158, endtime: 41052505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:12,3627731</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052159, endtime: 41052505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:12,3627789</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052161, endtime: 41052505, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:13,8442006</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56168 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:14,2027943</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56166 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,2928660</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP TCPCopy</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,2928782</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Receive</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,2931777</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:54920 -&gt; sheltex.company:8000</Path>
<Result>SUCCESS</Result>
<Detail>Length: 2, startime: 41052798, endtime: 41052798, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,3105682</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052505, endtime: 41052800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,3105882</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052506, endtime: 41052800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,3105973</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052508, endtime: 41052800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,3106059</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052511, endtime: 41052800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,3106131</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052512, endtime: 41052800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,3106209</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052514, endtime: 41052800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,3106272</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052515, endtime: 41052800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,3106350</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052517, endtime: 41052800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,3106417</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052519, endtime: 41052800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,3106727</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052522, endtime: 41052800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,3106793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052523, endtime: 41052800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,3106868</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052530, endtime: 41052800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,3106935</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052533, endtime: 41052800, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,5559421</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052408, endtime: 41052824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,5559709</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052409, endtime: 41052824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,5559798</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052411, endtime: 41052824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,5559886</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052412, endtime: 41052824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,5559956</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052414, endtime: 41052824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,5560033</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052416, endtime: 41052824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,5560097</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052417, endtime: 41052824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,5560175</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052419, endtime: 41052824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,5560241</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052420, endtime: 41052824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,5560554</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052422, endtime: 41052824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,5560621</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052423, endtime: 41052824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,5560693</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052425, endtime: 41052824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:15,5560754</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052426, endtime: 41052824, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,3120444</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56171 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,8322069</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41051644, endtime: 41053152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,8322260</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052401, endtime: 41053152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,8322351</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052403, endtime: 41053152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,8322418</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052405, endtime: 41053152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,8322490</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052406, endtime: 41053152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,8322548</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052408, endtime: 41053152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,8322617</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052409, endtime: 41053152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,8322675</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052411, endtime: 41053152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,8322742</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052412, endtime: 41053152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,8322800</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052414, endtime: 41053152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,8323119</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052416, endtime: 41053152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,8323177</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052417, endtime: 41053152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:18,8323246</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052419, endtime: 41053152, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:19,8585613</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56168 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:20,8045517</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052800, endtime: 41053349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:20,8045680</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052800, endtime: 41053349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:20,8045761</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052803, endtime: 41053349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:20,8045822</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052805, endtime: 41053349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:20,8045891</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052806, endtime: 41053349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:20,8045946</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052808, endtime: 41053349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:20,8046016</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052809, endtime: 41053349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:20,8046071</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052811, endtime: 41053349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:20,8046276</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052812, endtime: 41053349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:20,8046628</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052814, endtime: 41053349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:20,8046697</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052816, endtime: 41053349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:20,8046753</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052819, endtime: 41053349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:20,8052698</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56137 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052822, endtime: 41053349, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,0398280</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052276, endtime: 41053373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,0398460</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052278, endtime: 41053373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,0398667</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052281, endtime: 41053373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,0398792</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052284, endtime: 41053373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,0398889</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052287, endtime: 41053373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,0399003</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052289, endtime: 41053373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,0399094</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052291, endtime: 41053373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,0399205</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052292, endtime: 41053373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,0399296</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052295, endtime: 41053373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,0399695</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052298, endtime: 41053373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,0399762</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052300, endtime: 41053373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,0399834</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052300, endtime: 41053373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,0399892</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56141 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052303, endtime: 41053373, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,6673574</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052824, endtime: 41053435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,6673829</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052825, endtime: 41053435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,6673918</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052826, endtime: 41053435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,6674001</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052828, endtime: 41053435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,6674070</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052829, endtime: 41053435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,6674145</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052831, endtime: 41053435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,6674206</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052834, endtime: 41053435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,6674278</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052836, endtime: 41053435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,6674342</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052839, endtime: 41053435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,6674663</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052841, endtime: 41053435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,6674724</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052842, endtime: 41053435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,6674793</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052844, endtime: 41053435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:21,6674849</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41052845, endtime: 41053435, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,3745524</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56175 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,4749736</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053152, endtime: 41053616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,4749941</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053153, endtime: 41053616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,4750027</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053155, endtime: 41053616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,4750113</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053156, endtime: 41053616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,4750179</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053158, endtime: 41053616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,4750257</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053159, endtime: 41053616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,4750320</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053161, endtime: 41053616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,4750395</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053162, endtime: 41053616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,4750462</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053166, endtime: 41053616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,4750783</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053167, endtime: 41053616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,4750847</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053169, endtime: 41053616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,4750916</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053170, endtime: 41053616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,4750977</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56106 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053172, endtime: 41053616, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:23,9845198</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56176 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,1161899</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053435, endtime: 41053680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,1162112</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053437, endtime: 41053680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,1162195</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053441, endtime: 41053680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,1162281</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053444, endtime: 41053680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,1162348</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053447, endtime: 41053680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,1162420</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053449, endtime: 41053680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,1162481</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053451, endtime: 41053680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,1162553</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053451, endtime: 41053680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,1162614</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053453, endtime: 41053680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,1162929</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053456, endtime: 41053680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,1162996</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053458, endtime: 41053680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,1163065</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053459, endtime: 41053680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,1163126</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Send</Operation>
<Path>WIN-0UOTFKKVN1S:56160 -&gt; 54.36.38.171:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 5120, startime: 41053461, endtime: 41053680, seqnum: 0, connid: 0</Detail>
</event>

<event>
<ProcessIndex>98</ProcessIndex>
<Time_of_Day>13:11:24,3145545</Time_of_Day>
<Process_Name>MCLauncher.exe</Process_Name>
<PID>6080</PID>
<Operation>TCP Reconnect</Operation>
<Path>WIN-0UOTFKKVN1S:56171 -&gt; ip188.ip-188-165-24.eu:25565</Path>
<Result>SUCCESS</Result>
<Detail>Length: 0, seqnum: 0, connid: 0</Detail>
</event>
</eventlist></procmon>